<?xml version="1.0" encoding="UTF-8"?>
	<oval_definitions
		xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd"
		xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5"
		xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
		xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5"
		xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
	  <generator>
	      <oval:product_name>Marcus Updateinfo to OVAL Converter</oval:product_name>
	      <oval:schema_version>5.5</oval:schema_version>
	      <oval:timestamp>2023-10-19T04:54:53</oval:timestamp>
	  </generator>
<definitions>
<definition id="oval:org.opensuse.security:def:19990077" version="1" class="vulnerability">
 <metadata>
 <title>CVE-1999-0077</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-1999-0077" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0077" source="CVE"/>
    <reference ref_id="SUSE CVE-1999-0077" ref_url="https://www.suse.com/security/cve/CVE-1999-0077" source="SUSE CVE"/>
    <description>
    Predictable TCP sequence numbers allow spoofing.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-17"/>
	<updated date="2023-01-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-1999-0077/">CVE-1999-0077</cve>
	<bugzilla href="https://bugzilla.suse.com/954946">SUSE bug 954946</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:19990195" version="1" class="vulnerability">
 <metadata>
 <title>CVE-1999-0195</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-1999-0195" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0195" source="CVE"/>
    <reference ref_id="SUSE CVE-1999-0195" ref_url="https://www.suse.com/security/cve/CVE-1999-0195" source="SUSE CVE"/>
    <description>
    Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-17"/>
	<updated date="2023-01-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-1999-0195/">CVE-1999-0195</cve>
	<bugzilla href="https://bugzilla.suse.com/914171">SUSE bug 914171</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009732558" comment="rpcbind is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:19990524" version="1" class="vulnerability">
 <metadata>
 <title>CVE-1999-0524</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-1999-0524" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0524" source="CVE"/>
    <reference ref_id="SUSE CVE-1999-0524" ref_url="https://www.suse.com/security/cve/CVE-1999-0524" source="SUSE CVE"/>
    <description>
    ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-06"/>
	<updated date="2023-04-06"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-1999-0524/">CVE-1999-0524</cve>
	<bugzilla href="https://bugzilla.suse.com/351997">SUSE bug 351997</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/992991">SUSE bug 992991</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20001254" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2000-1254</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2000-1254" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1254" source="CVE"/>
    <reference ref_id="SUSE CVE-2000-1254" ref_url="https://www.suse.com/security/cve/CVE-2000-1254" source="SUSE CVE"/>
    <description>
    crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging improper RSA key generation on 64-bit HP-UX platforms.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2000-1254/">CVE-2000-1254</cve>
	<bugzilla href="https://bugzilla.suse.com/978847">SUSE bug 978847</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334866" comment="libopenssl1_1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333944" comment="openssl-1_1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20010405" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2001-0405</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2001-0405" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0405" source="CVE"/>
    <reference ref_id="SUSE CVE-2001-0405" ref_url="https://www.suse.com/security/cve/CVE-2001-0405" source="SUSE CVE"/>
    <description>
    ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2001-0405/">CVE-2001-0405</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20010851" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2001-0851</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2001-0851" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0851" source="CVE"/>
    <reference ref_id="SUSE CVE-2001-0851" ref_url="https://www.suse.com/security/cve/CVE-2001-0851" source="SUSE CVE"/>
    <description>
    Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2001-0851/">CVE-2001-0851</cve>
	<bugzilla href="https://bugzilla.suse.com/1175687">SUSE bug 1175687</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:200220001" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2002-20001</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2002-20001" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-20001" source="CVE"/>
    <reference ref_id="SUSE CVE-2002-20001" ref_url="https://www.suse.com/security/cve/CVE-2002-20001" source="SUSE CVE"/>
		<reference ref_id="TID000020510" ref_url="https://www.suse.com/support/kb/doc/?id=000020510" source="SUSE-SU"/>
    <description>
    The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2002-20001/">CVE-2002-20001</cve>
	<bugzilla href="https://bugzilla.suse.com/1192815">SUSE bug 1192815</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199367">SUSE bug 1199367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20030252" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2003-0252</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2003-0252" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0252" source="CVE"/>
    <reference ref_id="SUSE CVE-2003-0252" ref_url="https://www.suse.com/security/cve/CVE-2003-0252" source="SUSE CVE"/>
		<reference ref_id="SuSE-SA:2003:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2003-07/msg00002.html" source="SUSE-SU"/>
    <description>
    Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2003-0252/">CVE-2003-0252</cve>
	<bugzilla href="https://bugzilla.suse.com/42744">SUSE bug 42744</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/42918">SUSE bug 42918</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009667767" comment="nfs-client is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667769" comment="nfs-kernel-server is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20031605" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2003-1605</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2003-1605" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1605" source="CVE"/>
    <reference ref_id="SUSE CVE-2003-1605" ref_url="https://www.suse.com/security/cve/CVE-2003-1605" source="SUSE CVE"/>
    <description>
    curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-15"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.6/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2003-1605/">CVE-2003-1605</cve>
	<bugzilla href="https://bugzilla.suse.com/1105868">SUSE bug 1105868</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333977" comment="curl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335173" comment="libcurl4 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040790" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2004-0790</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2004-0790" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790" source="CVE"/>
    <reference ref_id="SUSE CVE-2004-0790" ref_url="https://www.suse.com/security/cve/CVE-2004-0790" source="SUSE CVE"/>
    <description>
    Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2004-0790/">CVE-2004-0790</cve>
	<bugzilla href="https://bugzilla.suse.com/1173637">SUSE bug 1173637</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173639">SUSE bug 1173639</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173640">SUSE bug 1173640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173642">SUSE bug 1173642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173643">SUSE bug 1173643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173644">SUSE bug 1173644</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173645">SUSE bug 1173645</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20040791" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2004-0791</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2004-0791" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791" source="CVE"/>
    <reference ref_id="SUSE CVE-2004-0791" ref_url="https://www.suse.com/security/cve/CVE-2004-0791" source="SUSE CVE"/>
    <description>
    Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2004-0791/">CVE-2004-0791</cve>
	<bugzilla href="https://bugzilla.suse.com/1173637">SUSE bug 1173637</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173639">SUSE bug 1173639</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173640">SUSE bug 1173640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173642">SUSE bug 1173642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173643">SUSE bug 1173643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173644">SUSE bug 1173644</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173645">SUSE bug 1173645</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20041060" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2004-1060</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2004-1060" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060" source="CVE"/>
    <reference ref_id="SUSE CVE-2004-1060" ref_url="https://www.suse.com/security/cve/CVE-2004-1060" source="SUSE CVE"/>
    <description>
    Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2004-1060/">CVE-2004-1060</cve>
	<bugzilla href="https://bugzilla.suse.com/1173637">SUSE bug 1173637</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173639">SUSE bug 1173639</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173640">SUSE bug 1173640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173642">SUSE bug 1173642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173643">SUSE bug 1173643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173644">SUSE bug 1173644</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173645">SUSE bug 1173645</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050065" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-0065</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-0065" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0065" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-0065" ref_url="https://www.suse.com/security/cve/CVE-2005-0065" source="SUSE CVE"/>
    <description>
    The original design of TCP does not check that the TCP sequence number in an ICMP error message is within the range of sequence numbers for data that has been sent but not acknowledged (aka "TCP sequence number checking"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2005-0065/">CVE-2005-0065</cve>
	<bugzilla href="https://bugzilla.suse.com/1173637">SUSE bug 1173637</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173639">SUSE bug 1173639</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173640">SUSE bug 1173640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173642">SUSE bug 1173642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173643">SUSE bug 1173643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173644">SUSE bug 1173644</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173645">SUSE bug 1173645</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050066" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-0066</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-0066" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0066" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-0066" ref_url="https://www.suse.com/security/cve/CVE-2005-0066" source="SUSE CVE"/>
    <description>
    The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka "TCP acknowledgement number checking"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2005-0066/">CVE-2005-0066</cve>
	<bugzilla href="https://bugzilla.suse.com/1173637">SUSE bug 1173637</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173639">SUSE bug 1173639</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173640">SUSE bug 1173640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173642">SUSE bug 1173642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173643">SUSE bug 1173643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173644">SUSE bug 1173644</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173645">SUSE bug 1173645</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050067" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-0067</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-0067" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0067" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-0067" ref_url="https://www.suse.com/security/cve/CVE-2005-0067" source="SUSE CVE"/>
    <description>
    The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2005-0067/">CVE-2005-0067</cve>
	<bugzilla href="https://bugzilla.suse.com/1173637">SUSE bug 1173637</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173639">SUSE bug 1173639</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173640">SUSE bug 1173640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173642">SUSE bug 1173642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173643">SUSE bug 1173643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173644">SUSE bug 1173644</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173645">SUSE bug 1173645</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050068" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-0068</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-0068" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0068" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-0068" ref_url="https://www.suse.com/security/cve/CVE-2005-0068" source="SUSE CVE"/>
    <description>
    The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2005-0068/">CVE-2005-0068</cve>
	<bugzilla href="https://bugzilla.suse.com/1173637">SUSE bug 1173637</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173639">SUSE bug 1173639</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173640">SUSE bug 1173640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173642">SUSE bug 1173642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173643">SUSE bug 1173643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173644">SUSE bug 1173644</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173645">SUSE bug 1173645</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050210" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-0210</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-0210" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0210" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-0210" ref_url="https://www.suse.com/security/cve/CVE-2005-0210" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2005:018" ref_url="https://lists.opensuse.org/opensuse-security-announce/2005-03/msg00020.html" source="SUSE-SU"/>
    <description>
    Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2005-0210/">CVE-2005-0210</cve>
	<bugzilla href="https://bugzilla.suse.com/65594">SUSE bug 65594</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050400" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-0400</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-0400" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0400" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-0400" ref_url="https://www.suse.com/security/cve/CVE-2005-0400" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2005:029" ref_url="https://lists.opensuse.org/opensuse-security-announce/2005-06/msg00015.html" source="SUSE-SU"/>
    <description>
    The ext2_make_empty function call in the Linux kernel before 2.6.11.6 does not properly initialize memory when creating a block for a new directory entry, which allows local users to obtain potentially sensitive information by reading the block.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2005-0400/">CVE-2005-0400</cve>
	<bugzilla href="https://bugzilla.suse.com/75706">SUSE bug 75706</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20050749" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-0749</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-0749" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0749" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-0749" ref_url="https://www.suse.com/security/cve/CVE-2005-0749" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2005:029" ref_url="https://lists.opensuse.org/opensuse-security-announce/2005-06/msg00015.html" source="SUSE-SU"/>
    <description>
    The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2005-0749/">CVE-2005-0749</cve>
	<bugzilla href="https://bugzilla.suse.com/73837">SUSE bug 73837</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20051265" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-1265</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-1265" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1265" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-1265" ref_url="https://www.suse.com/security/cve/CVE-2005-1265" source="SUSE CVE"/>
    <description>
    The mmap function in the Linux Kernel 2.6.10 can be used to create memory maps with a start address beyond the end address, which allows local users to cause a denial of service (kernel crash).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-21"/>
	<updated date="2023-06-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2005-1265/">CVE-2005-1265</cve>
	<bugzilla href="https://bugzilla.suse.com/84728">SUSE bug 84728</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20051763" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-1763</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-1763" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1763" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-1763" ref_url="https://www.suse.com/security/cve/CVE-2005-1763" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2005:029" ref_url="https://lists.opensuse.org/opensuse-security-announce/2005-06/msg00015.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-21"/>
	<updated date="2023-06-21"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2005-1763/">CVE-2005-1763</cve>
	<bugzilla href="https://bugzilla.suse.com/84078">SUSE bug 84078</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20051767" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-1767</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-1767" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1767" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-1767" ref_url="https://www.suse.com/security/cve/CVE-2005-1767" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2005:044" ref_url="https://lists.opensuse.org/opensuse-security-announce/2005-08/msg00008.html" source="SUSE-SU"/>
    <description>
    traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, which allows local users to cause a denial of service (oops and stack fault exception).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-16"/>
	<updated date="2023-02-16"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2005-1767/">CVE-2005-1767</cve>
	<bugzilla href="https://bugzilla.suse.com/88492">SUSE bug 88492</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/90500">SUSE bug 90500</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20052098" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-2098</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-2098" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2098" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-2098" ref_url="https://www.suse.com/security/cve/CVE-2005-2098" source="SUSE CVE"/>
    <description>
    The KEYCTL_JOIN_SESSION_KEYRING operation in the Linux kernel before 2.6.12.5 contains an error path that does not properly release the session management semaphore, which allows local users or remote attackers to cause a denial of service (semaphore hang) via a new session keyring (1) with an empty name string, (2) with a long name string, (3) with the key quota reached, or (4) ENOMEM.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-21"/>
	<updated date="2023-06-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2005-2098/">CVE-2005-2098</cve>
	<bugzilla href="https://bugzilla.suse.com/100506">SUSE bug 100506</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20052458" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-2458</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-2458" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2458" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-2458" ref_url="https://www.suse.com/security/cve/CVE-2005-2458" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2005:050" ref_url="https://lists.opensuse.org/opensuse-security-announce/2005-09/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2005:068" ref_url="https://lists.opensuse.org/opensuse-security-announce/2005-12/msg00011.html" source="SUSE-SU"/>
    <description>
    inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 allows remote attackers to cause a denial of service (kernel crash) via a compressed file with "improper tables".
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2005-2458/">CVE-2005-2458</cve>
	<bugzilla href="https://bugzilla.suse.com/100428">SUSE bug 100428</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/102323">SUSE bug 102323</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/104085">SUSE bug 104085</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/114364">SUSE bug 114364</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/117169">SUSE bug 117169</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/130270">SUSE bug 130270</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/132739">SUSE bug 132739</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/133577">SUSE bug 133577</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/133972">SUSE bug 133972</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20052492" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-2492</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-2492" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2492" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-2492" ref_url="https://www.suse.com/security/cve/CVE-2005-2492" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2005:068" ref_url="https://lists.opensuse.org/opensuse-security-announce/2005-12/msg00011.html" source="SUSE-SU"/>
    <description>
    The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-02"/>
	<updated date="2023-07-02"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2005-2492/">CVE-2005-2492</cve>
	<bugzilla href="https://bugzilla.suse.com/114365">SUSE bug 114365</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20053623" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-3623</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-3623" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3623" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-3623" ref_url="https://www.suse.com/security/cve/CVE-2005-3623" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2006:006" ref_url="https://lists.opensuse.org/opensuse-security-announce/2006-02/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2006:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2006-02/msg00021.html" source="SUSE-SU"/>
    <description>
    nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs for readonly mounted NFS filesystems.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-07"/>
	<updated date="2023-07-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2005-3623/">CVE-2005-3623</cve>
	<bugzilla href="https://bugzilla.suse.com/139411">SUSE bug 139411</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20054881" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2005-4881</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2005-4881" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4881" source="CVE"/>
    <reference ref_id="SUSE CVE-2005-4881" ref_url="https://www.suse.com/security/cve/CVE-2005-4881" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:061" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:064" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html" source="SUSE-SU"/>
    <description>
    The netlink subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.13-rc1 does not initialize certain padding fields in structures, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors, related to the (1) tc_fill_qdisc, (2) tcf_fill_node, (3) neightbl_fill_info, (4) neightbl_fill_param_info, (5) neigh_fill_info, (6) rtnetlink_fill_ifinfo, (7) rtnetlink_fill_iwinfo, (8) vif_delete, (9) ipmr_destroy_unres, (10) ipmr_cache_alloc_unres, (11) ipmr_cache_resolve, (12) inet6_fill_ifinfo, (13) tca_get_fill, (14) tca_action_flush, (15) tcf_add_notify, (16) tc_dump_action, (17) cbq_dump_police, (18) __nlmsg_put, (19) __rta_fill, (20) __rta_reserve, (21) inet6_fill_prefix, (22) rsvp_dump, and (23) cbq_dump_ovl functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-05"/>
	<updated date="2023-04-05"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2005-4881/">CVE-2005-4881</cve>
	<bugzilla href="https://bugzilla.suse.com/536467">SUSE bug 536467</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20063635" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2006-3635</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2006-3635" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3635" source="CVE"/>
    <reference ref_id="SUSE CVE-2006-3635" ref_url="https://www.suse.com/security/cve/CVE-2006-3635" source="SUSE CVE"/>
    <description>
    The ia64 subsystem in the Linux kernel before 2.6.26 allows local users to cause a denial of service (stack consumption and system crash) via a crafted application that leverages the mishandling of invalid Register Stack Engine (RSE) state.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-08"/>
	<updated date="2023-07-08"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2006-3635/">CVE-2006-3635</cve>
	<bugzilla href="https://bugzilla.suse.com/199440">SUSE bug 199440</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/199441">SUSE bug 199441</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20064623" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2006-4623</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2006-4623" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4623" source="CVE"/>
    <reference ref_id="SUSE CVE-2006-4623" ref_url="https://www.suse.com/security/cve/CVE-2006-4623" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2006:079" ref_url="https://lists.opensuse.org/opensuse-security-announce/2006-12/msg00018.html" source="SUSE-SU"/>
    <description>
    The Unidirectional Lightweight Encapsulation (ULE) decapsulation component in dvb-core/dvb_net.c in the dvb driver in the Linux kernel 2.6.17.8 allows remote attackers to cause a denial of service (crash) via an SNDU length of 0 in a ULE packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2006-4623/">CVE-2006-4623</cve>
	<bugzilla href="https://bugzilla.suse.com/201429">SUSE bug 201429</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20064814" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2006-4814</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2006-4814" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4814" source="CVE"/>
    <reference ref_id="SUSE CVE-2006-4814" ref_url="https://www.suse.com/security/cve/CVE-2006-4814" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:018" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-02/msg00009.html" source="SUSE-SU"/>
    <description>
    The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlock.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2006-4814/">CVE-2006-4814</cve>
	<bugzilla href="https://bugzilla.suse.com/207667">SUSE bug 207667</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20065701" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2006-5701</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2006-5701" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5701" source="CVE"/>
    <reference ref_id="SUSE CVE-2006-5701" ref_url="https://www.suse.com/security/cve/CVE-2006-5701" source="SUSE CVE"/>
    <description>
    Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and possibly other distributions, allows local users to cause a denial of service by mounting a crafted squashfs filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-02"/>
	<updated date="2023-07-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2006-5701/">CVE-2006-5701</cve>
	<bugzilla href="https://bugzilla.suse.com/218162">SUSE bug 218162</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20065751" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2006-5751</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2006-5751" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5751" source="CVE"/>
    <reference ref_id="SUSE CVE-2006-5751" ref_url="https://www.suse.com/security/cve/CVE-2006-5751" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2006:079" ref_url="https://lists.opensuse.org/opensuse-security-announce/2006-12/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2007:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-03/msg00009.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the get_fdb_entries function in net/bridge/br_ioctl.c in the Linux kernel before 2.6.18.4 allows local users to execute arbitrary code via a large maxnum value in an ioctl request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2006-5751/">CVE-2006-5751</cve>
	<bugzilla href="https://bugzilla.suse.com/222656">SUSE bug 222656</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20065794" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2006-5794</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2006-5794" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5794" source="CVE"/>
    <reference ref_id="SUSE CVE-2006-5794" ref_url="https://www.suse.com/security/cve/CVE-2006-5794" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2006:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2006-11/msg00020.html" source="SUSE-SU"/>
    <description>
    Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authentication. NOTE: as of 20061108, it is believed that this issue is only exploitable by leveraging vulnerabilities in the unprivileged process, which are not known to exist.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2006-5794/">CVE-2006-5794</cve>
	<bugzilla href="https://bugzilla.suse.com/219115">SUSE bug 219115</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333996" comment="openssh is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20066106" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2006-6106</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2006-6106" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6106" source="CVE"/>
    <reference ref_id="SUSE CVE-2006-6106" ref_url="https://www.suse.com/security/cve/CVE-2006-6106" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:018" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-02/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2007:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-03/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2007:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-05/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2007:035" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-06/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2007:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-10/msg00000.html" source="SUSE-SU"/>
    <description>
    Multiple buffer overflows in the cmtp_recv_interopmsg function in the Bluetooth driver (net/bluetooth/cmtp/capi.c) in the Linux kernel 2.4.22 up to 2.4.33.4 and 2.6.2 before 2.6.18.6, and 2.6.19.x, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via CAPI messages with a large value for the length of the (1) manu (manufacturer) or (2) serial (serial number) field.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2006-6106/">CVE-2006-6106</cve>
	<bugzilla href="https://bugzilla.suse.com/227603">SUSE bug 227603</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20067246" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2006-7246</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2006-7246" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7246" source="CVE"/>
    <reference ref_id="SUSE CVE-2006-7246" ref_url="https://www.suse.com/security/cve/CVE-2006-7246" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-11/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-February/000033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:1273-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00025.html" source="SUSE-SU"/>
    <description>
    NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2006-7246/">CVE-2006-7246</cve>
	<bugzilla href="https://bugzilla.suse.com/1047509">SUSE bug 1047509</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1047511">SUSE bug 1047511</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/574266">SUSE bug 574266</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/777228">SUSE bug 777228</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760817" comment="libnm0-1.22.10-3.3.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760818" comment="typelib-1_0-NM-1_0-1.22.10-3.3.4 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20070005" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-0005</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-0005" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0005" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-0005" ref_url="https://www.suse.com/security/cve/CVE-2007-0005" source="SUSE CVE"/>
    <description>
    Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2007-0005/">CVE-2007-0005</cve>
	<bugzilla href="https://bugzilla.suse.com/242996">SUSE bug 242996</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20071496" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-1496</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-1496" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1496" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-1496" ref_url="https://www.suse.com/security/cve/CVE-2007-1496" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:043" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-07/msg00005.html" source="SUSE-SU"/>
    <description>
    nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "multiple packets per netlink message", and (3) bridged packets, which trigger a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2007-1496/">CVE-2007-1496</cve>
	<bugzilla href="https://bugzilla.suse.com/270458">SUSE bug 270458</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20071497" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-1497</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-1497" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1497" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-1497" ref_url="https://www.suse.com/security/cve/CVE-2007-1497" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:043" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-07/msg00005.html" source="SUSE-SU"/>
    <description>
    nf_conntrack in netfilter in the Linux kernel before 2.6.20.3 does not set nfctinfo during reassembly of fragmented packets, which leaves the default value as IP_CT_ESTABLISHED and might allow remote attackers to bypass certain rulesets using IPv6 fragments.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2007-1497/">CVE-2007-1497</cve>
	<bugzilla href="https://bugzilla.suse.com/268298">SUSE bug 268298</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/270460">SUSE bug 270460</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20072875" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-2875</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-2875" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2875" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-2875" ref_url="https://www.suse.com/security/cve/CVE-2007-2875" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-10/msg00000.html" source="SUSE-SU"/>
    <description>
    Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-09"/>
	<updated date="2023-07-09"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2007-2875/">CVE-2007-2875</cve>
	<bugzilla href="https://bugzilla.suse.com/280819">SUSE bug 280819</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20072878" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-2878</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-2878" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2878" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-2878" ref_url="https://www.suse.com/security/cve/CVE-2007-2878" source="SUSE CVE"/>
    <description>
    The VFAT compat ioctls in the Linux kernel before 2.6.21.2, when run on a 64-bit system, allow local users to corrupt a kernel_dirent struct and cause a denial of service (system crash) via unknown vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2007-2878/">CVE-2007-2878</cve>
	<bugzilla href="https://bugzilla.suse.com/280888">SUSE bug 280888</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20073104" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-3104</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-3104" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3104" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-3104" ref_url="https://www.suse.com/security/cve/CVE-2007-3104" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:064" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-12/msg00001.html" source="SUSE-SU"/>
    <description>
    The sysfs_readdir function in the Linux kernel 2.6, as used in Red Hat Enterprise Linux (RHEL) 4.5 and other distributions, allows users to cause a denial of service (kernel OOPS) by dereferencing a null pointer to an inode in a dentry.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-21"/>
	<updated date="2023-05-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2007-3104/">CVE-2007-3104</cve>
	<bugzilla href="https://bugzilla.suse.com/329758">SUSE bug 329758</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20073107" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-3107</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-3107" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3107" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-3107" ref_url="https://www.suse.com/security/cve/CVE-2007-3107" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:051" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2007:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-10/msg00000.html" source="SUSE-SU"/>
    <description>
    The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2007-3107/">CVE-2007-3107</cve>
	<bugzilla href="https://bugzilla.suse.com/290622">SUSE bug 290622</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/329765">SUSE bug 329765</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20073513" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-3513</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-3513" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3513" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-3513" ref_url="https://www.suse.com/security/cve/CVE-2007-3513" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:051" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2007:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-10/msg00000.html" source="SUSE-SU"/>
    <description>
    The lcd_write function in drivers/usb/misc/usblcd.c in the Linux kernel before 2.6.22-rc7 does not limit the amount of memory used by a caller, which allows local users to cause a denial of service (memory consumption).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2007-3513/">CVE-2007-3513</cve>
	<bugzilla href="https://bugzilla.suse.com/293092">SUSE bug 293092</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20073719" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-3719</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-3719" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3719" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-3719" ref_url="https://www.suse.com/security/cve/CVE-2007-3719" source="SUSE CVE"/>
    <description>
    The process scheduler in the Linux kernel 2.6.16 gives preference to "interactive" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuser Privileges."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2007-3719/">CVE-2007-3719</cve>
	<bugzilla href="https://bugzilla.suse.com/291701">SUSE bug 291701</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20073851" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-3851</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-3851" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3851" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-3851" ref_url="https://www.suse.com/security/cve/CVE-2007-3851" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:051" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2007:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-10/msg00000.html" source="SUSE-SU"/>
    <description>
    The drm/i915 component in the Linux kernel before 2.6.22.2, when used with i965G and later chipsets, allows local users with access to an X11 session and Direct Rendering Manager (DRM) to write to arbitrary memory locations and gain privileges via a crafted batchbuffer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2007-3851/">CVE-2007-3851</cve>
	<bugzilla href="https://bugzilla.suse.com/298309">SUSE bug 298309</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20074308" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-4308</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-4308" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4308" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-4308" ref_url="https://www.suse.com/security/cve/CVE-2007-4308" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:064" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:006" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-03/msg00007.html" source="SUSE-SU"/>
    <description>
    The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users to cause a denial of service or gain privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2007-4308/">CVE-2007-4308</cve>
	<bugzilla href="https://bugzilla.suse.com/326270">SUSE bug 326270</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/329764">SUSE bug 329764</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20074567" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-4567</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-4567" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4567" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-4567" ref_url="https://www.suse.com/security/cve/CVE-2007-4567" source="SUSE CVE"/>
    <description>
    The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted IPv6 packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2007-4567/">CVE-2007-4567</cve>
	<bugzilla href="https://bugzilla.suse.com/307626">SUSE bug 307626</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/570608">SUSE bug 570608</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20074571" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-4571</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-4571" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4571" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-4571" ref_url="https://www.suse.com/security/cve/CVE-2007-4571" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-10/msg00000.html" source="SUSE-SU"/>
    <description>
    The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2007-4571/">CVE-2007-4571</cve>
	<bugzilla href="https://bugzilla.suse.com/328404">SUSE bug 328404</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20074774" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-4774</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-4774" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4774" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-4774" ref_url="https://www.suse.com/security/cve/CVE-2007-4774" source="SUSE CVE"/>
    <description>
    The Linux kernel before 2.4.36-rc1 has a race condition. It was possible to bypass systrace policies by flooding the ptraced process with SIGCONT signals, which can can wake up a PTRACED process.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2007-4774/">CVE-2007-4774</cve>
	<bugzilla href="https://bugzilla.suse.com/1161116">SUSE bug 1161116</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20075966" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-5966</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-5966" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5966" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-5966" ref_url="https://www.suse.com/security/cve/CVE-2007-5966" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:006" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="TID7002558" ref_url="https://www.suse.com/support/kb/doc?id=7002558" source="SUSE-SU"/>
    <description>
    Integer overflow in the hrtimer_start function in kernel/hrtimer.c in the Linux kernel before 2.6.23.10 allows local users to execute arbitrary code or cause a denial of service (panic) via a large relative timeout value. NOTE: some of these details are obtained from third party information.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2007-5966/">CVE-2007-5966</cve>
	<bugzilla href="https://bugzilla.suse.com/347262">SUSE bug 347262</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/512584">SUSE bug 512584</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20076063" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-6063</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-6063" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6063" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-6063" ref_url="https://www.suse.com/security/cve/CVE-2007-6063" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2007:064" ref_url="https://lists.opensuse.org/opensuse-security-announce/2007-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:006" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the isdn_net_setcfg function in isdn_net.c in Linux kernel 2.6.23 allows local users to have an unknown impact via a crafted argument to the isdn_ioctl function.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2007-6063/">CVE-2007-6063</cve>
	<bugzilla href="https://bugzilla.suse.com/343210">SUSE bug 343210</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20076206" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-6206</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-6206" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6206" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-6206" ref_url="https://www.suse.com/security/cve/CVE-2007-6206" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:032" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:036" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00001.html" source="SUSE-SU"/>
    <description>
    The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-16"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2007-6206/">CVE-2007-6206</cve>
	<bugzilla href="https://bugzilla.suse.com/342686">SUSE bug 342686</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20076716" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-6716</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-6716" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6716" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-6716" ref_url="https://www.suse.com/security/cve/CVE-2007-6716" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:047" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:051" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:056" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-12/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2008:025" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html" source="SUSE-SU"/>
    <description>
    fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-08"/>
	<updated date="2023-07-08"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2007-6716/">CVE-2007-6716</cve>
	<bugzilla href="https://bugzilla.suse.com/422963">SUSE bug 422963</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20076762" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2007-6762</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2007-6762" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6762" source="CVE"/>
    <reference ref_id="SUSE CVE-2007-6762" ref_url="https://www.suse.com/security/cve/CVE-2007-6762" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 2.6.20, there is an off-by-one bug in net/netlabel/netlabel_cipso_v4.c where it is possible to overflow the doi_def-&gt;tags[] array.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2007-6762/">CVE-2007-6762</cve>
	<bugzilla href="https://bugzilla.suse.com/1143172">SUSE bug 1143172</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20080007" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-0007</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-0007" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0007" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-0007" ref_url="https://www.suse.com/security/cve/CVE-2008-0007" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:006" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-03/msg00007.html" source="SUSE-SU"/>
    <description>
    Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-0007/">CVE-2008-0007</cve>
	<bugzilla href="https://bugzilla.suse.com/353207">SUSE bug 353207</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20080009" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-0009</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-0009" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0009" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-0009" ref_url="https://www.suse.com/security/cve/CVE-2008-0009" source="SUSE CVE"/>
    <description>
    The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-0009/">CVE-2008-0009</cve>
	<bugzilla href="https://bugzilla.suse.com/358006">SUSE bug 358006</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20080352" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-0352</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-0352" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0352" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-0352" ref_url="https://www.suse.com/security/cve/CVE-2008-0352" source="SUSE CVE"/>
    <description>
    The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-0352/">CVE-2008-0352</cve>
	<bugzilla href="https://bugzilla.suse.com/307626">SUSE bug 307626</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20081367" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-1367</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-1367" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1367" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-1367" ref_url="https://www.suse.com/security/cve/CVE-2008-1367" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-07/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:032" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-07/msg00002.html" source="SUSE-SU"/>
    <description>
    gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction flag (DF) from being reset in violation of ABI conventions and cause data to be copied in the wrong direction during signal handling in the Linux kernel, which might allow context-dependent attackers to trigger memory corruption. NOTE: this issue was originally reported for CPU consumption in SBCL.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-1367/">CVE-2008-1367</cve>
	<bugzilla href="https://bugzilla.suse.com/369911">SUSE bug 369911</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/372038">SUSE bug 372038</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20081420" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-1420</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-1420" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1420" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-1420" ref_url="https://www.suse.com/security/cve/CVE-2008-1420" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2008:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html" source="SUSE-SU"/>
    <description>
    Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-1420/">CVE-2008-1420</cve>
	<bugzilla href="https://bugzilla.suse.com/372246">SUSE bug 372246</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481533" comment="libvorbis0-1.3.6-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481534" comment="libvorbisenc2-1.3.6-4.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20081483" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-1483</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-1483" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1483" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-1483" ref_url="https://www.suse.com/security/cve/CVE-2008-1483" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2008:009" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-December/003476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004398.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004564.html" source="SUSE-SU"/>
		<reference ref_id="TID7005435" ref_url="https://www.suse.com/support/kb/doc/?id=7005435" source="SUSE-SU"/>
		<reference ref_id="TID7022102" ref_url="https://www.suse.com/support/kb/doc/?id=7022102" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3243-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-12/msg00032.html" source="SUSE-SU"/>
    <description>
    OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2008-1483/">CVE-2008-1483</cve>
	<bugzilla href="https://bugzilla.suse.com/1069509">SUSE bug 1069509</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/373527">SUSE bug 373527</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/585630">SUSE bug 585630</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/647633">SUSE bug 647633</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/706386">SUSE bug 706386</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333996" comment="openssh is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20082358" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-2358</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-2358" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2358" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-2358" ref_url="https://www.suse.com/security/cve/CVE-2008-2358" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-06/msg00006.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-12"/>
	<updated date="2023-07-12"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-2358/">CVE-2008-2358</cve>
	<bugzilla href="https://bugzilla.suse.com/387819">SUSE bug 387819</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20082365" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-2365</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-2365" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2365" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-2365" ref_url="https://www.suse.com/security/cve/CVE-2008-2365" source="SUSE CVE"/>
    <description>
    Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptrace_may_attach() check" and "race around &amp;dead_engine_ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this issue might only affect kernel versions before 2.6.16.x.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-2365/">CVE-2008-2365</cve>
	<bugzilla href="https://bugzilla.suse.com/404288">SUSE bug 404288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20082544" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-2544</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-2544" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2544" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-2544" ref_url="https://www.suse.com/security/cve/CVE-2008-2544" source="SUSE CVE"/>
    <description>
    Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot environment and gain write access to files, he would never have otherwise.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2008-2544/">CVE-2008-2544</cve>
	<bugzilla href="https://bugzilla.suse.com/1189500">SUSE bug 1189500</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20082750" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-2750</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-2750" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2750" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-2750" ref_url="https://www.suse.com/security/cve/CVE-2008-2750" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:037" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.html" source="SUSE-SU"/>
    <description>
    The pppol2tp_recvmsg function in drivers/net/pppol2tp.c in the Linux kernel 2.6 before 2.6.26-rc6 allows remote attackers to cause a denial of service (kernel heap memory corruption and system crash) and possibly have unspecified other impact via a crafted PPPOL2TP packet that results in a large value for a certain length variable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-2750/">CVE-2008-2750</cve>
	<bugzilla href="https://bugzilla.suse.com/400874">SUSE bug 400874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20082812" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-2812</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-2812" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2812" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-2812" ref_url="https://www.suse.com/security/cve/CVE-2008-2812" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:035" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-07/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:037" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:047" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:049" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2008:025" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html" source="SUSE-SU"/>
    <description>
    The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2008-2812/">CVE-2008-2812</cve>
	<bugzilla href="https://bugzilla.suse.com/1175688">SUSE bug 1175688</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/405017">SUSE bug 405017</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20082826" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-2826</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-2826" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2826" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-2826" ref_url="https://www.suse.com/security/cve/CVE-2008-2826" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:037" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and system outage) via vectors involving a large addr_num field in an sctp_getaddrs_old data structure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-09"/>
	<updated date="2023-07-09"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-2826/">CVE-2008-2826</cve>
	<bugzilla href="https://bugzilla.suse.com/402607">SUSE bug 402607</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20082931" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-2931</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-2931" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2931" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-2931" ref_url="https://www.suse.com/security/cve/CVE-2008-2931" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:035" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-07/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:049" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2008:025" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html" source="SUSE-SU"/>
    <description>
    The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2008-2931/">CVE-2008-2931</cve>
	<bugzilla href="https://bugzilla.suse.com/1175780">SUSE bug 1175780</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/407428">SUSE bug 407428</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083247" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-3247</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-3247" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3247" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-3247" ref_url="https://www.suse.com/security/cve/CVE-2008-3247" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:037" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-07/msg00009.html" source="SUSE-SU"/>
    <description>
    The LDT implementation in the Linux kernel 2.6.25.x before 2.6.25.11 on x86_64 platforms uses an incorrect size for ldt_desc, which allows local users to cause a denial of service (system crash) or possibly gain privileges via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-07"/>
	<updated date="2023-07-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-3247/">CVE-2008-3247</cve>
	<bugzilla href="https://bugzilla.suse.com/408734">SUSE bug 408734</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/432488">SUSE bug 432488</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083275" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-3275</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-3275" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3275" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-3275" ref_url="https://www.suse.com/security/cve/CVE-2008-3275" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:044" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-09/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:048" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:049" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:036" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00001.html" source="SUSE-SU"/>
    <description>
    The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denial of service ("overflow" of the UBIFS orphan area) via a series of attempted file creations within deleted directories.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2008-3275/">CVE-2008-3275</cve>
	<bugzilla href="https://bugzilla.suse.com/413936">SUSE bug 413936</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083496" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-3496</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-3496" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3496" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-3496" ref_url="https://www.suse.com/security/cve/CVE-2008-3496" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2008:018" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2008-3496/">CVE-2008-3496</cve>
	<bugzilla href="https://bugzilla.suse.com/415702">SUSE bug 415702</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083526" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-3526</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-3526" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3526" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-3526" ref_url="https://www.suse.com/security/cve/CVE-2008-3526" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.24-rc1 through 2.6.26.3 allows remote attackers to cause a denial of service (panic) or possibly have unspecified other impact via a crafted sca_keylength field associated with the SCTP_AUTH_KEY option.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-3526/">CVE-2008-3526</cve>
	<bugzilla href="https://bugzilla.suse.com/421003">SUSE bug 421003</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083527" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-3527</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-3527" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3527" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-3527" ref_url="https://www.suse.com/security/cve/CVE-2008-3527" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2008:025" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html" source="SUSE-SU"/>
    <description>
    arch/i386/kernel/sysenter.c in the Virtual Dynamic Shared Objects (vDSO) implementation in the Linux kernel before 2.6.21 does not properly check boundaries, which allows local users to gain privileges or cause a denial of service via unspecified vectors, related to the install_special_mapping, syscall, and syscall32_nopage functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-3527/">CVE-2008-3527</cve>
	<bugzilla href="https://bugzilla.suse.com/437689">SUSE bug 437689</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083528" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-3528</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-3528" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3528" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-3528" ref_url="https://www.suse.com/security/cve/CVE-2008-3528" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:051" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:056" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-12/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:057" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2008:025" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html" source="SUSE-SU"/>
    <description>
    The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir-&gt;i_size and dir-&gt;i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-3528/">CVE-2008-3528</cve>
	<bugzilla href="https://bugzilla.suse.com/427244">SUSE bug 427244</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083534" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-3534</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-3534" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3534" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-3534" ref_url="https://www.suse.com/security/cve/CVE-2008-3534" source="SUSE CVE"/>
    <description>
    The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as demonstrated by the insserv program, related to allocation of "useless pages" and improper maintenance of the i_blocks count.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-07"/>
	<updated date="2023-07-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-3534/">CVE-2008-3534</cve>
	<bugzilla href="https://bugzilla.suse.com/414257">SUSE bug 414257</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083792" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-3792</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-3792" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3792" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-3792" ref_url="https://www.suse.com/security/cve/CVE-2008-3792" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html" source="SUSE-SU"/>
    <description>
    net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to cause a denial of service (NULL pointer dereference and panic) via vectors that result in calls to (1) sctp_setsockopt_auth_chunk, (2) sctp_setsockopt_hmac_ident, (3) sctp_setsockopt_auth_key, (4) sctp_setsockopt_active_key, (5) sctp_setsockopt_del_key, (6) sctp_getsockopt_maxburst, (7) sctp_getsockopt_active_key, (8) sctp_getsockopt_peer_auth_chunks, or (9) sctp_getsockopt_local_auth_chunks.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-3792/">CVE-2008-3792</cve>
	<bugzilla href="https://bugzilla.suse.com/423541">SUSE bug 423541</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083831" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-3831</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-3831" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3831" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-3831" ref_url="https://www.suse.com/security/cve/CVE-2008-3831" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:003" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00005.html" source="SUSE-SU"/>
    <description>
    The i915 driver in (1) drivers/char/drm/i915_dma.c in the Linux kernel 2.6.24 on Debian GNU/Linux and (2) sys/dev/pci/drm/i915_drv.c in OpenBSD does not restrict the DRM_I915_HWS_ADDR ioctl to the Direct Rendering Manager (DRM) master, which allows local users to cause a denial of service (memory corruption) via a crafted ioctl call, related to absence of the DRM_MASTER and DRM_ROOT_ONLY flags in the ioctl's configuration.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-21"/>
	<updated date="2023-02-21"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-3831/">CVE-2008-3831</cve>
	<bugzilla href="https://bugzilla.suse.com/429919">SUSE bug 429919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083833" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-3833</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-3833" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3833" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-3833" ref_url="https://www.suse.com/security/cve/CVE-2008-3833" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2008:025" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html" source="SUSE-SU"/>
    <description>
    The generic_file_splice_write function in fs/splice.c in the Linux kernel before 2.6.19 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by splicing into an inode in order to create an executable file in a setgid directory, a different vulnerability than CVE-2008-4210.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-3833/">CVE-2008-3833</cve>
	<bugzilla href="https://bugzilla.suse.com/432487">SUSE bug 432487</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20083915" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-3915</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-3915" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3915" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-3915" ref_url="https://www.suse.com/security/cve/CVE-2008-3915" source="SUSE CVE"/>
    <description>
    Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2008-3915/">CVE-2008-3915</cve>
	<bugzilla href="https://bugzilla.suse.com/423515">SUSE bug 423515</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084113" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-4113</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-4113" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4113" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-4113" ref_url="https://www.suse.com/security/cve/CVE-2008-4113" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html" source="SUSE-SU"/>
    <description>
    The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit copying of data from kernel memory, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-4113/">CVE-2008-4113</cve>
	<bugzilla href="https://bugzilla.suse.com/429781">SUSE bug 429781</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/432898">SUSE bug 432898</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084210" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-4210</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-4210" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4210" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-4210" ref_url="https://www.suse.com/security/cve/CVE-2008-4210" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:051" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:056" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-12/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2008:057" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2008:025" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html" source="SUSE-SU"/>
    <description>
    fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-22"/>
	<updated date="2023-05-22"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-4210/">CVE-2008-4210</cve>
	<bugzilla href="https://bugzilla.suse.com/429478">SUSE bug 429478</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/432487">SUSE bug 432487</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084302" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-4302</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-4302" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4302" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-4302" ref_url="https://www.suse.com/security/cve/CVE-2008-4302" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2008:025" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html" source="SUSE-SU"/>
    <description>
    fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-07"/>
	<updated date="2023-07-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-4302/">CVE-2008-4302</cve>
	<bugzilla href="https://bugzilla.suse.com/427651">SUSE bug 427651</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084307" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-4307</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-4307" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4307" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-4307" ref_url="https://www.suse.com/security/cve/CVE-2008-4307" source="SUSE CVE"/>
    <description>
    Race condition in the do_setlk function in fs/nfs/file.c in the Linux kernel before 2.6.26 allows local users to cause a denial of service (crash) via vectors resulting in an interrupted RPC call that leads to a stray FL_POSIX lock, related to improper handling of a race between fcntl and close in the EINTR case.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2008-4307/">CVE-2008-4307</cve>
	<bugzilla href="https://bugzilla.suse.com/465672">SUSE bug 465672</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084409" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-4409</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-4409" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4409" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-4409" ref_url="https://www.suse.com/security/cve/CVE-2008-4409" source="SUSE CVE"/>
    <description>
    libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-11"/>
	<updated date="2023-07-11"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-4409/">CVE-2008-4409</cve>
	<bugzilla href="https://bugzilla.suse.com/432486">SUSE bug 432486</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009337751" comment="libxml2-2 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009337752" comment="libxml2-tools is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084445" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-4445</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-4445" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4445" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-4445" ref_url="https://www.suse.com/security/cve/CVE-2008-4445" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-10/msg00010.html" source="SUSE-SU"/>
    <description>
    The sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, does not verify that the identifier index is within the bounds established by SCTP_AUTH_HMAC_ID_MAX, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function, a different vulnerability than CVE-2008-4113.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-4445/">CVE-2008-4445</cve>
	<bugzilla href="https://bugzilla.suse.com/432898">SUSE bug 432898</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20084554" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-4554</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-4554" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4554" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-4554" ref_url="https://www.suse.com/security/cve/CVE-2008-4554" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:003" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
    <description>
    The do_splice_from function in fs/splice.c in the Linux kernel before 2.6.27 does not reject file descriptors that have the O_APPEND flag set, which allows local users to bypass append mode and make arbitrary changes to other locations in the file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-11"/>
	<updated date="2023-07-11"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-4554/">CVE-2008-4554</cve>
	<bugzilla href="https://bugzilla.suse.com/435151">SUSE bug 435151</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085029" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-5029</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-5029" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5029" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-5029" ref_url="https://www.suse.com/security/cve/CVE-2008-5029" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2008:057" ref_url="https://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:003" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html" source="SUSE-SU"/>
    <description>
    The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2008-5029/">CVE-2008-5029</cve>
	<bugzilla href="https://bugzilla.suse.com/442364">SUSE bug 442364</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/449739">SUSE bug 449739</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085079" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-5079</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-5079" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5079" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-5079" ref_url="https://www.suse.com/security/cve/CVE-2008-5079" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:003" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE-SU"/>
    <description>
    net/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier allows local users to cause a denial of service (kernel infinite loop) by making two calls to svc_listen for the same socket, and then reading a /proc/net/atm/*vc file, related to corruption of the vcc table.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-05"/>
	<updated date="2023-07-05"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2008-5079/">CVE-2008-5079</cve>
	<bugzilla href="https://bugzilla.suse.com/450417">SUSE bug 450417</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085700" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-5700</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-5700" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5700" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-5700" ref_url="https://www.suse.com/security/cve/CVE-2008-5700" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:003" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE-SU"/>
    <description>
    libata in the Linux kernel before 2.6.27.9 does not set minimum timeouts for SG_IO requests, which allows local users to cause a denial of service (Programmed I/O mode on drives) via multiple simultaneous invocations of an unspecified test program.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-06"/>
	<updated date="2023-07-06"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2008-5700/">CVE-2008-5700</cve>
	<bugzilla href="https://bugzilla.suse.com/457896">SUSE bug 457896</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20085702" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2008-5702</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2008-5702" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5702" source="CVE"/>
    <reference ref_id="SUSE CVE-2008-5702" ref_url="https://www.suse.com/security/cve/CVE-2008-5702" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:003" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
    <description>
    Buffer underflow in the ibwdt_ioctl function in drivers/watchdog/ib700wdt.c in the Linux kernel before 2.6.28-rc1 might allow local users to have an unknown impact via a certain /dev/watchdog WDIOC_SETTIMEOUT IOCTL call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-12"/>
	<updated date="2023-07-12"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2008-5702/">CVE-2008-5702</cve>
	<bugzilla href="https://bugzilla.suse.com/457898">SUSE bug 457898</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090024" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0024</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0024" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0024" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0024" ref_url="https://www.suse.com/security/cve/CVE-2009-0024" source="SUSE CVE"/>
    <description>
    The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileges via unspecified vectors, related to the vm_file structure member, and the mmap_region and do_munmap functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-0024/">CVE-2009-0024</cve>
	<bugzilla href="https://bugzilla.suse.com/464050">SUSE bug 464050</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090029" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0029</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0029" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0029" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0029" ref_url="https://www.suse.com/security/cve/CVE-2009-0029" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE-SU"/>
    <description>
    The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms requires that a 32-bit argument in a 64-bit register was properly sign extended when sent from a user-mode application, but cannot verify this, which allows local users to cause a denial of service (crash) or possibly gain privileges via a crafted system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-0029/">CVE-2009-0029</cve>
	<bugzilla href="https://bugzilla.suse.com/466015">SUSE bug 466015</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090065" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0065</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0065" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0065" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0065" ref_url="https://www.suse.com/security/cve/CVE-2009-0065" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 allows remote attackers to have an unknown impact via an FWD-TSN (aka FORWARD-TSN) chunk with a large stream ID.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2009-0065/">CVE-2009-0065</cve>
	<bugzilla href="https://bugzilla.suse.com/463522">SUSE bug 463522</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090269" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0269</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0269" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0269" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0269" ref_url="https://www.suse.com/security/cve/CVE-2009-0269" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
    <description>
    fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to use of a -1 return value as an array index.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-0269/">CVE-2009-0269</cve>
	<bugzilla href="https://bugzilla.suse.com/470942">SUSE bug 470942</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090316" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0316</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0316" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0316" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0316" ref_url="https://www.suse.com/security/cve/CVE-2009-0316" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-0316/">CVE-2009-0316</cve>
	<bugzilla href="https://bugzilla.suse.com/470100">SUSE bug 470100</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760864" comment="vim-data-common-8.0.1568-5.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760865" comment="vim-small-8.0.1568-5.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090322" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0322</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0322" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0322" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0322" ref_url="https://www.suse.com/security/cve/CVE-2009-0322" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
    <description>
    drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-0322/">CVE-2009-0322</cve>
	<bugzilla href="https://bugzilla.suse.com/470943">SUSE bug 470943</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090342" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0342</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0342" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0342" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0342" ref_url="https://www.suse.com/security/cve/CVE-2009-0342" source="SUSE CVE"/>
    <description>
    Niels Provos Systrace before 1.6f on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 64-bit syscall with a syscall number that corresponds to a policy-compliant 32-bit syscall.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-0342/">CVE-2009-0342</cve>
	<bugzilla href="https://bugzilla.suse.com/483819">SUSE bug 483819</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/483820">SUSE bug 483820</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090676" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0676</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0676" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0676" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0676" ref_url="https://www.suse.com/security/cve/CVE-2009-0676" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-08/msg00007.html" source="SUSE-SU"/>
    <description>
    The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2009-0676/">CVE-2009-0676</cve>
	<bugzilla href="https://bugzilla.suse.com/478002">SUSE bug 478002</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090745" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0745</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0745" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0745" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0745" ref_url="https://www.suse.com/security/cve/CVE-2009-0745" source="SUSE CVE"/>
    <description>
    The ext4_group_add function in fs/ext4/resize.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not properly initialize the group descriptor during a resize (aka resize2fs) operation, which might allow local users to cause a denial of service (OOPS) by arranging for crafted values to be present in available memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-0745/">CVE-2009-0745</cve>
	<bugzilla href="https://bugzilla.suse.com/480860">SUSE bug 480860</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090778" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0778</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0778" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0778" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0778" ref_url="https://www.suse.com/security/cve/CVE-2009-0778" source="SUSE CVE"/>
    <description>
    The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-0778/">CVE-2009-0778</cve>
	<bugzilla href="https://bugzilla.suse.com/482712">SUSE bug 482712</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090787" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0787</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0787" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0787" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0787" ref_url="https://www.suse.com/security/cve/CVE-2009-0787" source="SUSE CVE"/>
    <description>
    The ecryptfs_write_metadata_to_contents function in the eCryptfs functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an incorrect size when writing kernel memory to an eCryptfs file header, which triggers an out-of-bounds read and allows local users to obtain portions of kernel memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-0787/">CVE-2009-0787</cve>
	<bugzilla href="https://bugzilla.suse.com/487107">SUSE bug 487107</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090834" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0834</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0834" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0834" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0834" ref_url="https://www.suse.com/security/cve/CVE-2009-0834" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:028" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
    <description>
    The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-0834/">CVE-2009-0834</cve>
	<bugzilla href="https://bugzilla.suse.com/483819">SUSE bug 483819</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/483820">SUSE bug 483820</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090835" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0835</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0835" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0835" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0835" ref_url="https://www.suse.com/security/cve/CVE-2009-0835" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:028" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
    <description>
    The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as (a) stat or (b) chmod, a related issue to CVE-2009-0342 and CVE-2009-0343.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-07-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-0835/">CVE-2009-0835</cve>
	<bugzilla href="https://bugzilla.suse.com/483819">SUSE bug 483819</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/483820">SUSE bug 483820</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20090935" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-0935</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-0935" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0935" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-0935" ref_url="https://www.suse.com/security/cve/CVE-2009-0935" source="SUSE CVE"/>
    <description>
    The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users to cause a denial of service (OOPS) via a read with an invalid address to an inotify instance, which causes the device's event list mutex to be unlocked twice and prevents proper synchronization of a data structure for the inotify instance.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-08"/>
	<updated date="2023-07-08"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-0935/">CVE-2009-0935</cve>
	<bugzilla href="https://bugzilla.suse.com/482843">SUSE bug 482843</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091046" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1046</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1046" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1046" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1046" ref_url="https://www.suse.com/security/cve/CVE-2009-1046" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-08/msg00007.html" source="SUSE-SU"/>
    <description>
    The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an "off-by-two memory error." NOTE: it is not clear whether this issue crosses privilege boundaries.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-1046/">CVE-2009-1046</cve>
	<bugzilla href="https://bugzilla.suse.com/478699">SUSE bug 478699</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091072" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1072</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1072" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1072" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1072" ref_url="https://www.suse.com/security/cve/CVE-2009-1072" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:028" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:033" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00004.html" source="SUSE-SU"/>
    <description>
    nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-1072/">CVE-2009-1072</cve>
	<bugzilla href="https://bugzilla.suse.com/487681">SUSE bug 487681</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/497551">SUSE bug 497551</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091185" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1185</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1185" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1185" ref_url="https://www.suse.com/security/cve/CVE-2009-1185" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:025" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-04/msg00012.html" source="SUSE-SU"/>
    <description>
    udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-1185/">CVE-2009-1185</cve>
	<bugzilla href="https://bugzilla.suse.com/1034330">SUSE bug 1034330</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/493158">SUSE bug 493158</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/550249">SUSE bug 550249</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/776925">SUSE bug 776925</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091192" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1192</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1192" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1192" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1192" ref_url="https://www.suse.com/security/cve/CVE-2009-1192" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:032" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:054" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:055" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:056" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html" source="SUSE-SU"/>
    <description>
    The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-1192/">CVE-2009-1192</cve>
	<bugzilla href="https://bugzilla.suse.com/497159">SUSE bug 497159</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091242" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1242</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1242" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1242" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1242" ref_url="https://www.suse.com/security/cve/CVE-2009-1242" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:032" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html" source="SUSE-SU"/>
    <description>
    The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-06"/>
	<updated date="2023-07-06"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-1242/">CVE-2009-1242</cve>
	<bugzilla href="https://bugzilla.suse.com/492760">SUSE bug 492760</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091336" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1336</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1336" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1336" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1336" ref_url="https://www.suse.com/security/cve/CVE-2009-1336" source="SUSE CVE"/>
    <description>
    fs/nfs/client.c in the Linux kernel before 2.6.23 does not properly initialize a certain structure member that stores the maximum NFS filename length, which allows local users to cause a denial of service (OOPS) via a long filename, related to the encode_lookup function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-07"/>
	<updated date="2023-07-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-1336/">CVE-2009-1336</cve>
	<bugzilla href="https://bugzilla.suse.com/492766">SUSE bug 492766</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091337" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1337</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1337" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1337" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1337" ref_url="https://www.suse.com/security/cve/CVE-2009-1337" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:028" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:032" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:033" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00004.html" source="SUSE-SU"/>
    <description>
    The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-1337/">CVE-2009-1337</cve>
	<bugzilla href="https://bugzilla.suse.com/1171985">SUSE bug 1171985</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/492768">SUSE bug 492768</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091385" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1385</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1385" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1385" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1385" ref_url="https://www.suse.com/security/cve/CVE-2009-1385" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-08/msg00007.html" source="SUSE-SU"/>
    <description>
    Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-1385/">CVE-2009-1385</cve>
	<bugzilla href="https://bugzilla.suse.com/509822">SUSE bug 509822</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/567376">SUSE bug 567376</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/567678">SUSE bug 567678</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091389" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1389</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1389" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1389" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1389" ref_url="https://www.suse.com/security/cve/CVE-2009-1389" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:036" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-1389/">CVE-2009-1389</cve>
	<bugzilla href="https://bugzilla.suse.com/511243">SUSE bug 511243</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/567376">SUSE bug 567376</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/567678">SUSE bug 567678</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091439" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1439</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1439" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1439" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1439" ref_url="https://www.suse.com/security/cve/CVE-2009-1439" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:028" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:032" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:033" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00004.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a denial of service (crash) via a long nativeFileSystem field in a Tree Connect response to an SMB mount request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-17"/>
	<updated date="2023-05-17"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-1439/">CVE-2009-1439</cve>
	<bugzilla href="https://bugzilla.suse.com/492282">SUSE bug 492282</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/498824">SUSE bug 498824</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091630" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1630</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1630" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1630" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1630" ref_url="https://www.suse.com/security/cve/CVE-2009-1630" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-08/msg00007.html" source="SUSE-SU"/>
    <description>
    The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-1630/">CVE-2009-1630</cve>
	<bugzilla href="https://bugzilla.suse.com/1175689">SUSE bug 1175689</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/503353">SUSE bug 503353</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091633" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1633</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1633" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1633" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1633" ref_url="https://www.suse.com/security/cve/CVE-2009-1633" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:054" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:056" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
    <description>
    Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-19"/>
	<updated date="2023-05-19"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-1633/">CVE-2009-1633</cve>
	<bugzilla href="https://bugzilla.suse.com/492282">SUSE bug 492282</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091883" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1883</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1883" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1883" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1883" ref_url="https://www.suse.com/security/cve/CVE-2009-1883" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:013" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html" source="SUSE-SU"/>
    <description>
    The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-1883/">CVE-2009-1883</cve>
	<bugzilla href="https://bugzilla.suse.com/539879">SUSE bug 539879</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091895" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1895</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1895" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1895" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1895" ref_url="https://www.suse.com/security/cve/CVE-2009-1895" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-08/msg00007.html" source="SUSE-SU"/>
    <description>
    The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-17"/>
	<updated date="2023-02-17"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-1895/">CVE-2009-1895</cve>
	<bugzilla href="https://bugzilla.suse.com/521427">SUSE bug 521427</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20091961" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-1961</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-1961" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1961" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-1961" ref_url="https://www.suse.com/security/cve/CVE-2009-1961" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:030" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html" source="SUSE-SU"/>
    <description>
    The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2009-1961/">CVE-2009-1961</cve>
	<bugzilla href="https://bugzilla.suse.com/495065">SUSE bug 495065</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092406" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-2406</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-2406" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2406" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-2406" ref_url="https://www.suse.com/security/cve/CVE-2009-2406" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2009:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to not ensuring that the key signature length in a Tag 11 packet is compatible with the key signature buffer size.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-11"/>
	<updated date="2023-02-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-2406/">CVE-2009-2406</cve>
	<bugzilla href="https://bugzilla.suse.com/523719">SUSE bug 523719</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092407" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-2407</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-2407" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2407" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-2407" ref_url="https://www.suse.com/security/cve/CVE-2009-2407" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2009:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the parse_tag_3_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to a large encrypted key size in a Tag 3 packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-10"/>
	<updated date="2023-02-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-2407/">CVE-2009-2407</cve>
	<bugzilla href="https://bugzilla.suse.com/523719">SUSE bug 523719</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092691" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-2691</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-2691" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2691" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-2691" ref_url="https://www.suse.com/security/cve/CVE-2009-2691" source="SUSE CVE"/>
    <description>
    The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-17"/>
	<updated date="2023-05-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-2691/">CVE-2009-2691</cve>
	<bugzilla href="https://bugzilla.suse.com/529919">SUSE bug 529919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092698" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-2698</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-2698" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2698" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-2698" ref_url="https://www.suse.com/security/cve/CVE-2009-2698" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-08/msg00008.html" source="SUSE-SU"/>
    <description>
    The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-2698/">CVE-2009-2698</cve>
	<bugzilla href="https://bugzilla.suse.com/532338">SUSE bug 532338</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092767" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-2767</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-2767" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2767" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-2767" ref_url="https://www.suse.com/security/cve/CVE-2009-2767" source="SUSE CVE"/>
    <description>
    The init_posix_timers function in kernel/posix-timers.c in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (OOPS) or possibly gain privileges via a CLOCK_MONOTONIC_RAW clock_nanosleep call that triggers a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-2767/">CVE-2009-2767</cve>
	<bugzilla href="https://bugzilla.suse.com/529555">SUSE bug 529555</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092848" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-2848</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-2848" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2848" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-2848" ref_url="https://www.suse.com/security/cve/CVE-2009-2848" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:054" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:056" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
    <description>
    The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current-&gt;clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-2848/">CVE-2009-2848</cve>
	<bugzilla href="https://bugzilla.suse.com/527865">SUSE bug 527865</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092903" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-2903</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-2903" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2903" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-2903" ref_url="https://www.suse.com/security/cve/CVE-2009-2903" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:061" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:064" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:013" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html" source="SUSE-SU"/>
    <description>
    Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-2903/">CVE-2009-2903</cve>
	<bugzilla href="https://bugzilla.suse.com/539878">SUSE bug 539878</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092908" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-2908</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-2908" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2908" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-2908" ref_url="https://www.suse.com/security/cve/CVE-2009-2908" source="SUSE CVE"/>
    <description>
    The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a "negative dentry" and trigger a NULL pointer dereference, as demonstrated via a Mutt temporary directory in an eCryptfs mount.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-2908/">CVE-2009-2908</cve>
	<bugzilla href="https://bugzilla.suse.com/545274">SUSE bug 545274</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20092910" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-2910</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-2910" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2910" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-2910" ref_url="https://www.suse.com/security/cve/CVE-2009-2910" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:051" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:054" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:055" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:056" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
    <description>
    arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2009-2910/">CVE-2009-2910</cve>
	<bugzilla href="https://bugzilla.suse.com/1175785">SUSE bug 1175785</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/543740">SUSE bug 543740</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093228" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3228</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3228" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3228" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3228" ref_url="https://www.suse.com/security/cve/CVE-2009-3228" source="SUSE CVE"/>
    <description>
    The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-16"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2009-3228/">CVE-2009-3228</cve>
	<bugzilla href="https://bugzilla.suse.com/1175788">SUSE bug 1175788</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/536467">SUSE bug 536467</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093286" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3286</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3286" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3286" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3286" ref_url="https://www.suse.com/security/cve/CVE-2009-3286" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
    <description>
    NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-3286/">CVE-2009-3286</cve>
	<bugzilla href="https://bugzilla.suse.com/541648">SUSE bug 541648</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093297" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3297</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3297" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3297" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3297" ref_url="https://www.suse.com/security/cve/CVE-2009-3297" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2010:003" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2010:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2010:011" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE-SU"/>
    <description>
    ** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-0787, CVE-2010-0788, CVE-2010-0789.  Reason: this candidate was intended for one issue in Samba, but it was used for multiple distinct issues, including one in FUSE and one in ncpfs.  Notes: All CVE users should consult CVE-2010-0787 (Samba), CVE-2010-0788 (ncpfs), and CVE-2010-0789 (FUSE) to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2009-3297/">CVE-2009-3297</cve>
	<bugzilla href="https://bugzilla.suse.com/550002">SUSE bug 550002</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/550003">SUSE bug 550003</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/550004">SUSE bug 550004</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/577925">SUSE bug 577925</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/583535">SUSE bug 583535</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/583536">SUSE bug 583536</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/594263">SUSE bug 594263</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/620680">SUSE bug 620680</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/651598">SUSE bug 651598</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481128" comment="fuse-2.9.7-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481131" comment="libfuse2-2.9.7-3.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093379" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3379</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3379" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3379" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3379" ref_url="https://www.suse.com/security/cve/CVE-2009-3379" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00001.html" source="SUSE-SU"/>
    <description>
    Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  NOTE: this might overlap CVE-2009-2663.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-02"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2009-3379/">CVE-2009-3379</cve>
	<bugzilla href="https://bugzilla.suse.com/522109">SUSE bug 522109</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/545277">SUSE bug 545277</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/608192">SUSE bug 608192</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481533" comment="libvorbis0-1.3.6-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481534" comment="libvorbisenc2-1.3.6-4.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093547" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3547</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3547" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3547" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3547" ref_url="https://www.suse.com/security/cve/CVE-2009-3547" source="SUSE CVE"/>
		<reference ref_id="" ref_url="" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:054" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:055" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:056" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
    <description>
    Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-10"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2009-3547/">CVE-2009-3547</cve>
	<bugzilla href="https://bugzilla.suse.com/550001">SUSE bug 550001</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093556" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3556</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3556" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3556" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3556" ref_url="https://www.suse.com/security/cve/CVE-2009-3556" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:009" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html" source="SUSE-SU"/>
    <description>
    A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2009-3556/">CVE-2009-3556</cve>
	<bugzilla href="https://bugzilla.suse.com/572193">SUSE bug 572193</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/605463">SUSE bug 605463</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093559" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3559</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3559" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3559" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3559" ref_url="https://www.suse.com/security/cve/CVE-2009-3559" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations, as demonstrated by a script that attempts to perform a require_once on a file in a standard library directory. NOTE: a reliable third party reports that this is not a vulnerability, because it results in a more restrictive security policy.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-20"/>
	<updated date="2023-05-12"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-3559/">CVE-2009-3559</cve>
	<bugzilla href="https://bugzilla.suse.com/557157">SUSE bug 557157</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/992991">SUSE bug 992991</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093612" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3612</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3612" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3612" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3612" ref_url="https://www.suse.com/security/cve/CVE-2009-3612" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:061" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:064" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
    <description>
    The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2009-3612/">CVE-2009-3612</cve>
	<bugzilla href="https://bugzilla.suse.com/536467">SUSE bug 536467</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093620" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3620</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3620" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3620" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3620" ref_url="https://www.suse.com/security/cve/CVE-2009-3620" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:061" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:064" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:013" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html" source="SUSE-SU"/>
    <description>
    The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-10"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-3620/">CVE-2009-3620</cve>
	<bugzilla href="https://bugzilla.suse.com/548071">SUSE bug 548071</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093621" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3621</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3621" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3621" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3621" ref_url="https://www.suse.com/security/cve/CVE-2009-3621" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:061" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:064" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:013" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html" source="SUSE-SU"/>
    <description>
    net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2009-3621/">CVE-2009-3621</cve>
	<bugzilla href="https://bugzilla.suse.com/548070">SUSE bug 548070</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093623" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3623</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3623" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3623" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3623" ref_url="https://www.suse.com/security/cve/CVE-2009-3623" source="SUSE CVE"/>
    <description>
    The lookup_cb_cred function in fs/nfsd/nfs4callback.c in the nfsd4 subsystem in the Linux kernel before 2.6.31.2 attempts to access a credentials cache even when a client specifies the AUTH_NULL authentication flavor, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an NFSv4 mount request.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-3623/">CVE-2009-3623</cve>
	<bugzilla href="https://bugzilla.suse.com/549029">SUSE bug 549029</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093624" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3624</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3624" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3624" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3624" ref_url="https://www.suse.com/security/cve/CVE-2009-3624" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE-SU"/>
    <description>
    The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux kernel before 2.6.32-rc5 does not properly maintain the reference count of a keyring, which allows local users to gain privileges or cause a denial of service (OOPS) via vectors involving calls to this function without specifying a keyring by ID, as demonstrated by a series of keyctl request2 and keyctl list commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-3624/">CVE-2009-3624</cve>
	<bugzilla href="https://bugzilla.suse.com/549030">SUSE bug 549030</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093638" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3638</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3638" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3638" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3638" ref_url="https://www.suse.com/security/cve/CVE-2009-3638" source="SUSE CVE"/>
    <description>
    Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.31.4 allows local users to have an unspecified impact via a KVM_GET_SUPPORTED_CPUID request to the kvm_arch_dev_ioctl function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-3638/">CVE-2009-3638</cve>
	<bugzilla href="https://bugzilla.suse.com/550072">SUSE bug 550072</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093640" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3640</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3640" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3640" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3640" ref_url="https://www.suse.com/security/cve/CVE-2009-3640" source="SUSE CVE"/>
    <description>
    The update_cr8_intercept function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc1 does not properly handle the absence of an Advanced Programmable Interrupt Controller (APIC), which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via a call to the kvm_vcpu_ioctl function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-3640/">CVE-2009-3640</cve>
	<bugzilla href="https://bugzilla.suse.com/549487">SUSE bug 549487</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093889" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3889</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3889" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3889" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3889" ref_url="https://www.suse.com/security/cve/CVE-2009-3889" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:061" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:064" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:013" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html" source="SUSE-SU"/>
    <description>
    The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which allows local users to change the (1) behavior and (2) logging level of the driver by modifying this file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-16"/>
	<updated date="2023-02-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-3889/">CVE-2009-3889</cve>
	<bugzilla href="https://bugzilla.suse.com/555173">SUSE bug 555173</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/557180">SUSE bug 557180</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20093939" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-3939</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-3939" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3939" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-3939" ref_url="https://www.suse.com/security/cve/CVE-2009-3939" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2009:061" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2009:064" ref_url="https://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:014" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE-SU"/>
    <description>
    The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-3939/">CVE-2009-3939</cve>
	<bugzilla href="https://bugzilla.suse.com/555173">SUSE bug 555173</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/557180">SUSE bug 557180</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094012" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4012</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4012" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4012" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4012" ref_url="https://www.suse.com/security/cve/CVE-2009-4012" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2010:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00000.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in LibThai before 0.1.13 might allow context-dependent attackers to execute arbitrary code via long strings that trigger heap-based buffer overflows, related to (1) thbrk/thbrk.c and (2) thwbrk/thwbrk.c.  NOTE: some of these details are obtained from third party information.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-02"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2009-4012/">CVE-2009-4012</cve>
	<bugzilla href="https://bugzilla.suse.com/569615">SUSE bug 569615</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009480757" comment="libthai-data-0.1.27-1.16 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480758" comment="libthai0-0.1.27-1.16 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094020" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4020</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4020" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4020" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4020" ref_url="https://www.suse.com/security/cve/CVE-2009-4020" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:016" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:023" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:036" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0781-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0812-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-4020/">CVE-2009-4020</cve>
	<bugzilla href="https://bugzilla.suse.com/564374">SUSE bug 564374</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/605463">SUSE bug 605463</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/760902">SUSE bug 760902</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094026" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4026</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4026" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4026" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4026" ref_url="https://www.suse.com/security/cve/CVE-2009-4026" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE-SU"/>
    <description>
    The mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (panic) via a crafted Delete Block ACK (aka DELBA) packet, related to an erroneous "code shuffling patch."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-06"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-4026/">CVE-2009-4026</cve>
	<bugzilla href="https://bugzilla.suse.com/558267">SUSE bug 558267</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094027" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4027</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4027" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4027" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4027" ref_url="https://www.suse.com/security/cve/CVE-2009-4027" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE-SU"/>
    <description>
    Race condition in the mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (system crash) via a Delete Block ACK (aka DELBA) packet that triggers a certain state change in the absence of an aggregation session.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-04"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-4027/">CVE-2009-4027</cve>
	<bugzilla href="https://bugzilla.suse.com/558267">SUSE bug 558267</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094031" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4031</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4031" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4031" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4031" ref_url="https://www.suse.com/security/cve/CVE-2009-4031" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:018" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0205-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-04/msg00053.html" source="SUSE-SU"/>
    <description>
    The do_insn_fetch function in arch/x86/kvm/emulate.c in the x86 emulator in the KVM subsystem in the Linux kernel before 2.6.32-rc8-next-20091125 tries to interpret instructions that contain too many bytes to be valid, which allows guest OS users to cause a denial of service (increased scheduling latency) on the host OS via unspecified manipulations related to SMP support.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-4031/">CVE-2009-4031</cve>
	<bugzilla href="https://bugzilla.suse.com/558269">SUSE bug 558269</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/558662">SUSE bug 558662</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094067" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4067</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4067" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4067" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4067" ref_url="https://www.suse.com/security/cve/CVE-2009-4067" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:042" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1195-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attackers to execute arbitrary code, cause a denial of service via a crafted USB device, or take full control of the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-23"/>
	<updated date="2023-02-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.8/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2009-4067/">CVE-2009-4067</cve>
	<bugzilla href="https://bugzilla.suse.com/706375">SUSE bug 706375</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094131" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4131</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4131" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4131" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4131" ref_url="https://www.suse.com/security/cve/CVE-2009-4131" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE-SU"/>
    <description>
    The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local users to overwrite arbitrary files via a crafted request, related to insufficient checks for file permissions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-4131/">CVE-2009-4131</cve>
	<bugzilla href="https://bugzilla.suse.com/561018">SUSE bug 561018</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/564380">SUSE bug 564380</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094138" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4138</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4138" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4138" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4138" ref_url="https://www.suse.com/security/cve/CVE-2009-4138" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
    <description>
    drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl associated with receiving an ISO packet that contains zero in the payload-length field.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-4138/">CVE-2009-4138</cve>
	<bugzilla href="https://bugzilla.suse.com/564712">SUSE bug 564712</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094306" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4306</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4306" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4306" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4306" ref_url="https://www.suse.com/security/cve/CVE-2009-4306" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE-SU"/>
    <description>
    Unspecified vulnerability in the EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel 2.6.32-git6 and earlier allows local users to cause a denial of service (filesystem corruption) via unknown vectors, a different vulnerability than CVE-2009-4131.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2009-4306/">CVE-2009-4306</cve>
	<bugzilla href="https://bugzilla.suse.com/564380">SUSE bug 564380</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094307" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4307</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4307" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4307" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4307" ref_url="https://www.suse.com/security/cve/CVE-2009-4307" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html" source="SUSE-SU"/>
    <description>
    The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 2.6.32-git6 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-4307/">CVE-2009-4307</cve>
	<bugzilla href="https://bugzilla.suse.com/564381">SUSE bug 564381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/757278">SUSE bug 757278</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094308" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4308</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4308" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4308" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4308" ref_url="https://www.suse.com/security/cve/CVE-2009-4308" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
    <description>
    The ext4_decode_error function in fs/ext4/super.c in the ext4 filesystem in the Linux kernel before 2.6.32 allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference), and possibly have unspecified other impact, via a crafted read-only filesystem that lacks a journal.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-14"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-4308/">CVE-2009-4308</cve>
	<bugzilla href="https://bugzilla.suse.com/564382">SUSE bug 564382</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094536" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4536</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4536" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4536" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4536" ref_url="https://www.suse.com/security/cve/CVE-2009-4536" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:009" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:013" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:014" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
    <description>
    drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypass packet filters via a large packet with a crafted payload.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1385.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-4536/">CVE-2009-4536</cve>
	<bugzilla href="https://bugzilla.suse.com/567376">SUSE bug 567376</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/583434">SUSE bug 583434</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094537" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4537</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4537" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4537" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4537" ref_url="https://www.suse.com/security/cve/CVE-2009-4537" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:023" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:036" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-11"/>
	<updated date="2023-07-11"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2009-4537/">CVE-2009-4537</cve>
	<bugzilla href="https://bugzilla.suse.com/567376">SUSE bug 567376</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20094538" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-4538</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-4538" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4538" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-4538" ref_url="https://www.suse.com/security/cve/CVE-2009-4538" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:009" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:014" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE-SU"/>
    <description>
    drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-23"/>
	<updated date="2023-07-23"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2009-4538/">CVE-2009-4538</cve>
	<bugzilla href="https://bugzilla.suse.com/567376">SUSE bug 567376</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20095155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2009-5155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2009-5155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5155" source="CVE"/>
    <reference ref_id="SUSE CVE-2009-5155" ref_url="https://www.suse.com/security/cve/CVE-2009-5155" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005729.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1958-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1958-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005821.html" source="SUSE-SU"/>
    <description>
    In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2009-5155/">CVE-2009-5155</cve>
	<bugzilla href="https://bugzilla.suse.com/1127223">SUSE bug 1127223</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100003" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-0003</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-0003" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0003" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-0003" ref_url="https://www.suse.com/security/cve/CVE-2010-0003" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:014" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE-SU"/>
    <description>
    The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and then reading a log file, and might allow local users to cause a denial of service (system slowdown or crash) by jumping to an address.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-0003/">CVE-2010-0003</cve>
	<bugzilla href="https://bugzilla.suse.com/569902">SUSE bug 569902</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100006" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-0006</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-0006" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0006" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-0006" ref_url="https://www.suse.com/security/cve/CVE-2010-0006" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" source="SUSE-SU"/>
    <description>
    The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid IPv6 jumbogram, a related issue to CVE-2007-4567.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-0006/">CVE-2010-0006</cve>
	<bugzilla href="https://bugzilla.suse.com/570608">SUSE bug 570608</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100007" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-0007</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-0007" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0007" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-0007" ref_url="https://www.suse.com/security/cve/CVE-2010-0007" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-01/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:013" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:014" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE-SU"/>
    <description>
    net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-0007/">CVE-2010-0007</cve>
	<bugzilla href="https://bugzilla.suse.com/570602">SUSE bug 570602</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/570606">SUSE bug 570606</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100008" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-0008</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-0008" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0008" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-0008" ref_url="https://www.suse.com/security/cve/CVE-2010-0008" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
    <description>
    The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-0008/">CVE-2010-0008</cve>
	<bugzilla href="https://bugzilla.suse.com/586195">SUSE bug 586195</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100307" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-0307</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-0307" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0307" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-0307" ref_url="https://www.suse.com/security/cve/CVE-2010-0307" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:014" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:016" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00003.html" source="SUSE-SU"/>
    <description>
    The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensure that the ELF interpreter is available before a call to the SET_PERSONALITY macro, which allows local users to cause a denial of service (system crash) via a 32-bit application that attempts to execute a 64-bit application and then triggers a segmentation fault, as demonstrated by amd64_killer, related to the flush_old_exec function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-0307/">CVE-2010-0307</cve>
	<bugzilla href="https://bugzilla.suse.com/575644">SUSE bug 575644</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100410" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-0410</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-0410" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0410" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-0410" ref_url="https://www.suse.com/security/cve/CVE-2010-0410" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:014" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:016" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:018" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:023" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0205-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-04/msg00053.html" source="SUSE-SU"/>
    <description>
    drivers/connector/connector.c in the Linux kernel before 2.6.32.8 allows local users to cause a denial of service (memory consumption and system crash) by sending the kernel many NETLINK_CONNECTOR messages.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-0410/">CVE-2010-0410</cve>
	<bugzilla href="https://bugzilla.suse.com/576927">SUSE bug 576927</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/605463">SUSE bug 605463</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100415" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-0415</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-0415" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0415" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-0415" ref_url="https://www.suse.com/security/cve/CVE-2010-0415" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:014" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:016" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:018" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0205-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-04/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by specifying a node that is not part of the kernel's node set.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-0415/">CVE-2010-0415</cve>
	<bugzilla href="https://bugzilla.suse.com/577753">SUSE bug 577753</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100623" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-0623</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-0623" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0623" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-0623" ref_url="https://www.suse.com/security/cve/CVE-2010-0623" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:018" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0205-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-04/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users to cause a denial of service (OOPS) via vectors involving an unmount of an ext3 filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-0623/">CVE-2010-0623</cve>
	<bugzilla href="https://bugzilla.suse.com/579439">SUSE bug 579439</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100624" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-0624</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-0624" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0624" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-0624" ref_url="https://www.suse.com/security/cve/CVE-2010-0624" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2010:011" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0189-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-04/msg00044.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-0624/">CVE-2010-0624</cve>
	<bugzilla href="https://bugzilla.suse.com/579475">SUSE bug 579475</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/608034">SUSE bug 608034</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481663" comment="tar-1.30-3.3.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100730" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-0730</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-0730" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0730" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-0730" ref_url="https://www.suse.com/security/cve/CVE-2010-0730" source="SUSE CVE"/>
    <description>
    The MMIO instruction decoder in the Xen hypervisor in the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows guest OS users to cause a denial of service (32-bit guest OS crash) via vectors that trigger an unspecified instruction emulation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-0730/">CVE-2010-0730</cve>
	<bugzilla href="https://bugzilla.suse.com/601231">SUSE bug 601231</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20100741" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-0741</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-0741" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0741" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-0741" ref_url="https://www.suse.com/security/cve/CVE-2010-0741" source="SUSE CVE"/>
    <description>
    The virtio_net_bad_features function in hw/virtio-net.c in the virtio-net driver in the Linux kernel before 2.6.26, when used on a guest OS in conjunction with qemu-kvm 0.11.0 or KVM 83, allows remote attackers to cause a denial of service (guest OS crash, and an associated qemu-kvm process exit) by sending a large amount of network traffic to a TCP port on the guest OS, related to a virtio-net whitelist that includes an improper implementation of TCP Segment Offloading (TSO).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-0741/">CVE-2010-0741</cve>
	<bugzilla href="https://bugzilla.suse.com/596032">SUSE bug 596032</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101148" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-1148</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-1148" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1148" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-1148" ref_url="https://www.suse.com/security/cve/CVE-2010-1148" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
    <description>
    The cifs_create function in fs/cifs/dir.c in the Linux kernel 2.6.33.2 and earlier allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a NULL nameidata (aka nd) field in a POSIX file-creation request to a server that supports UNIX extensions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-1148/">CVE-2010-1148</cve>
	<bugzilla href="https://bugzilla.suse.com/593940">SUSE bug 593940</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101162" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-1162</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-1162" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1162" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-1162" ref_url="https://www.suse.com/security/cve/CVE-2010-1162" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
    <description>
    The release_one_tty function in drivers/char/tty_io.c in the Linux kernel before 2.6.34-rc4 omits certain required calls to the put_pid function, which has unspecified impact and local attack vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-1162/">CVE-2010-1162</cve>
	<bugzilla href="https://bugzilla.suse.com/596462">SUSE bug 596462</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101172" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-1172</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-1172" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1172" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-1172" ref_url="https://www.suse.com/security/cve/CVE-2010-1172" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2010:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2010:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2010:022" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0968-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-11/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0969-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-11/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0300-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0300-2" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00025.html" source="SUSE-SU"/>
    <description>
    DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-1172/">CVE-2010-1172</cve>
	<bugzilla href="https://bugzilla.suse.com/628607">SUSE bug 628607</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633621">SUSE bug 633621</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633622">SUSE bug 633622</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633623">SUSE bug 633623</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633629">SUSE bug 633629</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633637">SUSE bug 633637</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633639">SUSE bug 633639</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633648">SUSE bug 633648</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633652">SUSE bug 633652</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633653">SUSE bug 633653</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633654">SUSE bug 633654</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633658">SUSE bug 633658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633660">SUSE bug 633660</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633678">SUSE bug 633678</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633679">SUSE bug 633679</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633681">SUSE bug 633681</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633682">SUSE bug 633682</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633685">SUSE bug 633685</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633686">SUSE bug 633686</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633700">SUSE bug 633700</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633701">SUSE bug 633701</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/633702">SUSE bug 633702</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480190" comment="dbus-1-glib-0.108-1.29 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101173" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-1173</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-1173" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1173" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-1173" ref_url="https://www.suse.com/security/cve/CVE-2010-1173" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invalid parameters that require a large amount of error data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-1173/">CVE-2010-1173</cve>
	<bugzilla href="https://bugzilla.suse.com/600375">SUSE bug 600375</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/702025">SUSE bug 702025</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/941110">SUSE bug 941110</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101188" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-1188</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-1188" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1188" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-1188" ref_url="https://www.suse.com/security/cve/CVE-2010-1188" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:036" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00001.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled and causes the skb structure to be freed.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-1188/">CVE-2010-1188</cve>
	<bugzilla href="https://bugzilla.suse.com/592571">SUSE bug 592571</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101436" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-1436</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-1436" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1436" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-1436" ref_url="https://www.suse.com/security/cve/CVE-2010-1436" source="SUSE CVE"/>
    <description>
    gfs2 in the Linux kernel 2.6.18, and possibly other versions, does not properly handle when the gfs2_quota struct occupies two separate pages, which allows local users to cause a denial of service (kernel panic) via certain manipulations that cause an out-of-bounds write, as demonstrated by writing from an ext3 file system to a gfs2 file system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-06"/>
	<updated date="2023-02-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-1436/">CVE-2010-1436</cve>
	<bugzilla href="https://bugzilla.suse.com/599957">SUSE bug 599957</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101437" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-1437</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-1437" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1437" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-1437" ref_url="https://www.suse.com/security/cve/CVE-2010-1437" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-07"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-1437/">CVE-2010-1437</cve>
	<bugzilla href="https://bugzilla.suse.com/599955">SUSE bug 599955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101636" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-1636</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-1636" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1636" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-1636" ref_url="https://www.suse.com/security/cve/CVE-2010-1636" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
    <description>
    The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to read sensitive information from a write-only file descriptor.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-21"/>
	<updated date="2023-02-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-1636/">CVE-2010-1636</cve>
	<bugzilla href="https://bugzilla.suse.com/606743">SUSE bug 606743</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101641" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-1641</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-1641" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1641" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-1641" ref_url="https://www.suse.com/security/cve/CVE-2010-1641" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:033" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
    <description>
    The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-1641/">CVE-2010-1641</cve>
	<bugzilla href="https://bugzilla.suse.com/608576">SUSE bug 608576</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101643" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-1643</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-1643" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1643" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-1643" ref_url="https://www.suse.com/security/cve/CVE-2010-1643" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE-SU"/>
    <description>
    mm/shmem.c in the Linux kernel before 2.6.28-rc3, when strict overcommit is enabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer dereference and knfsd crash) or possibly have unspecified other impact via unknown vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-01"/>
	<updated date="2023-03-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-1643/">CVE-2010-1643</cve>
	<bugzilla href="https://bugzilla.suse.com/608933">SUSE bug 608933</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20101646" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-1646</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-1646" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1646" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-1646" ref_url="https://www.suse.com/security/cve/CVE-2010-1646" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0050-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00022.html" source="SUSE-SU"/>
    <description>
    The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-19"/>
	<updated date="2023-05-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-1646/">CVE-2010-1646</cve>
	<bugzilla href="https://bugzilla.suse.com/594738">SUSE bug 594738</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334290" comment="sudo is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102066" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2066</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2066" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2066" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2066" ref_url="https://www.suse.com/security/cve/CVE-2010-2066" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:033" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
    <description>
    The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2010-2066/">CVE-2010-2066</cve>
	<bugzilla href="https://bugzilla.suse.com/612457">SUSE bug 612457</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102226" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2226</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2226" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2226" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2226" ref_url="https://www.suse.com/security/cve/CVE-2010-2226" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file into another file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-20"/>
	<updated date="2023-02-20"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-2226/">CVE-2010-2226</cve>
	<bugzilla href="https://bugzilla.suse.com/615141">SUSE bug 615141</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102240" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2240</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2240" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2240" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2240" ref_url="https://www.suse.com/security/cve/CVE-2010-2240" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-May/000117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0644-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-May/000121.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0561-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-08/msg00064.html" source="SUSE-SU"/>
    <description>
    The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent attackers to execute arbitrary code by writing to the bottom page of a shared memory segment, as demonstrated by a memory-exhaustion attack against the X.Org X server.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-2240/">CVE-2010-2240</cve>
	<bugzilla href="https://bugzilla.suse.com/1039348">SUSE bug 1039348</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/211997">SUSE bug 211997</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/546062">SUSE bug 546062</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/59807">SUSE bug 59807</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/615929">SUSE bug 615929</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/618152">SUSE bug 618152</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/632737">SUSE bug 632737</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/643986">SUSE bug 643986</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/746947">SUSE bug 746947</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/746949">SUSE bug 746949</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102243" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2243</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2243" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2243" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2243" ref_url="https://www.suse.com/security/cve/CVE-2010-2243" source="SUSE CVE"/>
    <description>
    A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /sys/devices/system/clocksource/clocksource0/current_clocksource results in an OOPS.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2010-2243/">CVE-2010-2243</cve>
	<bugzilla href="https://bugzilla.suse.com/617903">SUSE bug 617903</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102248" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2248</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2248" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2248" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2248" ref_url="https://www.suse.com/security/cve/CVE-2010-2248" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
    <description>
    fs/cifs/cifssmb.c in the CIFS implementation in the Linux kernel before 2.6.34-rc4 allows remote attackers to cause a denial of service (panic) via an SMB response packet with an invalid CountHigh value, as demonstrated by a response from an OS/2 server, related to the CIFSSMBWrite and CIFSSMBWrite2 functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-2248/">CVE-2010-2248</cve>
	<bugzilla href="https://bugzilla.suse.com/618156">SUSE bug 618156</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102492" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2492</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2492" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2492" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2492" ref_url="https://www.suse.com/security/cve/CVE-2010-2492" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2010-2492/">CVE-2010-2492</cve>
	<bugzilla href="https://bugzilla.suse.com/619850">SUSE bug 619850</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102495" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2495</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2495" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2495" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2495" ref_url="https://www.suse.com/security/cve/CVE-2010-2495" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:033" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
    <description>
    The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-06"/>
	<updated date="2023-02-16"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2010-2495/">CVE-2010-2495</cve>
	<bugzilla href="https://bugzilla.suse.com/616612">SUSE bug 616612</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102521" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2521</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2521" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2521" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2521" ref_url="https://www.suse.com/security/cve/CVE-2010-2521" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:036" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
    <description>
    Multiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR implementation in the NFS server in the Linux kernel before 2.6.34-rc6 allow remote attackers to cause a denial of service (panic) or possibly execute arbitrary code via a crafted NFSv4 compound WRITE request, related to the read_buf and nfsd4_decode_compound functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-12"/>
	<updated date="2023-02-15"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2010-2521/">CVE-2010-2521</cve>
	<bugzilla href="https://bugzilla.suse.com/620372">SUSE bug 620372</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102524" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2524</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2524" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2524" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2524" ref_url="https://www.suse.com/security/cve/CVE-2010-2524" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:039" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0592-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-09/msg00009.html" source="SUSE-SU"/>
    <description>
    The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS mounts via vectors involving an add_key call, related to a "cache stuffing" issue and MS-DFS referrals.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2010-2524/">CVE-2010-2524</cve>
	<bugzilla href="https://bugzilla.suse.com/627386">SUSE bug 627386</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/627447">SUSE bug 627447</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102537" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2537</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2537" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2537" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2537" ref_url="https://www.suse.com/security/cve/CVE-2010-2537" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:039" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0592-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-09/msg00009.html" source="SUSE-SU"/>
    <description>
    The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2010-2537/">CVE-2010-2537</cve>
	<bugzilla href="https://bugzilla.suse.com/624587">SUSE bug 624587</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102798" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2798</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2798" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2798" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2798" ref_url="https://www.suse.com/security/cve/CVE-2010-2798" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:039" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0592-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, related to the gfs2_rename function in fs/gfs2/ops_inode.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-05"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2010-2798/">CVE-2010-2798</cve>
	<bugzilla href="https://bugzilla.suse.com/627386">SUSE bug 627386</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102803" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2803</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2803" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2803" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2803" ref_url="https://www.suse.com/security/cve/CVE-2010-2803" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:041" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-2803/">CVE-2010-2803</cve>
	<bugzilla href="https://bugzilla.suse.com/628604">SUSE bug 628604</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102942" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2942</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2942" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2942" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2942" ref_url="https://www.suse.com/security/cve/CVE-2010-2942" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:041" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-13"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2010-2942/">CVE-2010-2942</cve>
	<bugzilla href="https://bugzilla.suse.com/632309">SUSE bug 632309</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/642324">SUSE bug 642324</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102943" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2943</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2943" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2943" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2943" ref_url="https://www.suse.com/security/cve/CVE-2010-2943" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-17"/>
	<updated date="2023-02-17"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2010-2943/">CVE-2010-2943</cve>
	<bugzilla href="https://bugzilla.suse.com/632317">SUSE bug 632317</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102946" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2946</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2946" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2946" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2946" ref_url="https://www.suse.com/security/cve/CVE-2010-2946" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an "os2." substring at the beginning of a name.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-2946/">CVE-2010-2946</cve>
	<bugzilla href="https://bugzilla.suse.com/633585">SUSE bug 633585</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20102954" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-2954</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-2954" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2954" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-2954" ref_url="https://www.suse.com/security/cve/CVE-2010-2954" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:041" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:050" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0720-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-10/msg00013.html" source="SUSE-SU"/>
    <description>
    The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact via multiple unsuccessful calls to bind on an AF_IRDA (aka PF_IRDA) socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-2954/">CVE-2010-2954</cve>
	<bugzilla href="https://bugzilla.suse.com/636112">SUSE bug 636112</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103066" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3066</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3066" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3066" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3066" ref_url="https://www.suse.com/security/cve/CVE-2010-3066" source="SUSE CVE"/>
    <description>
    The io_submit_one function in fs/aio.c in the Linux kernel before 2.6.23 allows local users to cause a denial of service (NULL pointer dereference) via a crafted io_submit system call with an IOCB_FLAG_RESFD flag.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3066/">CVE-2010-3066</cve>
	<bugzilla href="https://bugzilla.suse.com/657944">SUSE bug 657944</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103067" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3067</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3067" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3067" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3067" ref_url="https://www.suse.com/security/cve/CVE-2010-3067" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3067/">CVE-2010-3067</cve>
	<bugzilla href="https://bugzilla.suse.com/642302">SUSE bug 642302</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103078" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3078</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3078" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3078" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3078" ref_url="https://www.suse.com/security/cve/CVE-2010-3078" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:041" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:044" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:050" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0720-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-10"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2010-3078/">CVE-2010-3078</cve>
	<bugzilla href="https://bugzilla.suse.com/637436">SUSE bug 637436</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103079" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3079</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3079" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3079" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3079" ref_url="https://www.suse.com/security/cve/CVE-2010-3079" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:047" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:050" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0720-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of service (NULL pointer dereference and outage of all function tracing files) via an lseek call on a file descriptor associated with the set_ftrace_filter file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2010-3079/">CVE-2010-3079</cve>
	<bugzilla href="https://bugzilla.suse.com/637502">SUSE bug 637502</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103080" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3080</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3080" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3080" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3080" ref_url="https://www.suse.com/security/cve/CVE-2010-3080" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:047" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:050" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0720-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    Double free vulnerability in the snd_seq_oss_open function in sound/core/seq/oss/seq_oss_init.c in the Linux kernel before 2.6.36-rc4 might allow local users to cause a denial of service or possibly have unspecified other impact via an unsuccessful attempt to open the /dev/sequencer device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-3080/">CVE-2010-3080</cve>
	<bugzilla href="https://bugzilla.suse.com/638277">SUSE bug 638277</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103081" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3081</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3081" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3081" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3081" ref_url="https://www.suse.com/security/cve/CVE-2010-3081" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:041" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:043" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:044" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:047" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:050" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2010:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0720-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-10/msg00013.html" source="SUSE-SU"/>
    <description>
    The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privileges by leveraging the ability of the compat_mc_getsockopt function (aka the MCAST_MSFILTER getsockopt support) to control a certain length value, related to a "stack pointer underflow" issue, as exploited in the wild in September 2010.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2010-3081/">CVE-2010-3081</cve>
	<bugzilla href="https://bugzilla.suse.com/639709">SUSE bug 639709</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/641575">SUSE bug 641575</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103084" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3084</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3084" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3084" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3084" ref_url="https://www.suse.com/security/cve/CVE-2010-3084" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:047" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the niu_get_ethtool_tcam_all function in drivers/net/niu.c in the Linux kernel before 2.6.36-rc4 allows local users to cause a denial of service or possibly have unspecified other impact via the ETHTOOL_GRXCLSRLALL ethtool command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-07"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-3084/">CVE-2010-3084</cve>
	<bugzilla href="https://bugzilla.suse.com/638274">SUSE bug 638274</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103086" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3086</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3086" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3086" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3086" ref_url="https://www.suse.com/security/cve/CVE-2010-3086" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
    <description>
    include/asm-x86/futex.h in the Linux kernel before 2.6.25 does not properly implement exception fixup, which allows local users to cause a denial of service (panic) via an invalid application that triggers a page fault.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3086/">CVE-2010-3086</cve>
	<bugzilla href="https://bugzilla.suse.com/652595">SUSE bug 652595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103192" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3192</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3192" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3192" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3192" ref_url="https://www.suse.com/security/cve/CVE-2010-3192" source="SUSE CVE"/>
    <description>
    Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorrect program, as demonstrated by a setuid program that contains a stack-based buffer overflow error, related to the __fortify_fail function in debug/fortify_fail.c, and the __stack_chk_fail (aka stack protection) and __chk_fail (aka FORTIFY_SOURCE) implementations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3192/">CVE-2010-3192</cve>
	<bugzilla href="https://bugzilla.suse.com/636113">SUSE bug 636113</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103296" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3296</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3296" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3296" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3296" ref_url="https://www.suse.com/security/cve/CVE-2010-3296" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:047" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:050" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0720-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-10/msg00013.html" source="SUSE-SU"/>
    <description>
    The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a CHELSIO_GET_QSET_NUM ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-3296/">CVE-2010-3296</cve>
	<bugzilla href="https://bugzilla.suse.com/639481">SUSE bug 639481</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/649187">SUSE bug 649187</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103297" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3297</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3297" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3297" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3297" ref_url="https://www.suse.com/security/cve/CVE-2010-3297" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:044" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:047" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:050" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:052" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0720-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-10/msg00013.html" source="SUSE-SU"/>
    <description>
    The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an EQL_GETMASTRCFG ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-3297/">CVE-2010-3297</cve>
	<bugzilla href="https://bugzilla.suse.com/639482">SUSE bug 639482</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/649187">SUSE bug 649187</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103298" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3298</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3298" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3298" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3298" ref_url="https://www.suse.com/security/cve/CVE-2010-3298" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:047" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:050" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2010:0720-1" ref_url="https://lists.opensuse.org/opensuse-updates/2010-10/msg00013.html" source="SUSE-SU"/>
    <description>
    The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-3298/">CVE-2010-3298</cve>
	<bugzilla href="https://bugzilla.suse.com/639483">SUSE bug 639483</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/649187">SUSE bug 649187</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103301" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3301</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3301" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3301" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3301" ref_url="https://www.suse.com/security/cve/CVE-2010-3301" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:041" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:043" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:045" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:047" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SR:2010:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE-SU"/>
    <description>
    The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to gain privileges by triggering an out-of-bounds access to the system call table using the %rax register. NOTE: this vulnerability exists because of a CVE-2007-4573 regression.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-3301/">CVE-2010-3301</cve>
	<bugzilla href="https://bugzilla.suse.com/639708">SUSE bug 639708</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103432" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3432</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3432" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3432" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3432" ref_url="https://www.suse.com/security/cve/CVE-2010-3432" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP traffic.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-07"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-3432/">CVE-2010-3432</cve>
	<bugzilla href="https://bugzilla.suse.com/641983">SUSE bug 641983</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103437" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3437</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3437" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3437" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3437" ref_url="https://www.suse.com/security/cve/CVE-2010-3437" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0048-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via a crafted index value in a PKT_CTRL_CMD_STATUS ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3437/">CVE-2010-3437</cve>
	<bugzilla href="https://bugzilla.suse.com/642486">SUSE bug 642486</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103442" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3442</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3442" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3442" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3442" ref_url="https://www.suse.com/security/cve/CVE-2010-3442" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) SNDRV_CTL_IOCTL_ELEM_ADD or (2) SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3442/">CVE-2010-3442</cve>
	<bugzilla href="https://bugzilla.suse.com/642484">SUSE bug 642484</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103448" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3448</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3448" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3448" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3448" ref_url="https://www.suse.com/security/cve/CVE-2010-3448" source="SUSE CVE"/>
    <description>
    drivers/platform/x86/thinkpad_acpi.c in the Linux kernel before 2.6.34 on ThinkPad devices, when the X.Org X server is used, does not properly restrict access to the video output control state, which allows local users to cause a denial of service (system hang) via a (1) read or (2) write operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3448/">CVE-2010-3448</cve>
	<bugzilla href="https://bugzilla.suse.com/662671">SUSE bug 662671</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103698" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3698</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3698" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3698" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3698" ref_url="https://www.suse.com/security/cve/CVE-2010-3698" source="SUSE CVE"/>
    <description>
    The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RUN ioctl call in conjunction with a modified Local Descriptor Table (LDT).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3698/">CVE-2010-3698</cve>
	<bugzilla href="https://bugzilla.suse.com/1161450">SUSE bug 1161450</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103705" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3705</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3705" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3705" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3705" ref_url="https://www.suse.com/security/cve/CVE-2010-3705" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted value in the last element of this array.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-3705/">CVE-2010-3705</cve>
	<bugzilla href="https://bugzilla.suse.com/643513">SUSE bug 643513</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103848" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3848</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3848" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3848" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3848" ref_url="https://www.suse.com/security/cve/CVE-2010-3848" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to gain privileges by providing a large number of iovec structures.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-18"/>
	<updated date="2023-02-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3848/">CVE-2010-3848</cve>
	<bugzilla href="https://bugzilla.suse.com/647632">SUSE bug 647632</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103849" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3849</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3849" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3849" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3849" ref_url="https://www.suse.com/security/cve/CVE-2010-3849" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
    <description>
    The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value for the remote address field.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3849/">CVE-2010-3849</cve>
	<bugzilla href="https://bugzilla.suse.com/647632">SUSE bug 647632</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103850" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3850</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3850" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3850" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3850" ref_url="https://www.suse.com/security/cve/CVE-2010-3850" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
    <description>
    The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet addresses via an SIOCSIFADDR ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-24"/>
	<updated date="2023-02-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3850/">CVE-2010-3850</cve>
	<bugzilla href="https://bugzilla.suse.com/647632">SUSE bug 647632</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/658461">SUSE bug 658461</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103858" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3858</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3858" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3858" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3858" ref_url="https://www.suse.com/security/cve/CVE-2010-3858" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
    <description>
    The setup_arg_pages function in fs/exec.c in the Linux kernel before 2.6.36, when CONFIG_STACK_GROWSDOWN is used, does not properly restrict the stack memory consumption of the (1) arguments and (2) environment for a 32-bit application on a 64-bit platform, which allows local users to cause a denial of service (system crash) via a crafted exec system call, a related issue to CVE-2010-2240.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3858/">CVE-2010-3858</cve>
	<bugzilla href="https://bugzilla.suse.com/648302">SUSE bug 648302</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/655220">SUSE bug 655220</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103861" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3861</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3861" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3861" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3861" ref_url="https://www.suse.com/security/cve/CVE-2010-3861" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0048-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value, a different vulnerability than CVE-2010-2478.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-3861/">CVE-2010-3861</cve>
	<bugzilla href="https://bugzilla.suse.com/649187">SUSE bug 649187</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103865" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3865</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3865" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3865" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3865" ref_url="https://www.suse.com/security/cve/CVE-2010-3865" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:057" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-11/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted iovec struct in a Reliable Datagram Sockets (RDS) request, which triggers a buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-3865/">CVE-2010-3865</cve>
	<bugzilla href="https://bugzilla.suse.com/650128">SUSE bug 650128</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103873" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3873</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3873" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3873" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3873" ref_url="https://www.suse.com/security/cve/CVE-2010-3873" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0153-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0364-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
    <description>
    The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, which allows remote attackers to cause a denial of service (heap memory corruption and panic) or possibly have unspecified other impact via malformed (1) X25_FAC_CALLING_AE or (2) X25_FAC_CALLED_AE data, related to net/x25/x25_facilities.c and net/x25/x25_in.c, a different vulnerability than CVE-2010-4164.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3873/">CVE-2010-3873</cve>
	<bugzilla href="https://bugzilla.suse.com/651219">SUSE bug 651219</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/653260">SUSE bug 653260</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103874" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3874</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3874" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3874" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3874" ref_url="https://www.suse.com/security/cve/CVE-2010-3874" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0048-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial of service (memory corruption) via a connect operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-3874/">CVE-2010-3874</cve>
	<bugzilla href="https://bugzilla.suse.com/651218">SUSE bug 651218</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103875" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3875</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3875" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3875" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3875" ref_url="https://www.suse.com/security/cve/CVE-2010-3875" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-19"/>
	<updated date="2023-02-19"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-3875/">CVE-2010-3875</cve>
	<bugzilla href="https://bugzilla.suse.com/650897">SUSE bug 650897</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103876" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3876</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3876" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3876" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3876" ref_url="https://www.suse.com/security/cve/CVE-2010-3876" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capability to read copies of the applicable structures.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-18"/>
	<updated date="2023-02-18"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-3876/">CVE-2010-3876</cve>
	<bugzilla href="https://bugzilla.suse.com/650897">SUSE bug 650897</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103877" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3877</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3877" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3877" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3877" ref_url="https://www.suse.com/security/cve/CVE-2010-3877" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The get_name function in net/tipc/socket.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-24"/>
	<updated date="2023-02-24"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-3877/">CVE-2010-3877</cve>
	<bugzilla href="https://bugzilla.suse.com/650897">SUSE bug 650897</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103880" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3880</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3880" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3880" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3880" ref_url="https://www.suse.com/security/cve/CVE-2010-3880" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-16"/>
	<updated date="2023-02-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-3880/">CVE-2010-3880</cve>
	<bugzilla href="https://bugzilla.suse.com/651599">SUSE bug 651599</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103881" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3881</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3881" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3881" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3881" ref_url="https://www.suse.com/security/cve/CVE-2010-3881" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0048-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-01"/>
	<updated date="2023-03-01"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-3881/">CVE-2010-3881</cve>
	<bugzilla href="https://bugzilla.suse.com/651596">SUSE bug 651596</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/662663">SUSE bug 662663</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/706696">SUSE bug 706696</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20103904" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-3904</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-3904" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3904" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-3904" ref_url="https://www.suse.com/security/cve/CVE-2010-3904" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:053" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2010:057" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-11/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-19"/>
	<updated date="2023-05-19"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-3904/">CVE-2010-3904</cve>
	<bugzilla href="https://bugzilla.suse.com/647392">SUSE bug 647392</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/676707">SUSE bug 676707</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/703752">SUSE bug 703752</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104078" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4078</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4078" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4078" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4078" ref_url="https://www.suse.com/security/cve/CVE-2010-4078" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The sisfb_ioctl function in drivers/video/sis/sis_main.c in the Linux kernel before 2.6.36-rc6 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FBIOGET_VBLANK ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-05-26"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-4078/">CVE-2010-4078</cve>
	<bugzilla href="https://bugzilla.suse.com/642311">SUSE bug 642311</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104080" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4080</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4080" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4080" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4080" ref_url="https://www.suse.com/security/cve/CVE-2010-4080" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The snd_hdsp_hwdep_ioctl function in sound/pci/rme9652/hdsp.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSP_IOCTL_GET_CONFIG_INFO ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-05-26"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-4080/">CVE-2010-4080</cve>
	<bugzilla href="https://bugzilla.suse.com/642312">SUSE bug 642312</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104081" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4081</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4081" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4081" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4081" ref_url="https://www.suse.com/security/cve/CVE-2010-4081" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
    <description>
    The snd_hdspm_hwdep_ioctl function in sound/pci/rme9652/hdspm.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSPM_IOCTL_GET_CONFIG_INFO ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-21"/>
	<updated date="2023-05-21"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-4081/">CVE-2010-4081</cve>
	<bugzilla href="https://bugzilla.suse.com/642312">SUSE bug 642312</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104158" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4158</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4158" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4158" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4158" ref_url="https://www.suse.com/security/cve/CVE-2010-4158" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0048-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users to obtain potentially sensitive information from kernel stack memory via a crafted socket filter.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-4158/">CVE-2010-4158</cve>
	<bugzilla href="https://bugzilla.suse.com/652563">SUSE bug 652563</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104160" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4160</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4160" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4160" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4160" ref_url="https://www.suse.com/security/cve/CVE-2010-4160" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0048-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (heap memory corruption and panic) or possibly gain privileges via a crafted sendto call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-22"/>
	<updated date="2023-02-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4160/">CVE-2010-4160</cve>
	<bugzilla href="https://bugzilla.suse.com/652939">SUSE bug 652939</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104162" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4162</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4162" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4162" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4162" ref_url="https://www.suse.com/security/cve/CVE-2010-4162" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2010:060" ref_url="https://lists.opensuse.org/opensuse-security-announce/2010-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0048-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4162/">CVE-2010-4162</cve>
	<bugzilla href="https://bugzilla.suse.com/652945">SUSE bug 652945</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104163" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4163</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4163" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4163" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4163" ref_url="https://www.suse.com/security/cve/CVE-2010-4163" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0048-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4163/">CVE-2010-4163</cve>
	<bugzilla href="https://bugzilla.suse.com/652945">SUSE bug 652945</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/662202">SUSE bug 662202</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104165" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4165</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4165" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4165" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4165" ref_url="https://www.suse.com/security/cve/CVE-2010-4165" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0048-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a denial of service (OOPS) via a setsockopt call that specifies a small value, leading to a divide-by-zero error or incorrect use of a signed integer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4165/">CVE-2010-4165</cve>
	<bugzilla href="https://bugzilla.suse.com/653258">SUSE bug 653258</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104169" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4169</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4169" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4169" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4169" ref_url="https://www.suse.com/security/cve/CVE-2010-4169" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0048-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4169/">CVE-2010-4169</cve>
	<bugzilla href="https://bugzilla.suse.com/653930">SUSE bug 653930</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104242" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4242</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4242" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4242" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4242" ref_url="https://www.suse.com/security/cve/CVE-2010-4242" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
    <description>
    The hci_uart_tty_open function in the HCI UART driver (drivers/bluetooth/hci_ldisc.c) in the Linux kernel 2.6.36, and possibly other versions, does not verify whether the tty has a write operation, which allows local users to cause a denial of service (NULL pointer dereference) via vectors related to the Bluetooth driver.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4242/">CVE-2010-4242</cve>
	<bugzilla href="https://bugzilla.suse.com/655451">SUSE bug 655451</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104243" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4243</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4243" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4243" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4243" ref_url="https://www.suse.com/security/cve/CVE-2010-4243" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-22"/>
	<updated date="2023-02-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4243/">CVE-2010-4243</cve>
	<bugzilla href="https://bugzilla.suse.com/655220">SUSE bug 655220</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/746947">SUSE bug 746947</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104248" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4248</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4248" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4248" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4248" ref_url="https://www.suse.com/security/cve/CVE-2010-4248" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
    <description>
    Race condition in the __exit_signal function in kernel/exit.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors related to multithreaded exec, the use of a thread group leader in kernel/posix-cpu-timers.c, and the selection of a new thread group leader in the de_thread function in fs/exec.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-22"/>
	<updated date="2023-02-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4248/">CVE-2010-4248</cve>
	<bugzilla href="https://bugzilla.suse.com/655468">SUSE bug 655468</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104249" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4249</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4249" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4249" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4249" ref_url="https://www.suse.com/security/cve/CVE-2010-4249" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via crafted use of the socketpair and sendmsg system calls for SOCK_SEQPACKET sockets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-18"/>
	<updated date="2023-02-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4249/">CVE-2010-4249</cve>
	<bugzilla href="https://bugzilla.suse.com/655696">SUSE bug 655696</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/656153">SUSE bug 656153</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104250" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4250</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4250" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4250" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4250" ref_url="https://www.suse.com/security/cve/CVE-2010-4250" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
    <description>
    Memory leak in the inotify_init1 function in fs/notify/inotify/inotify_user.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory consumption) via vectors involving failed attempts to create files.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4250/">CVE-2010-4250</cve>
	<bugzilla href="https://bugzilla.suse.com/655693">SUSE bug 655693</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104251" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4251</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4251" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4251" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4251" ref_url="https://www.suse.com/security/cve/CVE-2010-4251" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The socket implementation in net/core/sock.c in the Linux kernel before 2.6.34 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service (memory consumption) by sending a large amount of network traffic, as demonstrated by netperf UDP tests.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-20"/>
	<updated date="2023-02-20"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2010-4251/">CVE-2010-4251</cve>
	<bugzilla href="https://bugzilla.suse.com/643138">SUSE bug 643138</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/655973">SUSE bug 655973</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/826455">SUSE bug 826455</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104256" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4256</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4256" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4256" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4256" ref_url="https://www.suse.com/security/cve/CVE-2010-4256" source="SUSE CVE"/>
    <description>
    The pipe_fcntl function in fs/pipe.c in the Linux kernel before 2.6.37 does not properly determine whether a file is a named pipe, which allows local users to cause a denial of service via an F_SETPIPE_SZ fcntl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4256/">CVE-2010-4256</cve>
	<bugzilla href="https://bugzilla.suse.com/656483">SUSE bug 656483</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104258" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4258</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4258" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4258" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4258" ref_url="https://www.suse.com/security/cve/CVE-2010-4258" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:004" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0048-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-4258/">CVE-2010-4258</cve>
	<bugzilla href="https://bugzilla.suse.com/657350">SUSE bug 657350</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104263" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4263</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4263" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4263" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4263" ref_url="https://www.suse.com/security/cve/CVE-2010-4263" source="SUSE CVE"/>
    <description>
    The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34, when Single Root I/O Virtualization (SR-IOV) and promiscuous mode are enabled but no VLANs are registered, allows remote attackers to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact via a VLAN tagged frame.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-18"/>
	<updated date="2023-02-18"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-4263/">CVE-2010-4263</cve>
	<bugzilla href="https://bugzilla.suse.com/657716">SUSE bug 657716</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104342" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4342</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4342" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4342" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4342" ref_url="https://www.suse.com/security/cve/CVE-2010-4342" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The aun_incoming function in net/econet/af_econet.c in the Linux kernel before 2.6.37-rc6, when Econet is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending an Acorn Universal Networking (AUN) packet over UDP.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-4342/">CVE-2010-4342</cve>
	<bugzilla href="https://bugzilla.suse.com/658461">SUSE bug 658461</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104343" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4343</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4343" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4343" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4343" ref_url="https://www.suse.com/security/cve/CVE-2010-4343" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
    <description>
    drivers/scsi/bfa/bfa_core.c in the Linux kernel before 2.6.35 does not initialize a certain port data structure, which allows local users to cause a denial of service (system crash) via read operations on an fc_host statistics file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-17"/>
	<updated date="2023-02-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2010-4343/">CVE-2010-4343</cve>
	<bugzilla href="https://bugzilla.suse.com/658178">SUSE bug 658178</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104346" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4346</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4346" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4346" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4346" ref_url="https://www.suse.com/security/cve/CVE-2010-4346" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
    <description>
    The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL pointer dereference attacks via a crafted assembly-language application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4346/">CVE-2010-4346</cve>
	<bugzilla href="https://bugzilla.suse.com/658720">SUSE bug 658720</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104347" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4347</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4347" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4347" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4347" ref_url="https://www.suse.com/security/cve/CVE-2010-4347" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:001" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:007" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_init function in drivers/acpi/debugfs.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-17"/>
	<updated date="2023-02-17"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2010-4347/">CVE-2010-4347</cve>
	<bugzilla href="https://bugzilla.suse.com/659076">SUSE bug 659076</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104527" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4527</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4527" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4527" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4527" ref_url="https://www.suse.com/security/cve/CVE-2010-4527" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:008" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
    <description>
    The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-21"/>
	<updated date="2023-02-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4527/">CVE-2010-4527</cve>
	<bugzilla href="https://bugzilla.suse.com/661945">SUSE bug 661945</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104565" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4565</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4565" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4565" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4565" ref_url="https://www.suse.com/security/cve/CVE-2010-4565" source="SUSE CVE"/>
    <description>
    The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containing a kernel memory address, which allows local users to obtain potentially sensitive information about kernel memory use by listing this filename.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-16"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2010-4565/">CVE-2010-4565</cve>
	<bugzilla href="https://bugzilla.suse.com/1161355">SUSE bug 1161355</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/651218">SUSE bug 651218</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104648" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4648</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4648" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4648" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4648" ref_url="https://www.suse.com/security/cve/CVE-2010-4648" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
    <description>
    The orinoco_ioctl_set_auth function in drivers/net/wireless/orinoco/wext.c in the Linux kernel before 2.6.37 does not properly implement a TKIP protection mechanism, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading Wi-Fi frames.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4648/">CVE-2010-4648</cve>
	<bugzilla href="https://bugzilla.suse.com/662951">SUSE bug 662951</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104649" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4649</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4649" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4649" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4649" ref_url="https://www.suse.com/security/cve/CVE-2010-4649" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a certain structure member.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-4649/">CVE-2010-4649</cve>
	<bugzilla href="https://bugzilla.suse.com/662953">SUSE bug 662953</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/690537">SUSE bug 690537</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20104805" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-4805</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-4805" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4805" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-4805" ref_url="https://www.suse.com/security/cve/CVE-2010-4805" source="SUSE CVE"/>
    <description>
    The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service by sending a large amount of network traffic, related to the sk_add_backlog function and the sk_rmem_alloc socket field.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4251.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2010-4805/">CVE-2010-4805</cve>
	<bugzilla href="https://bugzilla.suse.com/698190">SUSE bug 698190</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20105107" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-5107</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-5107" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5107" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-5107" ref_url="https://www.suse.com/security/cve/CVE-2010-5107" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-August/000579.html" source="SUSE-SU"/>
    <description>
    The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-5107/">CVE-2010-5107</cve>
	<bugzilla href="https://bugzilla.suse.com/1074631">SUSE bug 1074631</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/802639">SUSE bug 802639</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/841638">SUSE bug 841638</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/858359">SUSE bug 858359</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/880259">SUSE bug 880259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/881234">SUSE bug 881234</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/992991">SUSE bug 992991</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/996040">SUSE bug 996040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333996" comment="openssh is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20105313" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-5313</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-5313" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5313" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-5313" ref_url="https://www.suse.com/security/cve/CVE-2010-5313" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
    <description>
    Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2010-5313/">CVE-2010-5313</cve>
	<bugzilla href="https://bugzilla.suse.com/905312">SUSE bug 905312</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/907822">SUSE bug 907822</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20105321" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-5321</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-5321" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5321" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-5321" ref_url="https://www.suse.com/security/cve/CVE-2010-5321" source="SUSE CVE"/>
    <description>
    Memory leak in drivers/media/video/videobuf-core.c in the videobuf subsystem in the Linux kernel 2.6.x through 4.x allows local users to cause a denial of service (memory consumption) by leveraging /dev/video access for a series of mmap calls that require new allocations, a different vulnerability than CVE-2007-6761. NOTE: as of 2016-06-18, this affects only 11 drivers that have not been updated to use videobuf2 instead of videobuf.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2010-5321/">CVE-2010-5321</cve>
	<bugzilla href="https://bugzilla.suse.com/1035720">SUSE bug 1035720</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/916831">SUSE bug 916831</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20105331" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-5331</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-5331" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5331" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-5331" ref_url="https://www.suse.com/security/cve/CVE-2010-5331" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** In the Linux kernel before 2.6.34, a range check issue in drivers/gpu/drm/radeon/atombios.c could cause an off by one (buffer overflow) problem. NOTE: At least one Linux maintainer believes that this CVE is incorrectly assigned and should be rejected because the value is hard coded and are not user-controllable where it is used.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-07"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2010-5331/">CVE-2010-5331</cve>
	<bugzilla href="https://bugzilla.suse.com/1143173">SUSE bug 1143173</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20105332" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2010-5332</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2010-5332" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5332" source="CVE"/>
    <reference ref_id="SUSE CVE-2010-5332" ref_url="https://www.suse.com/security/cve/CVE-2010-5332" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 2.6.37, an out of bounds array access happened in drivers/net/mlx4/port.c. When searching for a free entry in either mlx4_register_vlan() or mlx4_register_mac(), and there is no free entry, the loop terminates without updating the local variable free thus causing out of array bounds access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-08-05"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="5.6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2010-5332/">CVE-2010-5332</cve>
	<bugzilla href="https://bugzilla.suse.com/1143170">SUSE bug 1143170</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20110010" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-0010</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-0010" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0010" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-0010" ref_url="https://www.suse.com/security/cve/CVE-2011-0010" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2011:002" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0050-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-01/msg00022.html" source="SUSE-SU"/>
    <description>
    check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-12"/>
	<updated date="2023-07-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-0010/">CVE-2011-0010</cve>
	<bugzilla href="https://bugzilla.suse.com/663881">SUSE bug 663881</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334290" comment="sudo is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20110463" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-0463</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-0463" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0463" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-0463" ref_url="https://www.suse.com/security/cve/CVE-2011-0463" source="SUSE CVE"/>
    <description>
    The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which allows local users to obtain potentially sensitive information from uninitialized disk locations by reading a file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-09"/>
	<updated date="2023-07-09"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-0463/">CVE-2011-0463</cve>
	<bugzilla href="https://bugzilla.suse.com/670595">SUSE bug 670595</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/673037">SUSE bug 673037</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20110521" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-0521</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-0521" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0521" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-0521" ref_url="https://www.suse.com/security/cve/CVE-2011-0521" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The dvb_ca_ioctl function in drivers/media/dvb/ttpci/av7110_ca.c in the Linux kernel before 2.6.38-rc2 does not check the sign of a certain integer field, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a negative value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-16"/>
	<updated date="2023-02-16"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-0521/">CVE-2011-0521</cve>
	<bugzilla href="https://bugzilla.suse.com/666836">SUSE bug 666836</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20110541" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-0541</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-0541" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0541" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-0541" ref_url="https://www.suse.com/security/cve/CVE-2011-0541" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2011:005" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0264-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0265-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00039.html" source="SUSE-SU"/>
    <description>
    fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-0541/">CVE-2011-0541</cve>
	<bugzilla href="https://bugzilla.suse.com/668820">SUSE bug 668820</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/685055">SUSE bug 685055</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481128" comment="fuse-2.9.7-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481131" comment="libfuse2-2.9.7-3.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20110699" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-0699</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-0699" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0699" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-0699" ref_url="https://www.suse.com/security/cve/CVE-2011-0699" source="SUSE CVE"/>
    <description>
    Integer signedness error in the btrfs_ioctl_space_info function in the Linux kernel 2.6.37 allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted slot value.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2011-0699/">CVE-2011-0699</cve>
	<bugzilla href="https://bugzilla.suse.com/1167455">SUSE bug 1167455</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20110709" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-0709</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-0709" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0709" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-0709" ref_url="https://www.suse.com/security/cve/CVE-2011-0709" source="SUSE CVE"/>
    <description>
    The br_mdb_ip_get function in net/bridge/br_multicast.c in the Linux kernel before 2.6.35-rc5 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an IGMP packet, related to lack of a multicast table.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-16"/>
	<updated date="2023-02-16"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-0709/">CVE-2011-0709</cve>
	<bugzilla href="https://bugzilla.suse.com/672493">SUSE bug 672493</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20110710" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-0710</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-0710" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0710" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-0710" ref_url="https://www.suse.com/security/cve/CVE-2011-0710" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The task_show_regs function in arch/s390/kernel/traps.c in the Linux kernel before 2.6.38-rc4-next-20110216 on the s390 platform allows local users to obtain the values of the registers of an arbitrary process by reading a status file under /proc/.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-17"/>
	<updated date="2023-02-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-0710/">CVE-2011-0710</cve>
	<bugzilla href="https://bugzilla.suse.com/672492">SUSE bug 672492</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20110711" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-0711</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-0711" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0711" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-0711" ref_url="https://www.suse.com/security/cve/CVE-2011-0711" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:015" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
    <description>
    The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-0711/">CVE-2011-0711</cve>
	<bugzilla href="https://bugzilla.suse.com/672505">SUSE bug 672505</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/672524">SUSE bug 672524</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20110712" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-0712</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-0712" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0712" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-0712" ref_url="https://www.suse.com/security/cve/CVE-2011-0712" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:012" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0159-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
    <description>
    Multiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kernel before 2.6.38-rc4-next-20110215 might allow attackers to cause a denial of service or possibly have unspecified other impact via a long USB device name, related to (1) the snd_usb_caiaq_audio_init function in sound/usb/caiaq/audio.c and (2) the snd_usb_caiaq_midi_init function in sound/usb/caiaq/midi.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-01"/>
	<updated date="2023-03-01"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-0712/">CVE-2011-0712</cve>
	<bugzilla href="https://bugzilla.suse.com/672499">SUSE bug 672499</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20110726" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-0726</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-0726" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0726" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-0726" ref_url="https://www.suse.com/security/cve/CVE-2011-0726" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:034" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0899-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00023.html" source="SUSE-SU"/>
    <description>
    The do_task_stat function in fs/proc/array.c in the Linux kernel before 2.6.39-rc1 does not perform an expected uid check, which makes it easier for local users to defeat the ASLR protection mechanism by reading the start_code and end_code fields in the /proc/#####/stat file for a process executing a PIE binary.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-0726/">CVE-2011-0726</cve>
	<bugzilla href="https://bugzilla.suse.com/701254">SUSE bug 701254</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20110999" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-0999</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-0999" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0999" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-0999" ref_url="https://www.suse.com/security/cve/CVE-2011-0999" source="SUSE CVE"/>
    <description>
    mm/huge_memory.c in the Linux kernel before 2.6.38-rc5 does not prevent creation of a transparent huge page (THP) during the existence of a temporary stack for an exec system call, which allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-0999/">CVE-2011-0999</cve>
	<bugzilla href="https://bugzilla.suse.com/1183531">SUSE bug 1183531</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/673261">SUSE bug 673261</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111010" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1010</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1010" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1010" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1010" ref_url="https://www.suse.com/security/cve/CVE-2011-1010" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the mac_partition function in fs/partitions/mac.c in the Linux kernel before 2.6.37.2 allows local users to cause a denial of service (panic) or possibly have unspecified other impact via a malformed Mac OS partition table.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1010/">CVE-2011-1010</cve>
	<bugzilla href="https://bugzilla.suse.com/673929">SUSE bug 673929</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/690537">SUSE bug 690537</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111012" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1012</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1012" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1012" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1012" ref_url="https://www.suse.com/security/cve/CVE-2011-1012" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
    <description>
    The ldm_parse_vmdb function in fs/partitions/ldm.c in the Linux kernel before 2.6.38-rc6-git6 does not validate the VBLK size value in the VMDB structure in an LDM partition table, which allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted partition table.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-22"/>
	<updated date="2023-02-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1012/">CVE-2011-1012</cve>
	<bugzilla href="https://bugzilla.suse.com/674254">SUSE bug 674254</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111013" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1013</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1013" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1013" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1013" ref_url="https://www.suse.com/security/cve/CVE-2011-1013" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00003.html" source="SUSE-SU"/>
    <description>
    Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/drm_irq.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.38 and (2) sys/dev/pci/drm/drm_irq.c in the kernel in OpenBSD before 4.9 allows local users to trigger out-of-bounds write operations, and consequently cause a denial of service (system crash) or possibly have unspecified other impact, via a crafted num_crtcs (aka vb_num) structure member in an ioctl argument.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-1013/">CVE-2011-1013</cve>
	<bugzilla href="https://bugzilla.suse.com/674691">SUSE bug 674691</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111016" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1016</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1016" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1016" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1016" ref_url="https://www.suse.com/security/cve/CVE-2011-1016" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00003.html" source="SUSE-SU"/>
    <description>
    The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve registers, which allows local users to write to arbitrary memory locations associated with (1) Video RAM (aka VRAM) or (2) the Graphics Translation Table (GTT) via crafted values.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-21"/>
	<updated date="2023-02-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1016/">CVE-2011-1016</cve>
	<bugzilla href="https://bugzilla.suse.com/674691">SUSE bug 674691</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/674693">SUSE bug 674693</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111017" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1017</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1017" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1017" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1017" ref_url="https://www.suse.com/security/cve/CVE-2011-1017" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:034" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0899-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0860-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00003.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-06"/>
	<updated date="2023-07-06"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-1017/">CVE-2011-1017</cve>
	<bugzilla href="https://bugzilla.suse.com/674648">SUSE bug 674648</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/698221">SUSE bug 698221</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111019" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1019</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1019" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1019" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1019" ref_url="https://www.suse.com/security/cve/CVE-2011-1019" source="SUSE CVE"/>
    <description>
    The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1019/">CVE-2011-1019</cve>
	<bugzilla href="https://bugzilla.suse.com/674978">SUSE bug 674978</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111020" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1020</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1020" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1020" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1020" ref_url="https://www.suse.com/security/cve/CVE-2011-1020" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0860-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00003.html" source="SUSE-SU"/>
    <description>
    The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1020/">CVE-2011-1020</cve>
	<bugzilla href="https://bugzilla.suse.com/674982">SUSE bug 674982</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111021" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1021</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1021" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1021" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1021" ref_url="https://www.suse.com/security/cve/CVE-2011-1021" source="SUSE CVE"/>
    <description>
    drivers/acpi/debugfs.c in the Linux kernel before 3.0 allows local users to modify arbitrary kernel memory locations by leveraging root privileges to write to the /sys/kernel/debug/acpi/custom_method file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4347.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1021/">CVE-2011-1021</cve>
	<bugzilla href="https://bugzilla.suse.com/674988">SUSE bug 674988</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111023" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1023</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1023" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1023" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1023" ref_url="https://www.suse.com/security/cve/CVE-2011-1023" source="SUSE CVE"/>
    <description>
    The Reliable Datagram Sockets (RDS) subsystem in the Linux kernel before 2.6.38 does not properly handle congestion map updates, which allows local users to cause a denial of service (BUG_ON and system crash) via vectors involving (1) a loopback (aka loop) transmit operation or (2) an InfiniBand (aka ib) transmit operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1023/">CVE-2011-1023</cve>
	<bugzilla href="https://bugzilla.suse.com/676707">SUSE bug 676707</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/703752">SUSE bug 703752</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111076" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1076</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1076" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1076" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1076" ref_url="https://www.suse.com/security/cve/CVE-2011-1076" source="SUSE CVE"/>
    <description>
    net/dns_resolver/dns_key.c in the Linux kernel before 2.6.38 allows remote DNS servers to cause a denial of service (NULL pointer dereference and OOPS) by not providing a valid response to a DNS query, as demonstrated by an erroneous grand.centrall.org query, which triggers improper handling of error data within a DNS resolver key.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1076/">CVE-2011-1076</cve>
	<bugzilla href="https://bugzilla.suse.com/702355">SUSE bug 702355</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111078" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1078</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1078" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1078" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1078" ref_url="https://www.suse.com/security/cve/CVE-2011-1078" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
    <description>
    The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-1078/">CVE-2011-1078</cve>
	<bugzilla href="https://bugzilla.suse.com/676601">SUSE bug 676601</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111079" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1079</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1079" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1079" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1079" ref_url="https://www.suse.com/security/cve/CVE-2011-1079" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
    <description>
    The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1079/">CVE-2011-1079</cve>
	<bugzilla href="https://bugzilla.suse.com/1139868">SUSE bug 1139868</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/676601">SUSE bug 676601</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111080" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1080</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1080" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1080" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1080" ref_url="https://www.suse.com/security/cve/CVE-2011-1080" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
    <description>
    The do_replace function in net/bridge/netfilter/ebtables.c in the Linux kernel before 2.6.39 does not ensure that a certain name field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability to replace a table, and then reading a modprobe command line.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-1080/">CVE-2011-1080</cve>
	<bugzilla href="https://bugzilla.suse.com/676602">SUSE bug 676602</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111082" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1082</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1082" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1082" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1082" ref_url="https://www.suse.com/security/cve/CVE-2011-1082" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
    <description>
    fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1082/">CVE-2011-1082</cve>
	<bugzilla href="https://bugzilla.suse.com/676202">SUSE bug 676202</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/690537">SUSE bug 690537</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111083" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1083</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1083" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1083" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1083" ref_url="https://www.suse.com/security/cve/CVE-2011-1083" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0554-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0554-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0616-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0540-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-04/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-16"/>
	<updated date="2023-02-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1083/">CVE-2011-1083</cve>
	<bugzilla href="https://bugzilla.suse.com/676204">SUSE bug 676204</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/690537">SUSE bug 690537</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111090" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1090</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1090" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1090" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1090" ref_url="https://www.suse.com/security/cve/CVE-2011-1090" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
    <description>
    The __nfs4_proc_set_acl function in fs/nfs/nfs4proc.c in the Linux kernel before 2.6.38 stores NFSv4 ACL data in memory that is allocated by kmalloc but not properly freed, which allows local users to cause a denial of service (panic) via a crafted attempt to set an ACL.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-20"/>
	<updated date="2023-02-20"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1090/">CVE-2011-1090</cve>
	<bugzilla href="https://bugzilla.suse.com/677286">SUSE bug 677286</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111093" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1093</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1093" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1093" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1093" ref_url="https://www.suse.com/security/cve/CVE-2011-1093" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:034" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0899-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
    <description>
    The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending a DCCP-Close packet followed by a DCCP-Reset packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-06"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-1093/">CVE-2011-1093</cve>
	<bugzilla href="https://bugzilla.suse.com/677676">SUSE bug 677676</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111098" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1098</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1098" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1098" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1098" ref_url="https://www.suse.com/security/cve/CVE-2011-1098" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2011:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0536-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-05/msg00055.html" source="SUSE-SU"/>
    <description>
    Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-1098/">CVE-2011-1098</cve>
	<bugzilla href="https://bugzilla.suse.com/1007000">SUSE bug 1007000</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136195">SUSE bug 1136195</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/677335">SUSE bug 677335</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/677336">SUSE bug 677336</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481596" comment="logrotate-3.13.0-4.3.9 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111154" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1154</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1154" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1154" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1154" ref_url="https://www.suse.com/security/cve/CVE-2011-1154" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2011:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0536-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-05/msg00055.html" source="SUSE-SU"/>
    <description>
    The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1154/">CVE-2011-1154</cve>
	<bugzilla href="https://bugzilla.suse.com/677335">SUSE bug 677335</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/679661">SUSE bug 679661</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/681984">SUSE bug 681984</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481596" comment="logrotate-3.13.0-4.3.9 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1155" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1155" ref_url="https://www.suse.com/security/cve/CVE-2011-1155" source="SUSE CVE"/>
		<reference ref_id="SUSE-SR:2011:010" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0536-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-05/msg00055.html" source="SUSE-SU"/>
    <description>
    The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-02"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-1155/">CVE-2011-1155</cve>
	<bugzilla href="https://bugzilla.suse.com/677335">SUSE bug 677335</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/679662">SUSE bug 679662</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481596" comment="logrotate-3.13.0-4.3.9 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111160" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1160</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1160" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1160" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1160" ref_url="https://www.suse.com/security/cve/CVE-2011-1160" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00003.html" source="SUSE-SU"/>
    <description>
    The tpm_open function in drivers/char/tpm/tpm.c in the Linux kernel before 2.6.39 does not initialize a certain buffer, which allows local users to obtain potentially sensitive information from kernel memory via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-1160/">CVE-2011-1160</cve>
	<bugzilla href="https://bugzilla.suse.com/680040">SUSE bug 680040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111162" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1162</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1162" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1162" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1162" ref_url="https://www.suse.com/security/cve/CVE-2011-1162" source="SUSE CVE"/>
    <description>
    The tpm_read function in the Linux kernel 2.6 does not properly clear memory, which might allow local users to read the results of the previous TPM command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-1162/">CVE-2011-1162</cve>
	<bugzilla href="https://bugzilla.suse.com/680040">SUSE bug 680040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111163" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1163</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1163" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1163" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1163" ref_url="https://www.suse.com/security/cve/CVE-2011-1163" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
    <description>
    The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related to partition-table parsing.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-21"/>
	<updated date="2023-02-21"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-1163/">CVE-2011-1163</cve>
	<bugzilla href="https://bugzilla.suse.com/679812">SUSE bug 679812</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111169" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1169</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1169" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1169" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1169" ref_url="https://www.suse.com/security/cve/CVE-2011-1169" source="SUSE CVE"/>
    <description>
    Array index error in the asihpi_hpi_ioctl function in sound/pci/asihpi/hpioctl.c in the AudioScience HPI driver in the Linux kernel before 2.6.38.1 might allow local users to cause a denial of service (memory corruption) or possibly gain privileges via a crafted adapter index value that triggers access to an invalid kernel pointer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-1169/">CVE-2011-1169</cve>
	<bugzilla href="https://bugzilla.suse.com/680816">SUSE bug 680816</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111170" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1170</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1170" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1170" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1170" ref_url="https://www.suse.com/security/cve/CVE-2011-1170" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
    <description>
    net/ipv4/netfilter/arp_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-1170/">CVE-2011-1170</cve>
	<bugzilla href="https://bugzilla.suse.com/681180">SUSE bug 681180</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111171" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1171</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1171" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1171" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1171" ref_url="https://www.suse.com/security/cve/CVE-2011-1171" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
    <description>
    net/ipv4/netfilter/ip_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-1171/">CVE-2011-1171</cve>
	<bugzilla href="https://bugzilla.suse.com/681181">SUSE bug 681181</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111172" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1172</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1172" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1172" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1172" ref_url="https://www.suse.com/security/cve/CVE-2011-1172" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
    <description>
    net/ipv6/netfilter/ip6_tables.c in the IPv6 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability to issue a crafted request, and then reading the argument to the resulting modprobe process.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-1172/">CVE-2011-1172</cve>
	<bugzilla href="https://bugzilla.suse.com/681185">SUSE bug 681185</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/693976">SUSE bug 693976</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111173" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1173</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1173" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1173" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1173" ref_url="https://www.suse.com/security/cve/CVE-2011-1173" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain potentially sensitive information from kernel stack memory by reading uninitialized data in the ah field of an Acorn Universal Networking (AUN) packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1173/">CVE-2011-1173</cve>
	<bugzilla href="https://bugzilla.suse.com/681186">SUSE bug 681186</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111182" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1182</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1182" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1182" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1182" ref_url="https://www.suse.com/security/cve/CVE-2011-1182" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
    <description>
    kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1182/">CVE-2011-1182</cve>
	<bugzilla href="https://bugzilla.suse.com/681826">SUSE bug 681826</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/690537">SUSE bug 690537</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111410" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1410</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1410" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1410" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1410" ref_url="https://www.suse.com/security/cve/CVE-2011-1410" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2011-1410/">CVE-2011-1410</cve>
	<bugzilla href="https://bugzilla.suse.com/706386">SUSE bug 706386</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333996" comment="openssh is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111478" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1478</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1478" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1478" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1478" ref_url="https://www.suse.com/security/cve/CVE-2011-1478" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
    <description>
    The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset the values of certain structure members, which might allow remote attackers to cause a denial of service (NULL pointer dereference) via a malformed VLAN frame.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-03"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1478/">CVE-2011-1478</cve>
	<bugzilla href="https://bugzilla.suse.com/682965">SUSE bug 682965</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/698450">SUSE bug 698450</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111479" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1479</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1479" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1479" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1479" ref_url="https://www.suse.com/security/cve/CVE-2011-1479" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2011:0860-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00003.html" source="SUSE-SU"/>
    <description>
    Double free vulnerability in the inotify subsystem in the Linux kernel before 2.6.39 allows local users to cause a denial of service (system crash) via vectors involving failed attempts to create files. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-4250.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-18"/>
	<updated date="2023-02-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1479/">CVE-2011-1479</cve>
	<bugzilla href="https://bugzilla.suse.com/655693">SUSE bug 655693</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111493" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1493</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1493" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1493" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1493" ref_url="https://www.suse.com/security/cve/CVE-2011-1493" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:017" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:020" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0346-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0399-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
    <description>
    Array index error in the rose_parse_national function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by composing FAC_NATIONAL_DIGIS data that specifies a large number of digipeaters, and then sending this data to a ROSE socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-1493/">CVE-2011-1493</cve>
	<bugzilla href="https://bugzilla.suse.com/681175">SUSE bug 681175</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111494" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1494</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1494" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1494" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1494" ref_url="https://www.suse.com/security/cve/CVE-2011-1494" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:034" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0899-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the _ctl_do_mpt_command function in drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier might allow local users to gain privileges or cause a denial of service (memory corruption) via an ioctl call specifying a crafted value that triggers a heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-07"/>
	<updated date="2023-03-05"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1494/">CVE-2011-1494</cve>
	<bugzilla href="https://bugzilla.suse.com/685402">SUSE bug 685402</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111495" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1495</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1495" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1495" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1495" ref_url="https://www.suse.com/security/cve/CVE-2011-1495" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:034" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0899-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
    <description>
    drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier does not validate (1) length and (2) offset values before performing memory copy operations, which might allow local users to gain privileges, cause a denial of service (memory corruption), or obtain sensitive information from kernel memory via a crafted ioctl call, related to the _ctl_do_mpt_command and _ctl_diag_read_buffer functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-11"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-1495/">CVE-2011-1495</cve>
	<bugzilla href="https://bugzilla.suse.com/685402">SUSE bug 685402</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111573" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1573</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1573" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1573" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1573" ref_url="https://www.suse.com/security/cve/CVE-2011-1573" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:019" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT and (2) INIT ACK chunks, which allows remote attackers to cause a denial of service (OOPS) via crafted packet data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-1573/">CVE-2011-1573</cve>
	<bugzilla href="https://bugzilla.suse.com/686813">SUSE bug 686813</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111576" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1576</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1576" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1576" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1576" ref_url="https://www.suse.com/security/cve/CVE-2011-1576" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0364-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00004.html" source="SUSE-SU"/>
    <description>
    The Generic Receive Offload (GRO) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux 5 and 2.6.32 on Red Hat Enterprise Linux 6, as used in Red Hat Enterprise Virtualization (RHEV) Hypervisor and other products, allows remote attackers to cause a denial of service via crafted VLAN packets that are processed by the napi_reuse_skb function, leading to (1) a memory leak or (2) memory corruption, a different vulnerability than CVE-2011-1478.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-06"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1576/">CVE-2011-1576</cve>
	<bugzilla href="https://bugzilla.suse.com/698450">SUSE bug 698450</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111577" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1577</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1577" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1577" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1577" ref_url="https://www.suse.com/security/cve/CVE-2011-1577" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:021" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:042" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0364-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0416-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-04/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00003.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the is_gpt_valid function in fs/partitions/efi.c in the Linux kernel 2.6.38 and earlier allows physically proximate attackers to cause a denial of service (OOPS) or possibly have unspecified other impact via a crafted size of the EFI GUID partition-table header on removable media.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-17"/>
	<updated date="2023-05-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1577/">CVE-2011-1577</cve>
	<bugzilla href="https://bugzilla.suse.com/687113">SUSE bug 687113</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/692784">SUSE bug 692784</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111585" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1585</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1585" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1585" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1585" ref_url="https://www.suse.com/security/cve/CVE-2011-1585" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:026" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:027" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:034" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0711-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0899-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00003.html" source="SUSE-SU"/>
    <description>
    The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-1585/">CVE-2011-1585</cve>
	<bugzilla href="https://bugzilla.suse.com/687812">SUSE bug 687812</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111598" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1598</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1598" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1598" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1598" ref_url="https://www.suse.com/security/cve/CVE-2011-1598" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
    <description>
    The bcm_release function in net/can/bcm.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1598/">CVE-2011-1598</cve>
	<bugzilla href="https://bugzilla.suse.com/688685">SUSE bug 688685</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/689038">SUSE bug 689038</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111745" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1745</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1745" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1745" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1745" ref_url="https://www.suse.com/security/cve/CVE-2011-1745" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:034" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0899-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0860-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00002.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_BIND agp_ioctl ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-19"/>
	<updated date="2023-02-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1745/">CVE-2011-1745</cve>
	<bugzilla href="https://bugzilla.suse.com/689797">SUSE bug 689797</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/693043">SUSE bug 693043</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111747" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1747</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1747" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1747" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1747" ref_url="https://www.suse.com/security/cve/CVE-2011-1747" source="SUSE CVE"/>
    <description>
    The agp subsystem in the Linux kernel 2.6.38.5 and earlier does not properly restrict memory allocation by the (1) AGPIOC_RESERVE and (2) AGPIOC_ALLOCATE ioctls, which allows local users to cause a denial of service (memory consumption) by making many calls to these ioctls.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-03"/>
	<updated date="2023-03-03"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1747/">CVE-2011-1747</cve>
	<bugzilla href="https://bugzilla.suse.com/689797">SUSE bug 689797</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111767" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1767</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1767" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1767" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1767" ref_url="https://www.suse.com/security/cve/CVE-2011-1767" source="SUSE CVE"/>
    <description>
    net/ipv4/ip_gre.c in the Linux kernel before 2.6.34, when ip_gre is configured as a module, allows remote attackers to cause a denial of service (OOPS) by sending a packet during module loading.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1767/">CVE-2011-1767</cve>
	<bugzilla href="https://bugzilla.suse.com/692239">SUSE bug 692239</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111770" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1770</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1770" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1770" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1770" ref_url="https://www.suse.com/security/cve/CVE-2011-1770" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2012:0206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
    <description>
    Integer underflow in the dccp_parse_options function (net/dccp/options.c) in the Linux kernel before 2.6.33.14 allows remote attackers to cause a denial of service via a Datagram Congestion Control Protocol (DCCP) packet with an invalid feature options length, which triggers a buffer over-read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-08"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-1770/">CVE-2011-1770</cve>
	<bugzilla href="https://bugzilla.suse.com/692498">SUSE bug 692498</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111771" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1771</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1771" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1771" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1771" ref_url="https://www.suse.com/security/cve/CVE-2011-1771" source="SUSE CVE"/>
    <description>
    The cifs_close function in fs/cifs/file.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact by setting the O_DIRECT flag during an attempt to open a file on a CIFS filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2011-1771/">CVE-2011-1771</cve>
	<bugzilla href="https://bugzilla.suse.com/692497">SUSE bug 692497</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111776" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1776</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1776" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1776" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1776" ref_url="https://www.suse.com/security/cve/CVE-2011-1776" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:042" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1195-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:1221-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:1222-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00007.html" source="SUSE-SU"/>
    <description>
    The is_gpt_valid function in fs/partitions/efi.c in the Linux kernel before 2.6.39 does not check the size of an Extensible Firmware Interface (EFI) GUID Partition Table (GPT) entry, which allows physically proximate attackers to cause a denial of service (heap-based buffer overflow and OOPS) or obtain sensitive information from kernel heap memory by connecting a crafted GPT storage device, a different vulnerability than CVE-2011-1577.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-1776/">CVE-2011-1776</cve>
	<bugzilla href="https://bugzilla.suse.com/692784">SUSE bug 692784</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111833" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1833</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1833" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1833" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1833" ref_url="https://www.suse.com/security/cve/CVE-2011-1833" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0898-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0364-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:1221-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:1222-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00007.html" source="SUSE-SU"/>
    <description>
    Race condition in the ecryptfs_mount function in fs/ecryptfs/main.c in the eCryptfs subsystem in the Linux kernel before 3.1 allows local users to bypass intended file permissions via a mount.ecryptfs_private mount with a mismatched uid.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-1833/">CVE-2011-1833</cve>
	<bugzilla href="https://bugzilla.suse.com/709771">SUSE bug 709771</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/711539">SUSE bug 711539</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20111927" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-1927</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-1927" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1927" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-1927" ref_url="https://www.suse.com/security/cve/CVE-2011-1927" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2011:0860-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00002.html" source="SUSE-SU"/>
    <description>
    The ip_expire function in net/ipv4/ip_fragment.c in the Linux kernel before 2.6.39 does not properly construct ICMP_TIME_EXCEEDED packets after a timeout, which allows remote attackers to cause a denial of service (invalid pointer dereference) via crafted fragmented packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-1927/">CVE-2011-1927</cve>
	<bugzilla href="https://bugzilla.suse.com/694498">SUSE bug 694498</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112182" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2182</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2182" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2182" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2182" ref_url="https://www.suse.com/security/cve/CVE-2011-2182" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:034" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0899-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0860-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00003.html" source="SUSE-SU"/>
    <description>
    The ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel before 2.6.39.1 does not properly handle memory allocation for non-initial fragments, which might allow local users to conduct buffer overflow attacks, and gain privileges or obtain sensitive information, via a crafted LDM partition table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1017.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-2182/">CVE-2011-2182</cve>
	<bugzilla href="https://bugzilla.suse.com/674648">SUSE bug 674648</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/698221">SUSE bug 698221</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112189" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2189</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2189" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2189" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2189" ref_url="https://www.suse.com/security/cve/CVE-2011-2189" source="SUSE CVE"/>
    <description>
    net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-2189/">CVE-2011-2189</cve>
	<bugzilla href="https://bugzilla.suse.com/698449">SUSE bug 698449</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112203" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2203</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2203" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2203" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2203" ref_url="https://www.suse.com/security/cve/CVE-2011-2203" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0364-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
    <description>
    The hfs_find_init function in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and Oops) by mounting an HFS file system with a malformed MDB extent record.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-2203/">CVE-2011-2203</cve>
	<bugzilla href="https://bugzilla.suse.com/699709">SUSE bug 699709</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112213" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2213</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2213" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2213" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2213" ref_url="https://www.suse.com/security/cve/CVE-2011-2213" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
    <description>
    The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message, as demonstrated by an INET_DIAG_BC_JMP instruction with a zero yes value, a different vulnerability than CVE-2010-3880.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-18"/>
	<updated date="2023-02-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2213/">CVE-2011-2213</cve>
	<bugzilla href="https://bugzilla.suse.com/700879">SUSE bug 700879</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112482" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2482</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2482" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2482" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2482" ref_url="https://www.suse.com/security/cve/CVE-2011-2482" source="SUSE CVE"/>
    <description>
    A certain Red Hat patch to the sctp_sock_migrate function in net/sctp/socket.c in the Linux kernel before 2.6.21, as used in Red Hat Enterprise Linux (RHEL) 5, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) via a crafted SCTP packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-2482/">CVE-2011-2482</cve>
	<bugzilla href="https://bugzilla.suse.com/735611">SUSE bug 735611</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/750395">SUSE bug 750395</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112484" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2484</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2484" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2484" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2484" ref_url="https://www.suse.com/security/cve/CVE-2011-2484" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:034" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0899-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0860-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00003.html" source="SUSE-SU"/>
    <description>
    The add_del_listener function in kernel/taskstats.c in the Linux kernel 2.6.39.1 and earlier does not prevent multiple registrations of exit handlers, which allows local users to cause a denial of service (memory and CPU consumption), and bypass the OOM Killer, via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2484/">CVE-2011-2484</cve>
	<bugzilla href="https://bugzilla.suse.com/703153">SUSE bug 703153</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112491" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2491</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2491" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2491" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2491" ref_url="https://www.suse.com/security/cve/CVE-2011-2491" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:034" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0899-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0860-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00003.html" source="SUSE-SU"/>
    <description>
    The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 allows local users to cause a denial of service (system hang) via a LOCK_UN flock system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2491/">CVE-2011-2491</cve>
	<bugzilla href="https://bugzilla.suse.com/702013">SUSE bug 702013</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112492" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2492</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2492" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2492" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2492" ref_url="https://www.suse.com/security/cve/CVE-2011-2492" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
    <description>
    The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2cap_sock_getsockopt_old function in net/bluetooth/l2cap_sock.c and (2) the rfcomm_sock_getsockopt_old function in net/bluetooth/rfcomm/sock.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2492/">CVE-2011-2492</cve>
	<bugzilla href="https://bugzilla.suse.com/702014">SUSE bug 702014</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112493" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2493</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2493" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2493" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2493" ref_url="https://www.suse.com/security/cve/CVE-2011-2493" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2011:0860-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-08/msg00002.html" source="SUSE-SU"/>
    <description>
    The ext4_fill_super function in fs/ext4/super.c in the Linux kernel before 2.6.39 does not properly initialize a certain error-report data structure, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext4 filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-2493/">CVE-2011-2493</cve>
	<bugzilla href="https://bugzilla.suse.com/701998">SUSE bug 701998</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112494" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2494</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2494" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2494" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2494" ref_url="https://www.suse.com/security/cve/CVE-2011-2494" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0153-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0554-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0554-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-2494/">CVE-2011-2494</cve>
	<bugzilla href="https://bugzilla.suse.com/703156">SUSE bug 703156</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112497" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2497</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2497" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2497" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2497" ref_url="https://www.suse.com/security/cve/CVE-2011-2497" source="SUSE CVE"/>
    <description>
    Integer underflow in the l2cap_config_req function in net/bluetooth/l2cap_core.c in the Linux kernel before 3.0 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a small command-size value within the command header of a Logical Link Control and Adaptation Protocol (L2CAP) configuration request, leading to a buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-2497/">CVE-2011-2497</cve>
	<bugzilla href="https://bugzilla.suse.com/702286">SUSE bug 702286</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112517" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2517</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2517" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2517" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2517" ref_url="https://www.suse.com/security/cve/CVE-2011-2517" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:031" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0832-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    Multiple buffer overflows in net/wireless/nl80211.c in the Linux kernel before 2.6.39.2 allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability during scan operations with a long SSID value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-2517/">CVE-2011-2517</cve>
	<bugzilla href="https://bugzilla.suse.com/703410">SUSE bug 703410</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112518" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2518</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2518" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2518" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2518" ref_url="https://www.suse.com/security/cve/CVE-2011-2518" source="SUSE CVE"/>
    <description>
    The tomoyo_mount_acl function in security/tomoyo/mount.c in the Linux kernel before 2.6.39.2 calls the kern_path function with arguments taken directly from a mount system call, which allows local users to cause a denial of service (OOPS) or possibly have unspecified other impact via a NULL value for the device name.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-01"/>
	<updated date="2023-03-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2518/">CVE-2011-2518</cve>
	<bugzilla href="https://bugzilla.suse.com/703158">SUSE bug 703158</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112525" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2525</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2525" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2525" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2525" ref_url="https://www.suse.com/security/cve/CVE-2011-2525" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00004.html" source="SUSE-SU"/>
    <description>
    The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2011-2525/">CVE-2011-2525</cve>
	<bugzilla href="https://bugzilla.suse.com/735612">SUSE bug 735612</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112534" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2534</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2534" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2534" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2534" ref_url="https://www.suse.com/security/cve/CVE-2011-2534" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the clusterip_proc_write function in net/ipv4/netfilter/ipt_CLUSTERIP.c in the Linux kernel before 2.6.39 might allow local users to cause a denial of service or have unspecified other impact via a crafted write operation, related to string data that lacks a terminating '\0' character.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2534/">CVE-2011-2534</cve>
	<bugzilla href="https://bugzilla.suse.com/681182">SUSE bug 681182</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/702037">SUSE bug 702037</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112689" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2689</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2689" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2689" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2689" ref_url="https://www.suse.com/security/cve/CVE-2011-2689" source="SUSE CVE"/>
    <description>
    The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arranging for all resource groups to have too little free space.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2689/">CVE-2011-2689</cve>
	<bugzilla href="https://bugzilla.suse.com/710672">SUSE bug 710672</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112695" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2695</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2695" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2695" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2695" ref_url="https://www.suse.com/security/cve/CVE-2011-2695" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2011:1222-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00007.html" source="SUSE-SU"/>
    <description>
    Multiple off-by-one errors in the ext4 subsystem in the Linux kernel before 3.0-rc5 allow local users to cause a denial of service (BUG_ON and system crash) by accessing a sparse file in extent format with a write operation involving a block number corresponding to the largest possible 32-bit unsigned integer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2695/">CVE-2011-2695</cve>
	<bugzilla href="https://bugzilla.suse.com/706374">SUSE bug 706374</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112699" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2699</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2699" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2699" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2699" ref_url="https://www.suse.com/security/cve/CVE-2011-2699" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0115-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-January/000007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0153-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
    <description>
    The IPv6 implementation in the Linux kernel before 3.1 does not generate Fragment Identification values separately for each destination, which makes it easier for remote attackers to cause a denial of service (disrupted networking) by predicting these values and sending crafted packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-2699/">CVE-2011-2699</cve>
	<bugzilla href="https://bugzilla.suse.com/707288">SUSE bug 707288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112700" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2700</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2700" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2700" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2700" ref_url="https://www.suse.com/security/cve/CVE-2011-2700" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    Multiple buffer overflows in the si4713_write_econtrol_string function in drivers/media/radio/si4713-i2c.c in the Linux kernel before 2.6.39.4 on the N900 platform might allow local users to cause a denial of service or have unspecified other impact via a crafted s_ext_ctrls operation with a (1) V4L2_CID_RDS_TX_PS_NAME or (2) V4L2_CID_RDS_TX_RADIO_TEXT control ID.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2700/">CVE-2011-2700</cve>
	<bugzilla href="https://bugzilla.suse.com/707332">SUSE bug 707332</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112707" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2707</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2707" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2707" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2707" ref_url="https://www.suse.com/security/cve/CVE-2011-2707" source="SUSE CVE"/>
    <description>
    The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local users to obtain sensitive information from kernel memory locations via a crafted PTRACE_SETXTREGS request.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-2707/">CVE-2011-2707</cve>
	<bugzilla href="https://bugzilla.suse.com/707337">SUSE bug 707337</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112898" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2898</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2898" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2898" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2898" ref_url="https://www.suse.com/security/cve/CVE-2011-2898" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2012:0206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
    <description>
    net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated with VLAN Tag Control Information, which allows local users to obtain potentially sensitive information via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2011-2898/">CVE-2011-2898</cve>
	<bugzilla href="https://bugzilla.suse.com/710235">SUSE bug 710235</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112905" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2905</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2905" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2905" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2905" ref_url="https://www.suse.com/security/cve/CVE-2011-2905" source="SUSE CVE"/>
    <description>
    Untrusted search path vulnerability in the perf_config function in tools/perf/util/config.c in perf, as distributed in the Linux kernel before 3.1, allows local users to overwrite arbitrary files via a crafted config file in the current working directory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2905/">CVE-2011-2905</cve>
	<bugzilla href="https://bugzilla.suse.com/711414">SUSE bug 711414</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112918" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2918</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2918" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2918" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2918" ref_url="https://www.suse.com/security/cve/CVE-2011-2918" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:038" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:0984-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0364-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:1221-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:1222-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00007.html" source="SUSE-SU"/>
    <description>
    The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK events, which allows local users to cause a denial of service (system hang) via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-2918/">CVE-2011-2918</cve>
	<bugzilla href="https://bugzilla.suse.com/712366">SUSE bug 712366</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/713650">SUSE bug 713650</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112928" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2928</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2928" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2928" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2928" ref_url="https://www.suse.com/security/cve/CVE-2011-2928" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:041" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1101-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0364-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    The befs_follow_link function in fs/befs/linuxvfs.c in the Linux kernel before 3.1-rc3 does not validate the length attribute of long symlinks, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) by accessing a long symlink on a malformed Be filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2928/">CVE-2011-2928</cve>
	<bugzilla href="https://bugzilla.suse.com/713430">SUSE bug 713430</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20112942" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-2942</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-2942" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2942" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-2942" ref_url="https://www.suse.com/security/cve/CVE-2011-2942" source="SUSE CVE"/>
    <description>
    A certain Red Hat patch to the __br_deliver function in net/bridge/br_forward.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging connectivity to a network interface that uses an Ethernet bridge device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-2942/">CVE-2011-2942</cve>
	<bugzilla href="https://bugzilla.suse.com/726064">SUSE bug 726064</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20113188" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-3188</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-3188" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3188" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-3188" ref_url="https://www.suse.com/security/cve/CVE-2011-3188" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00013.html" source="SUSE-SU"/>
    <description>
    The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2011-3188/">CVE-2011-3188</cve>
	<bugzilla href="https://bugzilla.suse.com/713650">SUSE bug 713650</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/737874">SUSE bug 737874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20113191" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-3191</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-3191" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3191" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-3191" ref_url="https://www.suse.com/security/cve/CVE-2011-3191" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:040" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:041" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SA:2011:042" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1101-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1195-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0364-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:1221-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:1222-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00007.html" source="SUSE-SU"/>
    <description>
    Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel before 3.1 allows remote CIFS servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large length value in a response to a read request for a directory.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-05"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2011-3191/">CVE-2011-3191</cve>
	<bugzilla href="https://bugzilla.suse.com/714001">SUSE bug 714001</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20113359" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-3359</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-3359" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3359" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-3359" ref_url="https://www.suse.com/security/cve/CVE-2011-3359" source="SUSE CVE"/>
    <description>
    The dma_rx function in drivers/net/wireless/b43/dma.c in the Linux kernel before 2.6.39 does not properly allocate receive buffers, which allows remote attackers to cause a denial of service (system crash) via a crafted frame.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-3359/">CVE-2011-3359</cve>
	<bugzilla href="https://bugzilla.suse.com/717749">SUSE bug 717749</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20113363" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-3363</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-3363" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3363" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-3363" ref_url="https://www.suse.com/security/cve/CVE-2011-3363" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:042" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1195-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:1221-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2011:1222-1" ref_url="https://lists.opensuse.org/opensuse-updates/2011-11/msg00007.html" source="SUSE-SU"/>
    <description>
    The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-3363/">CVE-2011-3363</cve>
	<bugzilla href="https://bugzilla.suse.com/718028">SUSE bug 718028</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20113593" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-3593</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-3593" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3593" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-3593" ref_url="https://www.suse.com/security/cve/CVE-2011-3593" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    A certain Red Hat patch to the vlan_hwaccel_do_receive function in net/8021q/vlan_core.c in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows remote attackers to cause a denial of service (system crash) via priority-tagged VLAN frames.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-3593/">CVE-2011-3593</cve>
	<bugzilla href="https://bugzilla.suse.com/735347">SUSE bug 735347</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20113630" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-3630</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-3630" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3630" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-3630" ref_url="https://www.suse.com/security/cve/CVE-2011-3630" source="SUSE CVE"/>
    <description>
    Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2011-3630/">CVE-2011-3630</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480325" comment="hardlink-1.0+git.e66999f-1.25 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20113631" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-3631</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-3631" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3631" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-3631" ref_url="https://www.suse.com/security/cve/CVE-2011-3631" source="SUSE CVE"/>
    <description>
    Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable crash or potentially arbitrary code execution with user privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2011-3631/">CVE-2011-3631</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480325" comment="hardlink-1.0+git.e66999f-1.25 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20113632" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-3632</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-3632" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3632" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-3632" ref_url="https://www.suse.com/security/cve/CVE-2011-3632" source="SUSE CVE"/>
    <description>
    Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2011-3632/">CVE-2011-3632</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480325" comment="hardlink-1.0+git.e66999f-1.25 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20113638" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-3638</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-3638" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3638" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-3638" ref_url="https://www.suse.com/security/cve/CVE-2011-3638" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    fs/ext4/extents.c in the Linux kernel before 3.0 does not mark a modified extent as dirty in certain cases of extent splitting, which allows local users to cause a denial of service (system crash) via vectors involving ext4 umount and mount operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-3638/">CVE-2011-3638</cve>
	<bugzilla href="https://bugzilla.suse.com/726045">SUSE bug 726045</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114077" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4077</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4077" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4077" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4077" ref_url="https://www.suse.com/security/cve/CVE-2011-4077" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0153-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0540-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-04/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XFS image containing a symbolic link with a long pathname.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-17"/>
	<updated date="2023-02-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-4077/">CVE-2011-4077</cve>
	<bugzilla href="https://bugzilla.suse.com/726600">SUSE bug 726600</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114080" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4080</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4080" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4080" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4080" ref_url="https://www.suse.com/security/cve/CVE-2011-4080" source="SUSE CVE"/>
    <description>
    The sysrq_sysctl_handler function in kernel/sysctl.c in the Linux kernel before 2.6.39 does not require the CAP_SYS_ADMIN capability to modify the dmesg_restrict value, which allows local users to bypass intended access restrictions and read the kernel ring buffer by leveraging root privileges, as demonstrated by a root user in a Linux Containers (aka LXC) environment.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-4080/">CVE-2011-4080</cve>
	<bugzilla href="https://bugzilla.suse.com/726772">SUSE bug 726772</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114081" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4081</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4081" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4081" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4081" ref_url="https://www.suse.com/security/cve/CVE-2011-4081" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0153-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0364-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
    <description>
    crypto/ghash-generic.c in the Linux kernel before 3.1 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact by triggering a failed or missing ghash_setkey function call, followed by a (1) ghash_update function call or (2) ghash_final function call, as demonstrated by a write operation on an AF_ALG socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-4081/">CVE-2011-4081</cve>
	<bugzilla href="https://bugzilla.suse.com/726788">SUSE bug 726788</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114086" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4086</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4086" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4086" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4086" ref_url="https://www.suse.com/security/cve/CVE-2011-4086" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0554-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0554-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0616-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0540-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-04/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    The journal_unmap_buffer function in fs/jbd2/transaction.c in the Linux kernel before 3.3.1 does not properly handle the _Delay and _Unwritten buffer head states, which allows local users to cause a denial of service (system crash) by leveraging the presence of an ext4 filesystem that was mounted with a journal.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-4086/">CVE-2011-4086</cve>
	<bugzilla href="https://bugzilla.suse.com/745832">SUSE bug 745832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114110" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4110</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4110" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4110" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4110" ref_url="https://www.suse.com/security/cve/CVE-2011-4110" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0153-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0364-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-10/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-4110/">CVE-2011-4110</cve>
	<bugzilla href="https://bugzilla.suse.com/734056">SUSE bug 734056</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114131" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4131</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4131" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4131" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4131" ref_url="https://www.suse.com/security/cve/CVE-2011-4131" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0554-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0554-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-4131/">CVE-2011-4131</cve>
	<bugzilla href="https://bugzilla.suse.com/730117">SUSE bug 730117</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/762992">SUSE bug 762992</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114132" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4132</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4132" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4132" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4132" ref_url="https://www.suse.com/security/cve/CVE-2011-4132" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0153-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0554-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0554-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
    <description>
    The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service (assertion error and kernel oops) via an ext3 or ext4 image with an "invalid log first block value."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2011-4132/">CVE-2011-4132</cve>
	<bugzilla href="https://bugzilla.suse.com/730118">SUSE bug 730118</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114324" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4324</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4324" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4324" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4324" ref_url="https://www.suse.com/security/cve/CVE-2011-4324" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
    <description>
    The encode_share_access function in fs/nfs/nfs4xdr.c in the Linux kernel before 2.6.29 allows local users to cause a denial of service (BUG and system crash) by using the mknod system call with a pathname on an NFSv4 filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-4324/">CVE-2011-4324</cve>
	<bugzilla href="https://bugzilla.suse.com/732613">SUSE bug 732613</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114326" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4326</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4326" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4326" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4326" ref_url="https://www.suse.com/security/cve/CVE-2011-4326" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0364-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-4326/">CVE-2011-4326</cve>
	<bugzilla href="https://bugzilla.suse.com/732021">SUSE bug 732021</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114330" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4330</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4330" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4330" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4330" ref_url="https://www.suse.com/security/cve/CVE-2011-4330" source="SUSE CVE"/>
		<reference ref_id="SUSE-SA:2011:046" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2011:1319-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2011-12/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the hfs_mac2asc function in fs/hfs/trans.c in the Linux kernel 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via an HFS image with a crafted len field.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-4330/">CVE-2011-4330</cve>
	<bugzilla href="https://bugzilla.suse.com/731673">SUSE bug 731673</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/941447">SUSE bug 941447</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114348" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4348</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4348" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4348" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4348" ref_url="https://www.suse.com/security/cve/CVE-2011-4348" source="SUSE CVE"/>
    <description>
    Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets. NOTE: in some environments, this issue exists because of an incomplete fix for CVE-2011-2482.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2011-4348/">CVE-2011-4348</cve>
	<bugzilla href="https://bugzilla.suse.com/750395">SUSE bug 750395</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114594" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4594</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4594" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4594" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4594" ref_url="https://www.suse.com/security/cve/CVE-2011-4594" source="SUSE CVE"/>
    <description>
    The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted use of the sendmmsg system call, leading to an incorrect pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2011-4594/">CVE-2011-4594</cve>
	<bugzilla href="https://bugzilla.suse.com/735810">SUSE bug 735810</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114604" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4604</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4604" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4604" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4604" ref_url="https://www.suse.com/security/cve/CVE-2011-4604" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
    <description>
    The bat_socket_read function in net/batman-adv/icmp_socket.c in the Linux kernel before 3.3 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted batman-adv ICMP packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-4604/">CVE-2011-4604</cve>
	<bugzilla href="https://bugzilla.suse.com/736149">SUSE bug 736149</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114611" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4611</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4611" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4611" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4611" ref_url="https://www.suse.com/security/cve/CVE-2011-4611" source="SUSE CVE"/>
    <description>
    Integer overflow in the perf_event_interrupt function in arch/powerpc/kernel/perf_event.c in the Linux kernel before 2.6.39 on powerpc platforms allows local users to cause a denial of service (unhandled performance monitor exception) via vectors that trigger certain outcomes of performance events.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-4611/">CVE-2011-4611</cve>
	<bugzilla href="https://bugzilla.suse.com/744023">SUSE bug 744023</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20114915" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-4915</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-4915" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4915" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-4915" ref_url="https://www.suse.com/security/cve/CVE-2011-4915" source="SUSE CVE"/>
    <description>
    fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2011-4915/">CVE-2011-4915</cve>
	<bugzilla href="https://bugzilla.suse.com/738749">SUSE bug 738749</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20115321" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-5321</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-5321" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5321" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-5321" ref_url="https://www.suse.com/security/cve/CVE-2011-5321" source="SUSE CVE"/>
    <description>
    The tty_open function in drivers/tty/tty_io.c in the Linux kernel before 3.1.1 mishandles a driver-lookup failure, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted access to a device file under the /dev/pts directory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-01"/>
	<updated date="2023-07-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2011-5321/">CVE-2011-5321</cve>
	<bugzilla href="https://bugzilla.suse.com/922447">SUSE bug 922447</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20115327" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2011-5327</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2011-5327" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5327" source="CVE"/>
    <reference ref_id="SUSE CVE-2011-5327" ref_url="https://www.suse.com/security/cve/CVE-2011-5327" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function could result in at least memory corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2011-5327/">CVE-2011-5327</cve>
	<bugzilla href="https://bugzilla.suse.com/1143175">SUSE bug 1143175</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20120028" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-0028</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-0028" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0028" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-0028" ref_url="https://www.suse.com/security/cve/CVE-2012-0028" source="SUSE CVE"/>
    <description>
    The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec system calls, which allows local users to cause a denial of service or possibly gain privileges by writing to a memory location in a child process.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2012-0028/">CVE-2012-0028</cve>
	<bugzilla href="https://bugzilla.suse.com/739721">SUSE bug 739721</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20120045" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-0045</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-0045" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0045" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-0045" ref_url="https://www.suse.com/security/cve/CVE-2012-0045" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0616-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The em_syscall function in arch/x86/kvm/emulate.c in the KVM implementation in the Linux kernel before 3.2.14 does not properly handle the 0f05 (aka syscall) opcode, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application, as demonstrated by an NASM file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-0045/">CVE-2012-0045</cve>
	<bugzilla href="https://bugzilla.suse.com/740969">SUSE bug 740969</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20120055" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-0055</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-0055" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0055" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-0055" ref_url="https://www.suse.com/security/cve/CVE-2012-0055" source="SUSE CVE"/>
    <description>
    OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2012-0055/">CVE-2012-0055</cve>
	<bugzilla href="https://bugzilla.suse.com/742027">SUSE bug 742027</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20120056" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-0056</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-0056" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0056" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-0056" ref_url="https://www.suse.com/security/cve/CVE-2012-0056" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/&lt;pid&gt;/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-05"/>
	<updated date="2023-02-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-0056/">CVE-2012-0056</cve>
	<bugzilla href="https://bugzilla.suse.com/1171985">SUSE bug 1171985</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/742028">SUSE bug 742028</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/742279">SUSE bug 742279</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20120058" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-0058</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-0058" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0058" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-0058" ref_url="https://www.suse.com/security/cve/CVE-2012-0058" source="SUSE CVE"/>
    <description>
    The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-10"/>
	<updated date="2023-07-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2012-0058/">CVE-2012-0058</cve>
	<bugzilla href="https://bugzilla.suse.com/742030">SUSE bug 742030</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20120444" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-0444</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-0444" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0444" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-0444" ref_url="https://www.suse.com/security/cve/CVE-2012-0444" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-February/000016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-February/000023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0326-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-03/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00004.html" source="SUSE-SU"/>
    <description>
    Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2012-0444/">CVE-2012-0444</cve>
	<bugzilla href="https://bugzilla.suse.com/744275">SUSE bug 744275</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/747912">SUSE bug 747912</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481533" comment="libvorbis0-1.3.6-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481534" comment="libvorbisenc2-1.3.6-4.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20120786" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-0786</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-0786" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0786" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-0786" ref_url="https://www.suse.com/security/cve/CVE-2012-0786" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1017-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-August/000961.html" source="SUSE-SU"/>
    <description>
    The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augnew file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-02"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-0786/">CVE-2012-0786</cve>
	<bugzilla href="https://bugzilla.suse.com/853044">SUSE bug 853044</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/885003">SUSE bug 885003</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009480071" comment="augeas-1.10.1-1.11 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480073" comment="augeas-lenses-1.10.1-1.11 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480074" comment="libaugeas0-1.10.1-1.11 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20120810" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-0810</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-0810" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0810" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-0810" ref_url="https://www.suse.com/security/cve/CVE-2012-0810" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
    <description>
    The int3 handler in the Linux kernel before 3.3 relies on a per-CPU debug stack, which allows local users to cause a denial of service (stack corruption and panic) via a crafted application that triggers certain lock contention.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2012-0810/">CVE-2012-0810</cve>
	<bugzilla href="https://bugzilla.suse.com/749118">SUSE bug 749118</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20120876" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-0876</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-0876" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0876" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-0876" ref_url="https://www.suse.com/security/cve/CVE-2012-0876" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-June/000154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-June/000155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006536.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0423-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-03/msg00046.html" source="SUSE-SU"/>
    <description>
    The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2012-0876/">CVE-2012-0876</cve>
	<bugzilla href="https://bugzilla.suse.com/750914">SUSE bug 750914</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/751464">SUSE bug 751464</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/751465">SUSE bug 751465</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983215">SUSE bug 983215</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983216">SUSE bug 983216</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481944" comment="libexpat1-2.2.5-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20120879" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-0879</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-0879" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0879" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-0879" ref_url="https://www.suse.com/security/cve/CVE-2012-0879" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0616-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.html" source="SUSE-SU"/>
    <description>
    The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2012-0879/">CVE-2012-0879</cve>
	<bugzilla href="https://bugzilla.suse.com/748812">SUSE bug 748812</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20120957" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-0957</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-0957" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0957" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-0957" ref_url="https://www.suse.com/security/cve/CVE-2012-0957" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0259-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-February/000339.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0396-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00005.html" source="SUSE-SU"/>
    <description>
    The override_release function in kernel/sys.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from kernel stack memory via a uname system call in conjunction with a UNAME26 personality.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-0957/">CVE-2012-0957</cve>
	<bugzilla href="https://bugzilla.suse.com/783515">SUSE bug 783515</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/783606">SUSE bug 783606</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20121090" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-1090</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-1090" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1090" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-1090" ref_url="https://www.suse.com/security/cve/CVE-2012-1090" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0554-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0554-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-04/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0616-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0540-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-04/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2012-1090/">CVE-2012-1090</cve>
	<bugzilla href="https://bugzilla.suse.com/749569">SUSE bug 749569</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20121583" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-1583</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-1583" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1583" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-1583" ref_url="https://www.suse.com/security/cve/CVE-2012-1583" source="SUSE CVE"/>
    <description>
    Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-1583/">CVE-2012-1583</cve>
	<bugzilla href="https://bugzilla.suse.com/757707">SUSE bug 757707</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20121601" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-1601</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-1601" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1601" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-1601" ref_url="https://www.suse.com/security/cve/CVE-2012-1601" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-December/000318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-March/000365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The KVM implementation in the Linux kernel before 3.3.6 allows host OS users to cause a denial of service (NULL pointer dereference and host OS crash) by making a KVM_CREATE_IRQCHIP ioctl call after a virtual CPU already exists.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-1601/">CVE-2012-1601</cve>
	<bugzilla href="https://bugzilla.suse.com/754898">SUSE bug 754898</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122100" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2100</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2100" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2100" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2100" ref_url="https://www.suse.com/security/cve/CVE-2012-2100" source="SUSE CVE"/>
    <description>
    The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 3.2.2, on the x86 platform and unspecified other platforms, allows user-assisted remote attackers to trigger inconsistent filesystem-groups data and possibly cause a denial of service via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value). NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4307.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2012-2100/">CVE-2012-2100</cve>
	<bugzilla href="https://bugzilla.suse.com/757278">SUSE bug 757278</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122119" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2119</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2119" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2119" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2119" ref_url="https://www.suse.com/security/cve/CVE-2012-2119" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0789-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0781-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0812-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of service (crash) via a long descriptor with a long vector length.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-2119/">CVE-2012-2119</cve>
	<bugzilla href="https://bugzilla.suse.com/758243">SUSE bug 758243</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122121" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2121</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2121" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2121" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2121" ref_url="https://www.suse.com/security/cve/CVE-2012-2121" source="SUSE CVE"/>
    <description>
    The KVM implementation in the Linux kernel before 3.3.4 does not properly manage the relationships between memory slots and the iommu, which allows guest OS users to cause a denial of service (memory leak and host OS crash) by leveraging administrative access to the guest OS to conduct hotunplug and hotplug operations on devices.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-2121/">CVE-2012-2121</cve>
	<bugzilla href="https://bugzilla.suse.com/758355">SUSE bug 758355</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122123" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2123</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2123" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2123" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2123" ref_url="https://www.suse.com/security/cve/CVE-2012-2123" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-July/000194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0781-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0812-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    The cap_bprm_set_creds function in security/commoncap.c in the Linux kernel before 3.3.3 does not properly handle the use of file system capabilities (aka fcaps) for implementing a privileged executable file, which allows local users to bypass intended personality restrictions via a crafted application, as demonstrated by an attack that uses a parent process to disable ASLR.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2012-2123/">CVE-2012-2123</cve>
	<bugzilla href="https://bugzilla.suse.com/758260">SUSE bug 758260</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122127" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2127</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2127" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2127" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2127" ref_url="https://www.suse.com/security/cve/CVE-2012-2127" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0689-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00001.html" source="SUSE-SU"/>
    <description>
    fs/proc/root.c in the procfs implementation in the Linux kernel before 3.2 does not properly interact with CLONE_NEWPID clone system calls, which allows remote attackers to cause a denial of service (reference leak and memory consumption) by making many connections to a daemon that uses PID namespaces to isolate clients, as demonstrated by vsftpd.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-17"/>
	<updated date="2023-02-17"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2012-2127/">CVE-2012-2127</cve>
	<bugzilla href="https://bugzilla.suse.com/757783">SUSE bug 757783</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122133" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2133</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2133" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2133" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2133" ref_url="https://www.suse.com/security/cve/CVE-2012-2133" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0616-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0689-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the Linux kernel before 3.3.6, when huge pages are enabled, allows local users to cause a denial of service (system crash) or possibly gain privileges by interacting with a hugetlbfs filesystem, as demonstrated by a umount operation that triggers improper handling of quota data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-2133/">CVE-2012-2133</cve>
	<bugzilla href="https://bugzilla.suse.com/758532">SUSE bug 758532</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122136" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2136</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2136" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2136" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2136" ref_url="https://www.suse.com/security/cve/CVE-2012-2136" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0789-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-July/000194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-10/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0781-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:0812-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00002.html" source="SUSE-SU"/>
    <description>
    The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privileges by leveraging access to a TUN/TAP device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2012-2136/">CVE-2012-2136</cve>
	<bugzilla href="https://bugzilla.suse.com/765320">SUSE bug 765320</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122137" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2137</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2137" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2137" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2137" ref_url="https://www.suse.com/security/cve/CVE-2012-2137" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-March/000365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_irq function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-2137/">CVE-2012-2137</cve>
	<bugzilla href="https://bugzilla.suse.com/767612">SUSE bug 767612</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122313" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2313</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2313" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2313" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2313" ref_url="https://www.suse.com/security/cve/CVE-2012-2313" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0689-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-22"/>
	<updated date="2023-02-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-2313/">CVE-2012-2313</cve>
	<bugzilla href="https://bugzilla.suse.com/758813">SUSE bug 758813</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122372" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2372</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2372" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2372" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2372" ref_url="https://www.suse.com/security/cve/CVE-2012-2372" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-December/000318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-March/000365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-April/000435.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlier allows local users to cause a denial of service (BUG_ON and kernel panic) by establishing an RDS connection with the source IP address equal to the IPoIB interface's own IP address, as demonstrated by rds-ping.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-2372/">CVE-2012-2372</cve>
	<bugzilla href="https://bugzilla.suse.com/767610">SUSE bug 767610</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/795039">SUSE bug 795039</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122375" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2375</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2375" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2375" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2375" ref_url="https://www.suse.com/security/cve/CVE-2012-2375" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0789-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00020.html" source="SUSE-SU"/>
    <description>
    The __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the NFSv4 implementation in the Linux kernel before 3.3.2 uses an incorrect length variable during a copy operation, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words in an FATTR4_ACL reply. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-4131.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-04"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-2375/">CVE-2012-2375</cve>
	<bugzilla href="https://bugzilla.suse.com/762992">SUSE bug 762992</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/851103">SUSE bug 851103</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122383" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2383</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2383" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2383" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2383" ref_url="https://www.suse.com/security/cve/CVE-2012-2383" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-July/000194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the i915_gem_execbuffer2 function in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.3.5 on 32-bit platforms allows local users to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-10"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-2383/">CVE-2012-2383</cve>
	<bugzilla href="https://bugzilla.suse.com/763194">SUSE bug 763194</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122384" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2384</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2384" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2384" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2384" ref_url="https://www.suse.com/security/cve/CVE-2012-2384" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-July/000194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the i915_gem_do_execbuffer function in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.3.5 on 32-bit platforms allows local users to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-06"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-2384/">CVE-2012-2384</cve>
	<bugzilla href="https://bugzilla.suse.com/763194">SUSE bug 763194</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122390" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2390</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2390" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2390" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2390" ref_url="https://www.suse.com/security/cve/CVE-2012-2390" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0789-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-06/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:0904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-July/000194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid MAP_HUGETLB mmap operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-2390/">CVE-2012-2390</cve>
	<bugzilla href="https://bugzilla.suse.com/764150">SUSE bug 764150</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122669" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2669</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2669" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2669" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2669" ref_url="https://www.suse.com/security/cve/CVE-2012-2669" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-July/000166.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1526-1" ref_url="https://lists.opensuse.org/opensuse-updates/2012-11/msg00042.html" source="SUSE-SU"/>
    <description>
    The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-18"/>
	<updated date="2023-02-18"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-2669/">CVE-2012-2669</cve>
	<bugzilla href="https://bugzilla.suse.com/761200">SUSE bug 761200</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122744" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2744</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2744" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2744" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2744" ref_url="https://www.suse.com/security/cve/CVE-2012-2744" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-10/msg00015.html" source="SUSE-SU"/>
    <description>
    net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when the nf_conntrack_ipv6 module is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via certain types of fragmented IPv6 packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2012-2744/">CVE-2012-2744</cve>
	<bugzilla href="https://bugzilla.suse.com/770697">SUSE bug 770697</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20122745" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-2745</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-2745" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2745" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-2745" ref_url="https://www.suse.com/security/cve/CVE-2012-2745" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-October/000278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-March/000365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0396-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The copy_creds function in kernel/cred.c in the Linux kernel before 3.3.2 provides an invalid replacement session keyring to a child process, which allows local users to cause a denial of service (panic) via a crafted application that uses the fork system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-2745/">CVE-2012-2745</cve>
	<bugzilla href="https://bugzilla.suse.com/770695">SUSE bug 770695</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/795039">SUSE bug 795039</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20123364" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-3364</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-3364" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3364" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-3364" ref_url="https://www.suse.com/security/cve/CVE-2012-3364" source="SUSE CVE"/>
    <description>
    Multiple stack-based buffer overflows in the Near Field Communication Controller Interface (NCI) in the Linux kernel before 3.4.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via incoming frames with crafted length fields.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-24"/>
	<updated date="2023-02-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-3364/">CVE-2012-3364</cve>
	<bugzilla href="https://bugzilla.suse.com/769171">SUSE bug 769171</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20123375" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-3375</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-3375" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3375" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-3375" ref_url="https://www.suse.com/security/cve/CVE-2012-3375" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:0904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-July/000194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1016-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-August/000234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted application that attempts to create a circular epoll dependency. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1083.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-3375/">CVE-2012-3375</cve>
	<bugzilla href="https://bugzilla.suse.com/769896">SUSE bug 769896</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20123406" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-3406</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-3406" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3406" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-3406" ref_url="https://www.suse.com/security/cve/CVE-2012-3406" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1488-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-November/000297.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1666-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-December/000315.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1251-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-July/000539.html" source="SUSE-SU"/>
    <description>
    The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (crash) or possibly execute arbitrary code via a crafted format string using positional parameters and a large number of format specifiers, a different vulnerability than CVE-2012-3404 and CVE-2012-3405.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-3406/">CVE-2012-3406</cve>
	<bugzilla href="https://bugzilla.suse.com/770891">SUSE bug 770891</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/826666">SUSE bug 826666</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20123412" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-3412</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-3412" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3412" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-3412" ref_url="https://www.suse.com/security/cve/CVE-2012-3412" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-December/000318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-March/000365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005470.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2012:1330-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0396-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2012-3412/">CVE-2012-3412</cve>
	<bugzilla href="https://bugzilla.suse.com/774523">SUSE bug 774523</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20123430" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-3430</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-3430" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3430" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-3430" ref_url="https://www.suse.com/security/cve/CVE-2012-3430" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-December/000318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2012:1708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-December/000321.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-March/000365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005470.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg system call on an RDS socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-17"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-3430/">CVE-2012-3430</cve>
	<bugzilla href="https://bugzilla.suse.com/773383">SUSE bug 773383</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/795039">SUSE bug 795039</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20123510" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-3510</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-3510" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3510" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-3510" ref_url="https://www.suse.com/security/cve/CVE-2012-3510" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-10/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKSTATS_CMD_ATTR_PID command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-3510/">CVE-2012-3510</cve>
	<bugzilla href="https://bugzilla.suse.com/776888">SUSE bug 776888</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20123520" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-3520</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-3520" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3520" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-3520" ref_url="https://www.suse.com/security/cve/CVE-2012-3520" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2012:1330-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2012-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0261-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-02/msg00018.html" source="SUSE-SU"/>
    <description>
    The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-3520/">CVE-2012-3520</cve>
	<bugzilla href="https://bugzilla.suse.com/776925">SUSE bug 776925</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20123552" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-3552</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-3552" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3552" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-3552" ref_url="https://www.suse.com/security/cve/CVE-2012-3552" source="SUSE CVE"/>
    <description>
    Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of network traffic.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2012-3552/">CVE-2012-3552</cve>
	<bugzilla href="https://bugzilla.suse.com/778460">SUSE bug 778460</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/795039">SUSE bug 795039</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/827565">SUSE bug 827565</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20124024" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-4024</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-4024" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4024" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-4024" ref_url="https://www.suse.com/security/cve/CVE-2012-4024" source="SUSE CVE"/>
    <description>
    Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted list file (aka a crafted file for the -ef option).  NOTE: probably in most cases, the list file is a trusted file constructed by the program's user; however, there are some realistic situations in which a list file would be obtained from an untrusted remote source.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-4024/">CVE-2012-4024</cve>
	<bugzilla href="https://bugzilla.suse.com/773015">SUSE bug 773015</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480927" comment="squashfs-4.3-1.29 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20124025" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-4025</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-4025" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4025" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-4025" ref_url="https://www.suse.com/security/cve/CVE-2012-4025" source="SUSE CVE"/>
    <description>
    Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-4025/">CVE-2012-4025</cve>
	<bugzilla href="https://bugzilla.suse.com/773015">SUSE bug 773015</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480927" comment="squashfs-4.3-1.29 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20124398" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-4398</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-4398" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4398" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-4398" ref_url="https://www.suse.com/security/cve/CVE-2012-4398" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The __request_module function in kernel/kmod.c in the Linux kernel before 3.4 does not set a certain killable attribute, which allows local users to cause a denial of service (memory consumption) via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-4398/">CVE-2012-4398</cve>
	<bugzilla href="https://bugzilla.suse.com/778463">SUSE bug 778463</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/779488">SUSE bug 779488</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20124444" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-4444</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-4444" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4444" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-4444" ref_url="https://www.suse.com/security/cve/CVE-2012-4444" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0856-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    The ip6_frag_queue function in net/ipv6/reassembly.c in the Linux kernel before 2.6.36 allows remote attackers to bypass intended network restrictions via overlapping IPv6 fragments.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-4444/">CVE-2012-4444</cve>
	<bugzilla href="https://bugzilla.suse.com/789831">SUSE bug 789831</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20124461" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-4461</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-4461" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4461" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-4461" ref_url="https://www.suse.com/security/cve/CVE-2012-4461" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-December/000318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-March/000365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The KVM subsystem in the Linux kernel before 3.6.9, when running on hosts that use qemu userspace without XSAVE, allows local users to cause a denial of service (kernel OOPS) by using the KVM_SET_SREGS ioctl to set the X86_CR4_OSXSAVE bit in the guest cr4 register, then calling the KVM_RUN ioctl.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-4461/">CVE-2012-4461</cve>
	<bugzilla href="https://bugzilla.suse.com/787821">SUSE bug 787821</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20124508" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-4508</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-4508" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4508" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-4508" ref_url="https://www.suse.com/security/cve/CVE-2012-4508" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-December/000318.html" source="SUSE-SU"/>
    <description>
    Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-4508/">CVE-2012-4508</cve>
	<bugzilla href="https://bugzilla.suse.com/784192">SUSE bug 784192</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20124530" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-4530</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-4530" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4530" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-4530" ref_url="https://www.suse.com/security/cve/CVE-2012-4530" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0259-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-February/000339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0674-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0396-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00005.html" source="SUSE-SU"/>
    <description>
    The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-4530/">CVE-2012-4530</cve>
	<bugzilla href="https://bugzilla.suse.com/786013">SUSE bug 786013</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/841063">SUSE bug 841063</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20124542" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-4542</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-4542" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4542" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-4542" ref_url="https://www.suse.com/security/cve/CVE-2012-4542" source="SUSE CVE"/>
    <description>
    block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-4542/">CVE-2012-4542</cve>
	<bugzilla href="https://bugzilla.suse.com/807154">SUSE bug 807154</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20124565" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-4565</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-4565" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4565" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-4565" ref_url="https://www.suse.com/security/cve/CVE-2012-4565" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0259-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-February/000339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    The tcp_illinois_info function in net/ipv4/tcp_illinois.c in the Linux kernel before 3.4.19, when the net.ipv4.tcp_congestion_control illinois setting is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) by reading TCP stats.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-4565/">CVE-2012-4565</cve>
	<bugzilla href="https://bugzilla.suse.com/787576">SUSE bug 787576</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20125517" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-5517</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-5517" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5517" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-5517" ref_url="https://www.suse.com/security/cve/CVE-2012-5517" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2012:1679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2012-December/000318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-March/000365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by using memory that was hot-added by an administrator.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-5517/">CVE-2012-5517</cve>
	<bugzilla href="https://bugzilla.suse.com/789235">SUSE bug 789235</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20125532" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-5532</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-5532" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5532" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-5532" ref_url="https://www.suse.com/security/cve/CVE-2012-5532" source="SUSE CVE"/>
    <description>
    The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-5532/">CVE-2012-5532</cve>
	<bugzilla href="https://bugzilla.suse.com/791605">SUSE bug 791605</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126536" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6536</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6536" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6536" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6536" ref_url="https://www.suse.com/security/cve/CVE-2012-6536" source="SUSE CVE"/>
    <description>
    net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not verify that the actual Netlink message length is consistent with a certain header field, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability and providing a (1) new or (2) updated state.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-6536/">CVE-2012-6536</cve>
	<bugzilla href="https://bugzilla.suse.com/809889">SUSE bug 809889</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126537" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6537</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6537" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6537" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6537" ref_url="https://www.suse.com/security/cve/CVE-2012-6537" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
    <description>
    net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-6537/">CVE-2012-6537</cve>
	<bugzilla href="https://bugzilla.suse.com/809889">SUSE bug 809889</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126538" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6538</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6538" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6538" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6538" ref_url="https://www.suse.com/security/cve/CVE-2012-6538" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-13"/>
	<updated date="2023-05-13"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-6538/">CVE-2012-6538</cve>
	<bugzilla href="https://bugzilla.suse.com/809889">SUSE bug 809889</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126539" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6539</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6539" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6539" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6539" ref_url="https://www.suse.com/security/cve/CVE-2012-6539" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
    <description>
    The dev_ifconf function in net/socket.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-6539/">CVE-2012-6539</cve>
	<bugzilla href="https://bugzilla.suse.com/809891">SUSE bug 809891</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126542" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6542</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6542" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6542" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6542" ref_url="https://www.suse.com/security/cve/CVE-2012-6542" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
    <description>
    The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that leverages an uninitialized pointer argument.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-6542/">CVE-2012-6542</cve>
	<bugzilla href="https://bugzilla.suse.com/809894">SUSE bug 809894</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126544" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6544</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6544" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6544" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6544" ref_url="https://www.suse.com/security/cve/CVE-2012-6544" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
    <description>
    The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI implementation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-6544/">CVE-2012-6544</cve>
	<bugzilla href="https://bugzilla.suse.com/809898">SUSE bug 809898</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126545" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6545</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6545" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6545" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6545" ref_url="https://www.suse.com/security/cve/CVE-2012-6545" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
    <description>
    The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-6545/">CVE-2012-6545</cve>
	<bugzilla href="https://bugzilla.suse.com/809899">SUSE bug 809899</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126546" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6546</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6546" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6546" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6546" ref_url="https://www.suse.com/security/cve/CVE-2012-6546" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
    <description>
    The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-6546/">CVE-2012-6546</cve>
	<bugzilla href="https://bugzilla.suse.com/809900">SUSE bug 809900</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126547" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6547</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6547" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6547" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6547" ref_url="https://www.suse.com/security/cve/CVE-2012-6547" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
    <description>
    The __tun_chr_ioctl function in drivers/net/tun.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-6547/">CVE-2012-6547</cve>
	<bugzilla href="https://bugzilla.suse.com/809901">SUSE bug 809901</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126548" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6548</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6548" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6548" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6548" ref_url="https://www.suse.com/security/cve/CVE-2012-6548" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html" source="SUSE-SU"/>
    <description>
    The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-6548/">CVE-2012-6548</cve>
	<bugzilla href="https://bugzilla.suse.com/809902">SUSE bug 809902</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126549" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6549</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6549" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6549" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6549" ref_url="https://www.suse.com/security/cve/CVE-2012-6549" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html" source="SUSE-SU"/>
    <description>
    The isofs_export_encode_fh function in fs/isofs/export.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2012-6549/">CVE-2012-6549</cve>
	<bugzilla href="https://bugzilla.suse.com/809903">SUSE bug 809903</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126647" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6647</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6647" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6647" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6647" ref_url="https://www.suse.com/security/cve/CVE-2012-6647" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00022.html" source="SUSE-SU"/>
    <description>
    The futex_wait_requeue_pi function in kernel/futex.c in the Linux kernel before 3.5.1 does not ensure that calls have two different futex addresses, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted FUTEX_WAIT_REQUEUE_PI command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-6647/">CVE-2012-6647</cve>
	<bugzilla href="https://bugzilla.suse.com/878289">SUSE bug 878289</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126657" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6657</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6657" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6657" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6657" ref_url="https://www.suse.com/security/cve/CVE-2012-6657" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
    <description>
    The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2012-6657/">CVE-2012-6657</cve>
	<bugzilla href="https://bugzilla.suse.com/896779">SUSE bug 896779</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126689" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6689</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6689" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6689" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6689" ref_url="https://www.suse.com/security/cve/CVE-2012-6689" source="SUSE CVE"/>
    <description>
    The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2012-6689/">CVE-2012-6689</cve>
	<bugzilla href="https://bugzilla.suse.com/920170">SUSE bug 920170</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126701" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6701</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6701" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6701" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6701" ref_url="https://www.suse.com/security/cve/CVE-2012-6701" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
    <description>
    Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2012-6701/">CVE-2012-6701</cve>
	<bugzilla href="https://bugzilla.suse.com/969354">SUSE bug 969354</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969355">SUSE bug 969355</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126702" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6702</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6702" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6702" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6702" ref_url="https://www.suse.com/security/cve/CVE-2012-6702" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002631.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0483-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00071.html" source="SUSE-SU"/>
    <description>
    Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2012-6702/">CVE-2012-6702</cve>
	<bugzilla href="https://bugzilla.suse.com/983215">SUSE bug 983215</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983216">SUSE bug 983216</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481944" comment="libexpat1-2.2.5-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126703" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6703</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6703" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6703" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6703" ref_url="https://www.suse.com/security/cve/CVE-2012-6703" source="SUSE CVE"/>
    <description>
    Integer overflow in the snd_compr_allocate_buffer function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.6-rc6-next-20120917 allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-18"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2012-6703/">CVE-2012-6703</cve>
	<bugzilla href="https://bugzilla.suse.com/986811">SUSE bug 986811</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986941">SUSE bug 986941</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126704" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6704</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6704" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6704" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6704" ref_url="https://www.suse.com/security/cve/CVE-2012-6704" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
    <description>
    The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUF or (2) SO_RCVBUF option.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2012-6704/">CVE-2012-6704</cve>
	<bugzilla href="https://bugzilla.suse.com/1013531">SUSE bug 1013531</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1013542">SUSE bug 1013542</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126708" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6708</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6708" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6708" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6708" ref_url="https://www.suse.com/security/cve/CVE-2012-6708" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006630.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html" source="SUSE-SU"/>
    <description>
    jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the '&lt;' character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the '&lt;' character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2012-6708/">CVE-2012-6708</cve>
	<bugzilla href="https://bugzilla.suse.com/1111661">SUSE bug 1111661</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20126712" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2012-6712</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2012-6712" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6712" source="CVE"/>
    <reference ref_id="SUSE CVE-2012-6712" ref_url="https://www.suse.com/security/cve/CVE-2012-6712" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2012-6712/">CVE-2012-6712</cve>
	<bugzilla href="https://bugzilla.suse.com/1143176">SUSE bug 1143176</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130216" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0216</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0216" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0216" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0216" ref_url="https://www.suse.com/security/cve/CVE-2013-0216" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0674-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005470.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0396-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
    <description>
    The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-0216/">CVE-2013-0216</cve>
	<bugzilla href="https://bugzilla.suse.com/800280">SUSE bug 800280</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/800801">SUSE bug 800801</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/801178">SUSE bug 801178</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/841063">SUSE bug 841063</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130217" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0217</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0217" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0217" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0217" ref_url="https://www.suse.com/security/cve/CVE-2013-0217" source="SUSE CVE"/>
    <description>
    Memory leak in drivers/net/xen-netback/netback.c in the Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (memory consumption) by triggering certain error conditions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-0217/">CVE-2013-0217</cve>
	<bugzilla href="https://bugzilla.suse.com/800280">SUSE bug 800280</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/800801">SUSE bug 800801</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/801178">SUSE bug 801178</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130221" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0221</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0221" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0221" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0221" ref_url="https://www.suse.com/security/cve/CVE-2013-0221" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-September/000600.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0232-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0233-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-02/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0930-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00032.html" source="SUSE-SU"/>
    <description>
    The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command, when using the (1) -d or (2) -M switch, which triggers a stack-based buffer overflow in the alloca function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-0221/">CVE-2013-0221</cve>
	<bugzilla href="https://bugzilla.suse.com/798538">SUSE bug 798538</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480143" comment="coreutils-8.29-2.12 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130222" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0222</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0222" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0222" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0222" ref_url="https://www.suse.com/security/cve/CVE-2013-0222" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-September/000600.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0232-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0233-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-02/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0930-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00032.html" source="SUSE-SU"/>
    <description>
    The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the uniq command, which triggers a stack-based buffer overflow in the alloca function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-0222/">CVE-2013-0222</cve>
	<bugzilla href="https://bugzilla.suse.com/796243">SUSE bug 796243</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/798538">SUSE bug 798538</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/798541">SUSE bug 798541</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480143" comment="coreutils-8.29-2.12 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130223" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0223</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0223" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0223" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0223" ref_url="https://www.suse.com/security/cve/CVE-2013-0223" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-September/000600.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0232-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-02/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0233-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-02/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0930-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00032.html" source="SUSE-SU"/>
    <description>
    The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the join command, when using the -i switch, which triggers a stack-based buffer overflow in the alloca function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-0223/">CVE-2013-0223</cve>
	<bugzilla href="https://bugzilla.suse.com/798538">SUSE bug 798538</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/798541">SUSE bug 798541</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480143" comment="coreutils-8.29-2.12 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130228" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0228</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0228" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0228" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0228" ref_url="https://www.suse.com/security/cve/CVE-2013-0228" source="SUSE CVE"/>
    <description>
    The xen_iret function in arch/x86/xen/xen-asm_32.S in the Linux kernel before 3.7.9 on 32-bit Xen paravirt_ops platforms does not properly handle an invalid value in the DS segment register, which allows guest OS users to gain guest OS privileges via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-0228/">CVE-2013-0228</cve>
	<bugzilla href="https://bugzilla.suse.com/801179">SUSE bug 801179</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130268" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0268</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0268" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0268" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0268" ref_url="https://www.suse.com/security/cve/CVE-2013-0268" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0674-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0396-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html" source="SUSE-SU"/>
    <description>
    The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-0268/">CVE-2013-0268</cve>
	<bugzilla href="https://bugzilla.suse.com/802642">SUSE bug 802642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/841063">SUSE bug 841063</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130290" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0290</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0290" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0290" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0290" ref_url="https://www.suse.com/security/cve/CVE-2013-0290" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2013:0951-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1042-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00017.html" source="SUSE-SU"/>
    <description>
    The __skb_recv_datagram function in net/core/datagram.c in the Linux kernel before 3.8 does not properly handle the MSG_PEEK flag with zero-length data, which allows local users to cause a denial of service (infinite loop and system hang) via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-0290/">CVE-2013-0290</cve>
	<bugzilla href="https://bugzilla.suse.com/803931">SUSE bug 803931</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130292" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0292</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0292" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0292" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0292" ref_url="https://www.suse.com/security/cve/CVE-2013-0292" source="SUSE CVE"/>
    <description>
    The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-0292/">CVE-2013-0292</cve>
	<bugzilla href="https://bugzilla.suse.com/792095">SUSE bug 792095</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/804392">SUSE bug 804392</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480190" comment="dbus-1-glib-0.108-1.29 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130309" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0309</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0309" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0309" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0309" ref_url="https://www.suse.com/security/cve/CVE-2013-0309" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2013:0396-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00005.html" source="SUSE-SU"/>
    <description>
    arch/x86/include/asm/pgtable.h in the Linux kernel before 3.6.2, when transparent huge pages are used, does not properly support PROT_NONE memory regions, which allows local users to cause a denial of service (system crash) via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-0309/">CVE-2013-0309</cve>
	<bugzilla href="https://bugzilla.suse.com/804652">SUSE bug 804652</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/841063">SUSE bug 841063</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130310" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0310</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0310" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0310" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0310" ref_url="https://www.suse.com/security/cve/CVE-2013-0310" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-0310/">CVE-2013-0310</cve>
	<bugzilla href="https://bugzilla.suse.com/1133087">SUSE bug 1133087</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/804653">SUSE bug 804653</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130311" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0311</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0311" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0311" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0311" ref_url="https://www.suse.com/security/cve/CVE-2013-0311" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html" source="SUSE-SU"/>
    <description>
    The translate_desc function in drivers/vhost/vhost.c in the Linux kernel before 3.7 does not properly handle cross-region descriptors, which allows guest OS users to obtain host OS privileges by leveraging KVM guest OS privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-0311/">CVE-2013-0311</cve>
	<bugzilla href="https://bugzilla.suse.com/804656">SUSE bug 804656</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130343" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0343</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0343" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0343" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0343" ref_url="https://www.suse.com/security/cve/CVE-2013-0343" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000880.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0204-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    The ipv6_create_tempaddr function in net/ipv6/addrconf.c in the Linux kernel through 3.8 does not properly handle problems with the generation of IPv6 temporary addresses, which allows remote attackers to cause a denial of service (excessive retries and address-generation outage), and consequently obtain sensitive information, via ICMPv6 Router Advertisement (RA) messages.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-0343/">CVE-2013-0343</cve>
	<bugzilla href="https://bugzilla.suse.com/805226">SUSE bug 805226</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130349" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0349</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0349" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0349" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0349" ref_url="https://www.suse.com/security/cve/CVE-2013-0349" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    The hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux kernel before 3.7.6 does not properly copy a certain name field, which allows local users to obtain sensitive information from kernel memory by setting a long name and making an HIDPCONNADD ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-0349/">CVE-2013-0349</cve>
	<bugzilla href="https://bugzilla.suse.com/805227">SUSE bug 805227</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130871" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0871</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0871" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0871" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0871" ref_url="https://www.suse.com/security/cve/CVE-2013-0871" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0341-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-02/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0674-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0396-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00064.html" source="SUSE-SU"/>
    <description>
    Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-0871/">CVE-2013-0871</cve>
	<bugzilla href="https://bugzilla.suse.com/804154">SUSE bug 804154</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/804227">SUSE bug 804227</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/841063">SUSE bug 841063</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130913" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0913</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0913" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0913" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0913" ref_url="https://www.suse.com/security/cve/CVE-2013-0913" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0824-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-05/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0923-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
    <description>
    Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted application that triggers many relocation copies, and potentially leads to a race condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-0913/">CVE-2013-0913</cve>
	<bugzilla href="https://bugzilla.suse.com/808829">SUSE bug 808829</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20130914" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-0914</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-0914" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0914" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-0914" ref_url="https://www.suse.com/security/cve/CVE-2013-0914" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted application containing a sigaction system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-0914/">CVE-2013-0914</cve>
	<bugzilla href="https://bugzilla.suse.com/808827">SUSE bug 808827</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131763" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1763</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1763" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1763" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1763" ref_url="https://www.suse.com/security/cve/CVE-2013-1763" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2013:0395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0824-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-05/msg00030.html" source="SUSE-SU"/>
    <description>
    Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows local users to gain privileges via a large family value in a Netlink message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-1763/">CVE-2013-1763</cve>
	<bugzilla href="https://bugzilla.suse.com/805633">SUSE bug 805633</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/807436">SUSE bug 807436</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131767" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1767</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1767" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1767" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1767" ref_url="https://www.suse.com/security/cve/CVE-2013-1767" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0824-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-05/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1767/">CVE-2013-1767</cve>
	<bugzilla href="https://bugzilla.suse.com/806138">SUSE bug 806138</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/807436">SUSE bug 807436</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131772" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1772</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1772" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1772" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1772" ref_url="https://www.suse.com/security/cve/CVE-2013-1772" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html" source="SUSE-SU"/>
    <description>
    The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-1772/">CVE-2013-1772</cve>
	<bugzilla href="https://bugzilla.suse.com/806238">SUSE bug 806238</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/807441">SUSE bug 807441</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131773" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1773</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1773" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1773" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1773" ref_url="https://www.suse.com/security/cve/CVE-2013-1773" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileges or cause a denial of service (system crash) via a VFAT write operation on a filesystem with the utf8 mount option, which is not properly handled during UTF-8 to UTF-16 conversion.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1773/">CVE-2013-1773</cve>
	<bugzilla href="https://bugzilla.suse.com/806977">SUSE bug 806977</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/807452">SUSE bug 807452</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131774" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1774</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1774" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1774" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1774" ref_url="https://www.suse.com/security/cve/CVE-2013-1774" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1474-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0824-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-05/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1619-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1773-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-11/msg00106.html" source="SUSE-SU"/>
    <description>
    The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1774/">CVE-2013-1774</cve>
	<bugzilla href="https://bugzilla.suse.com/806976">SUSE bug 806976</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/807455">SUSE bug 807455</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131776" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1776</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1776" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1776" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1776" ref_url="https://www.suse.com/security/cve/CVE-2013-1776" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-May/000452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1594-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000613.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000614.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0495-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-03/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0503-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-03/msg00074.html" source="SUSE-SU"/>
    <description>
    sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal.  NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-22"/>
	<updated date="2023-07-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1776/">CVE-2013-1776</cve>
	<bugzilla href="https://bugzilla.suse.com/806921">SUSE bug 806921</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/817349">SUSE bug 817349</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/817350">SUSE bug 817350</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334290" comment="sudo is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131792" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1792</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1792" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1792" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1792" ref_url="https://www.suse.com/security/cve/CVE-2013-1792" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0204-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html" source="SUSE-SU"/>
    <description>
    Race condition in the install_user_keyrings function in security/keys/process_keys.c in the Linux kernel before 3.8.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) via crafted keyctl system calls that trigger keyring operations in simultaneous threads.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1792/">CVE-2013-1792</cve>
	<bugzilla href="https://bugzilla.suse.com/807428">SUSE bug 807428</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/808358">SUSE bug 808358</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131796" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1796</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1796" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1796" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1796" ref_url="https://www.suse.com/security/cve/CVE-2013-1796" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0824-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-05/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0923-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html" source="SUSE-SU"/>
    <description>
    The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 does not ensure a required time_page alignment during an MSR_KVM_SYSTEM_TIME operation, which allows guest OS users to cause a denial of service (buffer overflow and host OS memory corruption) or possibly have unspecified other impact via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1796/">CVE-2013-1796</cve>
	<bugzilla href="https://bugzilla.suse.com/806980">SUSE bug 806980</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/819789">SUSE bug 819789</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131797" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1797</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1797" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1797" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1797" ref_url="https://www.suse.com/security/cve/CVE-2013-1797" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0824-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-05/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0923-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 allows guest OS users to cause a denial of service (host OS memory corruption) or possibly have unspecified other impact via a crafted application that triggers use of a guest physical address (GPA) in (1) movable or (2) removable memory during an MSR_KVM_SYSTEM_TIME kvm_set_msr_common operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-06"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1797/">CVE-2013-1797</cve>
	<bugzilla href="https://bugzilla.suse.com/806980">SUSE bug 806980</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/819789">SUSE bug 819789</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131819" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1819</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1819" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1819" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1819" ref_url="https://www.suse.com/security/cve/CVE-2013-1819" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1474-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000608.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1619-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1773-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-11/msg00106.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The _xfs_buf_find function in fs/xfs/xfs_buf.c in the Linux kernel before 3.7.6 does not validate block numbers, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the ability to mount an XFS filesystem containing a metadata inode with an invalid extent map.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1819/">CVE-2013-1819</cve>
	<bugzilla href="https://bugzilla.suse.com/807471">SUSE bug 807471</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131826" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1826</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1826" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1826" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1826" ref_url="https://www.suse.com/security/cve/CVE-2013-1826" source="SUSE CVE"/>
    <description>
    The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel before 3.5.7 does not properly handle error conditions in dump_one_state function calls, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-17"/>
	<updated date="2023-02-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1826/">CVE-2013-1826</cve>
	<bugzilla href="https://bugzilla.suse.com/809889">SUSE bug 809889</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131827" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1827</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1827" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1827" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1827" ref_url="https://www.suse.com/security/cve/CVE-2013-1827" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
    <description>
    net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for a certain (1) sender or (2) receiver getsockopt call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1827/">CVE-2013-1827</cve>
	<bugzilla href="https://bugzilla.suse.com/811354">SUSE bug 811354</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131848" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1848</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1848" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1848" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1848" ref_url="https://www.suse.com/security/cve/CVE-2013-1848" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0824-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-05/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0923-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
    <description>
    fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local users to conduct format-string attacks and possibly gain privileges via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1848/">CVE-2013-1848</cve>
	<bugzilla href="https://bugzilla.suse.com/809155">SUSE bug 809155</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131860" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1860</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1860" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1860" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1860" ref_url="https://www.suse.com/security/cve/CVE-2013-1860" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted cdc-wdm USB device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1860/">CVE-2013-1860</cve>
	<bugzilla href="https://bugzilla.suse.com/806431">SUSE bug 806431</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131873" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1873</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1873" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1873" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1873" ref_url="https://www.suse.com/security/cve/CVE-2013-1873" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2634, CVE-2013-2635, CVE-2013-2636. Reason: This candidate is a duplicate of CVE-2013-2634, CVE-2013-2635, and CVE-2013-2636. Notes: All CVE users should reference one or more of CVE-2013-2634, CVE-2013-2635, and CVE-2013-2636 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-1873/">CVE-2013-1873</cve>
	<bugzilla href="https://bugzilla.suse.com/810473">SUSE bug 810473</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131928" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1928</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1928" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1928" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1928" ref_url="https://www.suse.com/security/cve/CVE-2013-1928" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0856-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1928/">CVE-2013-1928</cve>
	<bugzilla href="https://bugzilla.suse.com/813735">SUSE bug 813735</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131929" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1929</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1929" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1929" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1929" ref_url="https://www.suse.com/security/cve/CVE-2013-1929" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1474-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000608.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1773-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-11/msg00106.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1950-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00112.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted firmware that specifies a long string in the Vital Product Data (VPD) data structure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1929/">CVE-2013-1929</cve>
	<bugzilla href="https://bugzilla.suse.com/813733">SUSE bug 813733</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131943" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1943</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1943" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1943" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1943" ref_url="https://www.suse.com/security/cve/CVE-2013-1943" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a guest's physical address space, which allows local users to gain privileges or obtain sensitive information from kernel memory via a crafted application, related to arch/x86/kvm/paging_tmpl.h and virt/kvm/kvm_main.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-05"/>
	<updated date="2023-02-17"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2013-1943/">CVE-2013-1943</cve>
	<bugzilla href="https://bugzilla.suse.com/828012">SUSE bug 828012</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131979" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1979</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1979" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1979" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1979" ref_url="https://www.suse.com/security/cve/CVE-2013-1979" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1316-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005470.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The scm_set_cred function in include/net/scm.h in the Linux kernel before 3.8.11 uses incorrect uid and gid values during credentials passing, which allows local users to gain privileges via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1979/">CVE-2013-1979</cve>
	<bugzilla href="https://bugzilla.suse.com/816708">SUSE bug 816708</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131982" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1982</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1982" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1982" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1982" ref_url="https://www.suse.com/security/cve/CVE-2013-1982" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1099-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-June/000500.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1099-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-July/000550.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-July/000525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0883-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-July/000906.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1009-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00139.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in X.org libXext 1.3.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XcupGetReservedColormapEntries, (2) XcupStoreColors, (3) XdbeGetVisualInfo, (4) XeviGetVisualInfo, (5) XShapeGetRectangles, and (6) XSyncListSystemCounters functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1982/">CVE-2013-1982</cve>
	<bugzilla href="https://bugzilla.suse.com/815451">SUSE bug 815451</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/821665">SUSE bug 821665</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480415" comment="libXext6-1.3.3-1.30 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131987" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1987</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1987" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1987" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1987" ref_url="https://www.suse.com/security/cve/CVE-2013-1987" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-June/000496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1095-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-July/000551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-July/000525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0919-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-July/000929.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1011-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00141.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRenderQueryFilters, (2) XRenderQueryFormats, and (3) XRenderQueryPictIndexValues functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1987/">CVE-2013-1987</cve>
	<bugzilla href="https://bugzilla.suse.com/815451">SUSE bug 815451</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/821669">SUSE bug 821669</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/880221">SUSE bug 880221</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480433" comment="libXrender1-0.9.10-1.30 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20131989" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-1989</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-1989" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1989" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-1989" ref_url="https://www.suse.com/security/cve/CVE-2013-1989" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-June/000505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1104-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-July/000554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-July/000525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0882-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-July/000905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1010-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00140.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in X.org libXv 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XvQueryPortAttributes, (2) XvListImageFormats, and (3) XvCreateImage function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-1989/">CVE-2013-1989</cve>
	<bugzilla href="https://bugzilla.suse.com/815451">SUSE bug 815451</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/821671">SUSE bug 821671</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/880221">SUSE bug 880221</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480441" comment="libXv1-1.0.11-1.23 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132015" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2015</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2015" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2015" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2015" ref_url="https://www.suse.com/security/cve/CVE-2013-2015" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1950-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00112.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a crafted filesystem on removable media, as demonstrated by the e2fsprogs tests/f_orphan_extents_inode/image.gz test.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-2015/">CVE-2013-2015</cve>
	<bugzilla href="https://bugzilla.suse.com/817377">SUSE bug 817377</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132066" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2066</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2066" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2066" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2066" ref_url="https://www.suse.com/security/cve/CVE-2013-2066" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-June/000505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1104-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-July/000554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-July/000525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0882-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-July/000905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1010-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-06/msg00140.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in X.org libXv 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvQueryPortAttributes function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2066/">CVE-2013-2066</cve>
	<bugzilla href="https://bugzilla.suse.com/815451">SUSE bug 815451</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/821671">SUSE bug 821671</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/880221">SUSE bug 880221</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480441" comment="libXv1-1.0.11-1.23 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132094" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2094</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2094" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2094" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2094" ref_url="https://www.suse.com/security/cve/CVE-2013-2094" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0819-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0819-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000608.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0925-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:0951-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1042-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00017.html" source="SUSE-SU"/>
    <description>
    The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-2094/">CVE-2013-2094</cve>
	<bugzilla href="https://bugzilla.suse.com/819789">SUSE bug 819789</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/820202">SUSE bug 820202</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132128" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2128</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2128" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2128" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2128" ref_url="https://www.suse.com/security/cve/CVE-2013-2128" source="SUSE CVE"/>
    <description>
    The tcp_read_sock function in net/ipv4/tcp.c in the Linux kernel before 2.6.34 does not properly manage skb consumption, which allows local users to cause a denial of service (system crash) via a crafted splice system call for a TCP socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2013-2128/">CVE-2013-2128</cve>
	<bugzilla href="https://bugzilla.suse.com/822583">SUSE bug 822583</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132141" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2141</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2141" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2141" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2141" ref_url="https://www.suse.com/security/cve/CVE-2013-2141" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The do_tkill function in kernel/signal.c in the Linux kernel before 3.8.9 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted application that makes a (1) tkill or (2) tgkill system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-2141/">CVE-2013-2141</cve>
	<bugzilla href="https://bugzilla.suse.com/823267">SUSE bug 823267</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132146" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2146</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2146" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2146" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2146" ref_url="https://www.suse.com/security/cve/CVE-2013-2146" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000716.html" source="SUSE-SU"/>
    <description>
    arch/x86/kernel/cpu/perf_event_intel.c in the Linux kernel before 3.8.9, when the Performance Events Subsystem is enabled, specifies an incorrect bitmask, which allows local users to cause a denial of service (general protection fault and system crash) by attempting to set a reserved bit.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2146/">CVE-2013-2146</cve>
	<bugzilla href="https://bugzilla.suse.com/825006">SUSE bug 825006</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132206" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2206</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2206" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2206" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2206" ref_url="https://www.suse.com/security/cve/CVE-2013-2206" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1744-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-11/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-11/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1749-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-11/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-11/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1950-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00112.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-2206/">CVE-2013-2206</cve>
	<bugzilla href="https://bugzilla.suse.com/781018">SUSE bug 781018</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/826102">SUSE bug 826102</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132232" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2232</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2232" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2232" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2232" ref_url="https://www.suse.com/security/cve/CVE-2013-2232" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1474-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1619-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1773-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-11/msg00106.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using an AF_INET6 socket for a connection to an IPv4 interface.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-2232/">CVE-2013-2232</cve>
	<bugzilla href="https://bugzilla.suse.com/827750">SUSE bug 827750</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132234" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2234</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2234" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2234" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2234" ref_url="https://www.suse.com/security/cve/CVE-2013-2234" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1474-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1619-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1773-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-11/msg00106.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify interface of an IPSec key_socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-2234/">CVE-2013-2234</cve>
	<bugzilla href="https://bugzilla.suse.com/827749">SUSE bug 827749</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132237" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2237</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2237" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2237" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2237" ref_url="https://www.suse.com/security/cve/CVE-2013-2237" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1474-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1619-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1773-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-11/msg00106.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify_policy interface of an IPSec key_socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2237/">CVE-2013-2237</cve>
	<bugzilla href="https://bugzilla.suse.com/828119">SUSE bug 828119</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132634" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2634</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2634" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2634" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2634" ref_url="https://www.suse.com/security/cve/CVE-2013-2634" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    net/dcb/dcbnl.c in the Linux kernel before 3.8.4 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-2634/">CVE-2013-2634</cve>
	<bugzilla href="https://bugzilla.suse.com/810473">SUSE bug 810473</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132635" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2635</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2635" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2635" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2635" ref_url="https://www.suse.com/security/cve/CVE-2013-2635" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:0759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0759-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-05/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The rtnl_fill_ifinfo function in net/core/rtnetlink.c in the Linux kernel before 3.8.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-2635/">CVE-2013-2635</cve>
	<bugzilla href="https://bugzilla.suse.com/810473">SUSE bug 810473</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871595">SUSE bug 871595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132636" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2636</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2636" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2636" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2636" ref_url="https://www.suse.com/security/cve/CVE-2013-2636" source="SUSE CVE"/>
    <description>
    net/bridge/br_mdb.c in the Linux kernel before 3.8.4 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-17"/>
	<updated date="2023-02-17"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-2636/">CVE-2013-2636</cve>
	<bugzilla href="https://bugzilla.suse.com/810473">SUSE bug 810473</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132888" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2888</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2888" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2888" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2888" ref_url="https://www.suse.com/security/cve/CVE-2013-2888" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000880.html" source="SUSE-SU"/>
    <description>
    Multiple array index errors in drivers/hid/hid-core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11 allow physically proximate attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted device that provides an invalid Report ID.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2888/">CVE-2013-2888</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132889" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2889</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2889" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2889" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2889" ref_url="https://www.suse.com/security/cve/CVE-2013-2889" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
    <description>
    drivers/hid/hid-zpff.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_ZEROPLUS is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2889/">CVE-2013-2889</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132890" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2890</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2890" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2890" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2890" ref_url="https://www.suse.com/security/cve/CVE-2013-2890" source="SUSE CVE"/>
    <description>
    drivers/hid/hid-sony.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SONY is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2890/">CVE-2013-2890</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132891" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2891</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2891" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2891" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2891" ref_url="https://www.suse.com/security/cve/CVE-2013-2891" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
    <description>
    drivers/hid/hid-steelseries.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_STEELSERIES is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2891/">CVE-2013-2891</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132892" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2892</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2892" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2892" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2892" ref_url="https://www.suse.com/security/cve/CVE-2013-2892" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PANTHERLORD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2892/">CVE-2013-2892</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132893" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2893</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2893" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2893" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2893" ref_url="https://www.suse.com/security/cve/CVE-2013-2893" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_LOGITECH_FF, CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device, related to (1) drivers/hid/hid-lgff.c, (2) drivers/hid/hid-lg3ff.c, and (3) drivers/hid/hid-lg4ff.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2893/">CVE-2013-2893</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132894" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2894</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2894" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2894" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2894" ref_url="https://www.suse.com/security/cve/CVE-2013-2894" source="SUSE CVE"/>
    <description>
    drivers/hid/hid-lenovo-tpkbd.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LENOVO_TPKBD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2894/">CVE-2013-2894</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132895" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2895</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2895" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2895" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2895" ref_url="https://www.suse.com/security/cve/CVE-2013-2895" source="SUSE CVE"/>
    <description>
    drivers/hid/hid-logitech-dj.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LOGITECH_DJ is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or obtain sensitive information from kernel memory via a crafted device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2895/">CVE-2013-2895</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132896" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2896</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2896" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2896" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2896" ref_url="https://www.suse.com/security/cve/CVE-2013-2896" source="SUSE CVE"/>
    <description>
    drivers/hid/hid-ntrig.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_NTRIG is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) via a crafted device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2896/">CVE-2013-2896</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132897" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2897</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2897" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2897" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2897" ref_url="https://www.suse.com/security/cve/CVE-2013-2897" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    Multiple array index errors in drivers/hid/hid-multitouch.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_MULTITOUCH is enabled, allow physically proximate attackers to cause a denial of service (heap memory corruption, or NULL pointer dereference and OOPS) via a crafted device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2897/">CVE-2013-2897</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132898" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2898</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2898" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2898" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2898" ref_url="https://www.suse.com/security/cve/CVE-2013-2898" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
    <description>
    drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proximate attackers to obtain sensitive information from kernel memory via a crafted device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2898/">CVE-2013-2898</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20132899" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-2899</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-2899" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2899" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-2899" ref_url="https://www.suse.com/security/cve/CVE-2013-2899" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    drivers/hid/hid-picolcd_core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PICOLCD is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) via a crafted device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-2899/">CVE-2013-2899</cve>
	<bugzilla href="https://bugzilla.suse.com/835839">SUSE bug 835839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133076" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3076</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3076" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3076" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3076" ref_url="https://www.suse.com/security/cve/CVE-2013-3076" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
    <description>
    The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg function in crypto/algif_hash.c and the skcipher_recvmsg function in crypto/algif_skcipher.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3076/">CVE-2013-3076</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133222" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3222</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3222" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3222" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3222" ref_url="https://www.suse.com/security/cve/CVE-2013-3222" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The vcc_recvmsg function in net/atm/common.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3222/">CVE-2013-3222</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133223" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3223</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3223" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3223" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3223" ref_url="https://www.suse.com/security/cve/CVE-2013-3223" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The ax25_recvmsg function in net/ax25/af_ax25.c in the Linux kernel before 3.9-rc7 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3223/">CVE-2013-3223</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133224" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3224</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3224" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3224" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3224" ref_url="https://www.suse.com/security/cve/CVE-2013-3224" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The bt_sock_recvmsg function in net/bluetooth/af_bluetooth.c in the Linux kernel before 3.9-rc7 does not properly initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3224/">CVE-2013-3224</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133226" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3226</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3226" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3226" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3226" ref_url="https://www.suse.com/security/cve/CVE-2013-3226" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The sco_sock_recvmsg function in net/bluetooth/sco.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-04"/>
	<updated date="2023-07-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3226/">CVE-2013-3226</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133227" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3227</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3227" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3227" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3227" ref_url="https://www.suse.com/security/cve/CVE-2013-3227" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The caif_seqpkt_recvmsg function in net/caif/caif_socket.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3227/">CVE-2013-3227</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133228" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3228</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3228" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3228" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3228" ref_url="https://www.suse.com/security/cve/CVE-2013-3228" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The irda_recvmsg_dgram function in net/irda/af_irda.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3228/">CVE-2013-3228</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133229" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3229</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3229" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3229" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3229" ref_url="https://www.suse.com/security/cve/CVE-2013-3229" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The iucv_sock_recvmsg function in net/iucv/af_iucv.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3229/">CVE-2013-3229</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133230" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3230</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3230" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3230" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3230" ref_url="https://www.suse.com/security/cve/CVE-2013-3230" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The l2tp_ip6_recvmsg function in net/l2tp/l2tp_ip6.c in the Linux kernel before 3.9-rc7 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-09"/>
	<updated date="2023-07-09"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3230/">CVE-2013-3230</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133231" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3231</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3231" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3231" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3231" ref_url="https://www.suse.com/security/cve/CVE-2013-3231" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The llc_ui_recvmsg function in net/llc/af_llc.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3231/">CVE-2013-3231</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133232" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3232</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3232" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3232" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3232" ref_url="https://www.suse.com/security/cve/CVE-2013-3232" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The nr_recvmsg function in net/netrom/af_netrom.c in the Linux kernel before 3.9-rc7 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3232/">CVE-2013-3232</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133233" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3233</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3233" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3233" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3233" ref_url="https://www.suse.com/security/cve/CVE-2013-3233" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The llcp_sock_recvmsg function in net/nfc/llcp/sock.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable and a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-05"/>
	<updated date="2023-07-05"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3233/">CVE-2013-3233</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133234" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3234</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3234" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3234" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3234" ref_url="https://www.suse.com/security/cve/CVE-2013-3234" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The rose_recvmsg function in net/rose/af_rose.c in the Linux kernel before 3.9-rc7 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3234/">CVE-2013-3234</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133235" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3235</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3235" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3235" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3235" ref_url="https://www.suse.com/security/cve/CVE-2013-3235" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1022-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-07/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-December/000659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    net/tipc/socket.c in the Linux kernel before 3.9-rc7 does not initialize a certain data structure and a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3235/">CVE-2013-3235</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133236" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3236</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3236" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3236" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3236" ref_url="https://www.suse.com/security/cve/CVE-2013-3236" source="SUSE CVE"/>
    <description>
    The vmci_transport_dgram_dequeue function in net/vmw_vsock/vmci_transport.c in the Linux kernel before 3.9-rc7 does not properly initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-08"/>
	<updated date="2023-07-08"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3236/">CVE-2013-3236</cve>
	<bugzilla href="https://bugzilla.suse.com/816668">SUSE bug 816668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133301" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3301</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3301" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3301" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3301" ref_url="https://www.suse.com/security/cve/CVE-2013-3301" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000608.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3301/">CVE-2013-3301</cve>
	<bugzilla href="https://bugzilla.suse.com/815256">SUSE bug 815256</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20133495" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-3495</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-3495" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3495" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-3495" ref_url="https://www.suse.com/security/cve/CVE-2013-3495" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-April/001354.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0256-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.html" source="SUSE-SU"/>
    <description>
    The Intel VT-d Interrupt Remapping engine in Xen 3.3.x through 4.3.x allows local guests to cause a denial of service (kernel panic) via a malformed Message Signaled Interrupt (MSI) from a PCI device that is bus mastering capable that triggers a System Error Reporting (SERR) Non-Maskable Interrupt (NMI).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-3495/">CVE-2013-3495</cve>
	<bugzilla href="https://bugzilla.suse.com/826717">SUSE bug 826717</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/903970">SUSE bug 903970</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134162" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4162</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4162" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4162" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4162" ref_url="https://www.suse.com/security/cve/CVE-2013-4162" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1474-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1619-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1773-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-11/msg00106.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1971-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-12/msg00129.html" source="SUSE-SU"/>
    <description>
    The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 implementation in the Linux kernel through 3.10.3 makes an incorrect function call for pending data, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4162/">CVE-2013-4162</cve>
	<bugzilla href="https://bugzilla.suse.com/831058">SUSE bug 831058</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134163" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4163</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4163" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4163" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4163" ref_url="https://www.suse.com/security/cve/CVE-2013-4163" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2013:1473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1474-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2013:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2013-October/000608.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1619-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1773-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-11/msg00106.html" source="SUSE-SU"/>
    <description>
    The ip6_append_data_mtu function in net/ipv6/ip6_output.c in the IPv6 implementation in the Linux kernel through 3.10.3 does not properly maintain information about whether the IPV6_MTU setsockopt option had been specified, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4163/">CVE-2013-4163</cve>
	<bugzilla href="https://bugzilla.suse.com/831055">SUSE bug 831055</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134270" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4270</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4270" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4270" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4270" ref_url="https://www.suse.com/security/cve/CVE-2013-4270" source="SUSE CVE"/>
    <description>
    The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-4270/">CVE-2013-4270</cve>
	<bugzilla href="https://bugzilla.suse.com/836949">SUSE bug 836949</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134282" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4282</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4282" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4282" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4282" ref_url="https://www.suse.com/security/cve/CVE-2013-4282" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0884-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0884-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1750-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-10/msg00032.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2013-4282/">CVE-2013-4282</cve>
	<bugzilla href="https://bugzilla.suse.com/848279">SUSE bug 848279</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134288" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4288</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4288" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4288" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4288" ref_url="https://www.suse.com/security/cve/CVE-2013-4288" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2013:1527-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1528-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1617-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1620-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-11/msg00000.html" source="SUSE-SU"/>
    <description>
    Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4288/">CVE-2013-4288</cve>
	<bugzilla href="https://bugzilla.suse.com/1070943">SUSE bug 1070943</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1099031">SUSE bug 1099031</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/835827">SUSE bug 835827</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/836931">SUSE bug 836931</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/836932">SUSE bug 836932</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/836937">SUSE bug 836937</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/836939">SUSE bug 836939</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/844967">SUSE bug 844967</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/852368">SUSE bug 852368</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/854144">SUSE bug 854144</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/864716">SUSE bug 864716</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334933" comment="libvirt-daemon is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334936" comment="libvirt-daemon-driver-interface is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334939" comment="libvirt-daemon-driver-network is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334940" comment="libvirt-daemon-driver-nodedev is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334941" comment="libvirt-daemon-driver-nwfilter is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334942" comment="libvirt-daemon-driver-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334943" comment="libvirt-daemon-driver-secret is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334944" comment="libvirt-daemon-driver-storage is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336191" comment="libvirt-daemon-driver-storage-core is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336192" comment="libvirt-daemon-driver-storage-disk is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336193" comment="libvirt-daemon-driver-storage-iscsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336194" comment="libvirt-daemon-driver-storage-logical is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336195" comment="libvirt-daemon-driver-storage-mpath is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336196" comment="libvirt-daemon-driver-storage-rbd is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336197" comment="libvirt-daemon-driver-storage-scsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334946" comment="libvirt-daemon-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336198" comment="libvirt-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134311" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4311</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4311" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4311" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4311" ref_url="https://www.suse.com/security/cve/CVE-2013-4311" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2013:1549-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2013:1550-1" ref_url="https://lists.opensuse.org/opensuse-updates/2013-10/msg00024.html" source="SUSE-SU"/>
    <description>
    libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4311/">CVE-2013-4311</cve>
	<bugzilla href="https://bugzilla.suse.com/836931">SUSE bug 836931</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/838638">SUSE bug 838638</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/864716">SUSE bug 864716</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334933" comment="libvirt-daemon is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334936" comment="libvirt-daemon-driver-interface is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334939" comment="libvirt-daemon-driver-network is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334940" comment="libvirt-daemon-driver-nodedev is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334941" comment="libvirt-daemon-driver-nwfilter is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334942" comment="libvirt-daemon-driver-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334943" comment="libvirt-daemon-driver-secret is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334944" comment="libvirt-daemon-driver-storage is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336191" comment="libvirt-daemon-driver-storage-core is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336192" comment="libvirt-daemon-driver-storage-disk is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336193" comment="libvirt-daemon-driver-storage-iscsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336194" comment="libvirt-daemon-driver-storage-logical is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336195" comment="libvirt-daemon-driver-storage-mpath is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336196" comment="libvirt-daemon-driver-storage-rbd is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336197" comment="libvirt-daemon-driver-storage-scsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334946" comment="libvirt-daemon-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336198" comment="libvirt-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134350" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4350</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4350" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4350" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4350" ref_url="https://www.suse.com/security/cve/CVE-2013-4350" source="SUSE CVE"/>
    <description>
    The IPv6 SCTP implementation in net/sctp/ipv6.c in the Linux kernel through 3.11.1 uses data structures and function calls that do not trigger an intended configuration of IPsec encryption, which allows remote attackers to obtain sensitive information by sniffing the network.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4350/">CVE-2013-4350</cve>
	<bugzilla href="https://bugzilla.suse.com/840506">SUSE bug 840506</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134387" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4387</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4387" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4387" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4387" ref_url="https://www.suse.com/security/cve/CVE-2013-4387" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
    <description>
    net/ipv6/ip6_output.c in the Linux kernel through 3.11.4 does not properly determine the need for UDP Fragmentation Offload (UFO) processing of small packets after the UFO queueing of a large packet, which allows remote attackers to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via network traffic that triggers a large response packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4387/">CVE-2013-4387</cve>
	<bugzilla href="https://bugzilla.suse.com/843430">SUSE bug 843430</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/848042">SUSE bug 848042</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134458" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4458</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4458" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4458" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4458" ref_url="https://www.suse.com/security/cve/CVE-2013-4458" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of AF_INET6 address results. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1914.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4458/">CVE-2013-4458</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/847227">SUSE bug 847227</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/883217">SUSE bug 883217</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/941444">SUSE bug 941444</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/955181">SUSE bug 955181</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/967023">SUSE bug 967023</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980483">SUSE bug 980483</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134483" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4483</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4483" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4483" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4483" ref_url="https://www.suse.com/security/cve/CVE-2013-4483" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000716.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000880.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0247-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html" source="SUSE-SU"/>
    <description>
    The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, which allows local users to cause a denial of service (memory consumption or system crash) via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4483/">CVE-2013-4483</cve>
	<bugzilla href="https://bugzilla.suse.com/848321">SUSE bug 848321</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134515" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4515</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4515" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4515" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4515" ref_url="https://www.suse.com/security/cve/CVE-2013-4515" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000716.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0204-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0247-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html" source="SUSE-SU"/>
    <description>
    The bcm_char_ioctl function in drivers/staging/bcm/Bcmchar.c in the Linux kernel before 3.12 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an IOCTL_BCM_GET_DEVICE_DRIVER_INFO ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4515/">CVE-2013-4515</cve>
	<bugzilla href="https://bugzilla.suse.com/849034">SUSE bug 849034</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134516" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4516</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4516" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4516" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4516" ref_url="https://www.suse.com/security/cve/CVE-2013-4516" source="SUSE CVE"/>
    <description>
    The mp_get_count function in drivers/staging/sb105x/sb_pci_mp.c in the Linux kernel before 3.12 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4516/">CVE-2013-4516</cve>
	<bugzilla href="https://bugzilla.suse.com/849036">SUSE bug 849036</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134533" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4533</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4533" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4533" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4533" ref_url="https://www.suse.com/security/cve/CVE-2013-4533" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s-&gt;rx_level value in a savevm image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-4533/">CVE-2013-4533</cve>
	<bugzilla href="https://bugzilla.suse.com/1072223">SUSE bug 1072223</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/864655">SUSE bug 864655</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871442">SUSE bug 871442</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/964644">SUSE bug 964644</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134534" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4534</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4534" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4534" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4534" ref_url="https://www.suse.com/security/cve/CVE-2013-4534" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors related to IRQDest elements.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-4534/">CVE-2013-4534</cve>
	<bugzilla href="https://bugzilla.suse.com/864811">SUSE bug 864811</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871442">SUSE bug 871442</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/964452">SUSE bug 964452</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134537" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4537</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4537" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4537" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4537" ref_url="https://www.suse.com/security/cve/CVE-2013-4537" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-4537/">CVE-2013-4537</cve>
	<bugzilla href="https://bugzilla.suse.com/864391">SUSE bug 864391</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871442">SUSE bug 871442</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962642">SUSE bug 962642</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134538" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4538</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4538" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4538" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4538" ref_url="https://www.suse.com/security/cve/CVE-2013-4538" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col values; (4) row_start and row_end values; or (5) col_star and col_end values in a savevm image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-4538/">CVE-2013-4538</cve>
	<bugzilla href="https://bugzilla.suse.com/1072223">SUSE bug 1072223</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/864769">SUSE bug 864769</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871442">SUSE bug 871442</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962335">SUSE bug 962335</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134539" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4539</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4539" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4539" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4539" ref_url="https://www.suse.com/security/cve/CVE-2013-4539" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a savevm image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-4539/">CVE-2013-4539</cve>
	<bugzilla href="https://bugzilla.suse.com/1072223">SUSE bug 1072223</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/864805">SUSE bug 864805</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871442">SUSE bug 871442</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962758">SUSE bug 962758</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134540" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4540</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4540" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4540" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4540" ref_url="https://www.suse.com/security/cve/CVE-2013-4540" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-October/001039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1279-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1281-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00003.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-4540/">CVE-2013-4540</cve>
	<bugzilla href="https://bugzilla.suse.com/864801">SUSE bug 864801</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871442">SUSE bug 871442</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/880751">SUSE bug 880751</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134579" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4579</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4579" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4579" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4579" ref_url="https://www.suse.com/security/cve/CVE-2013-4579" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000882.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach to determine the set of MAC addresses on which a Wi-Fi device is listening, which allows remote attackers to discover the original MAC address after spoofing by sending a series of packets to MAC addresses with certain bit manipulations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4579/">CVE-2013-4579</cve>
	<bugzilla href="https://bugzilla.suse.com/851426">SUSE bug 851426</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134587" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4587</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4587" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4587" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4587" ref_url="https://www.suse.com/security/cve/CVE-2013-4587" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000716.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0204-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0205-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0247-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html" source="SUSE-SU"/>
    <description>
    Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-4587/">CVE-2013-4587</cve>
	<bugzilla href="https://bugzilla.suse.com/853050">SUSE bug 853050</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/882914">SUSE bug 882914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134591" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4591</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4591" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4591" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4591" ref_url="https://www.suse.com/security/cve/CVE-2013-4591" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a getxattr system call for the system.nfs4_acl extended attribute of a pathname on an NFSv4 filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-4591/">CVE-2013-4591</cve>
	<bugzilla href="https://bugzilla.suse.com/851103">SUSE bug 851103</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20134592" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-4592</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-4592" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4592" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-4592" ref_url="https://www.suse.com/security/cve/CVE-2013-4592" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000716.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0247-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html" source="SUSE-SU"/>
    <description>
    Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main.c in the Linux kernel before 3.9 allows local users to cause a denial of service (memory consumption) by leveraging certain device access to trigger movement of memory slots.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-15"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2013-4592/">CVE-2013-4592</cve>
	<bugzilla href="https://bugzilla.suse.com/851101">SUSE bug 851101</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20136370" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-6370</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-6370" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6370" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-6370" ref_url="https://www.suse.com/security/cve/CVE-2013-6370" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:0558-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-04/msg00059.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-6370/">CVE-2013-6370</cve>
	<bugzilla href="https://bugzilla.suse.com/870147">SUSE bug 870147</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480594" comment="libjson-c3-0.13-1.19 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20136371" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-6371</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-6371" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6371" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-6371" ref_url="https://www.suse.com/security/cve/CVE-2013-6371" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:0558-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-04/msg00059.html" source="SUSE-SU"/>
    <description>
    The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-6371/">CVE-2013-6371</cve>
	<bugzilla href="https://bugzilla.suse.com/870147">SUSE bug 870147</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480594" comment="libjson-c3-0.13-1.19 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20136376" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-6376</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-6376" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6376" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-6376" ref_url="https://www.suse.com/security/cve/CVE-2013-6376" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000716.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0204-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0205-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html" source="SUSE-SU"/>
    <description>
    The recalculate_apic_map function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (host OS crash) via a crafted ICR write operation in x2apic mode.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-6376/">CVE-2013-6376</cve>
	<bugzilla href="https://bugzilla.suse.com/853053">SUSE bug 853053</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20136378" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-6378</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-6378" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6378" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-6378" ref_url="https://www.suse.com/security/cve/CVE-2013-6378" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-January/000710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000716.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-February/000734.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0204-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0247-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html" source="SUSE-SU"/>
    <description>
    The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service (OOPS) by leveraging root privileges for a zero-length write operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-6378/">CVE-2013-6378</cve>
	<bugzilla href="https://bugzilla.suse.com/852559">SUSE bug 852559</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20136381" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-6381</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-6381" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6381" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-6381" ref_url="https://www.suse.com/security/cve/CVE-2013-6381" source="SUSE CVE"/>
    <description>
    Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that is incompatible with the command-buffer size.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-6381/">CVE-2013-6381</cve>
	<bugzilla href="https://bugzilla.suse.com/852552">SUSE bug 852552</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20136393" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-6393</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-6393" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6393" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-6393" ref_url="https://www.suse.com/security/cve/CVE-2013-6393" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0403-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-March/000756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0456-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-March/000769.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0953-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0953-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001412.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0272-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-02/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0273-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-02/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0381-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-03/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0319-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1067-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-04/msg00050.html" source="SUSE-SU"/>
    <description>
    The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-6393/">CVE-2013-6393</cve>
	<bugzilla href="https://bugzilla.suse.com/860617">SUSE bug 860617</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/911782">SUSE bug 911782</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480828" comment="libyaml-0-2-0.1.7-1.17 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20136763" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-6763</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-6763" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6763" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-6763" ref_url="https://www.suse.com/security/cve/CVE-2013-6763" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted mmap operations, a different vulnerability than CVE-2013-4511.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-6763/">CVE-2013-6763</cve>
	<bugzilla href="https://bugzilla.suse.com/850263">SUSE bug 850263</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20136999" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-6999</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-6999" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6999" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-6999" ref_url="https://www.suse.com/security/cve/CVE-2013-6999" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** The IsHandleEntrySecure function in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 SP2 does not properly validate the tagPROCESSINFO pW32Job field, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted NtUserValidateHandleSecure call for an owned object.  NOTE: the vendor reportedly disputes the significance of this report, stating that "it appears to be a local DOS ... we don't consider it a security vulnerability."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-19"/>
	<updated date="2023-02-19"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-6999/">CVE-2013-6999</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20137263" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-7263</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-7263" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7263" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-7263" ref_url="https://www.suse.com/security/cve/CVE-2013-7263" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-03/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0531-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call, related to net/ipv4/ping.c, net/ipv4/raw.c, net/ipv4/udp.c, net/ipv6/raw.c, and net/ipv6/udp.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2013-7263/">CVE-2013-7263</cve>
	<bugzilla href="https://bugzilla.suse.com/853040">SUSE bug 853040</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/857643">SUSE bug 857643</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20137264" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-7264</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-7264" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7264" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-7264" ref_url="https://www.suse.com/security/cve/CVE-2013-7264" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-03/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0531-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000880.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    The l2tp_ip_recvmsg function in net/l2tp/l2tp_ip.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-07"/>
	<updated date="2023-07-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-7264/">CVE-2013-7264</cve>
	<bugzilla href="https://bugzilla.suse.com/853040">SUSE bug 853040</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/857643">SUSE bug 857643</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20137265" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-7265</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-7265" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7265" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-7265" ref_url="https://www.suse.com/security/cve/CVE-2013-7265" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-03/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0531-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000880.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    The pn_recvmsg function in net/phonet/datagram.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-05"/>
	<updated date="2023-07-05"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-7265/">CVE-2013-7265</cve>
	<bugzilla href="https://bugzilla.suse.com/853040">SUSE bug 853040</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/857643">SUSE bug 857643</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20137267" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-7267</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-7267" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7267" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-7267" ref_url="https://www.suse.com/security/cve/CVE-2013-7267" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
    <description>
    The atalk_recvmsg function in net/appletalk/ddp.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-18"/>
	<updated date="2023-05-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-7267/">CVE-2013-7267</cve>
	<bugzilla href="https://bugzilla.suse.com/854722">SUSE bug 854722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/857643">SUSE bug 857643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/882914">SUSE bug 882914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20137268" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-7268</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-7268" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7268" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-7268" ref_url="https://www.suse.com/security/cve/CVE-2013-7268" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
    <description>
    The ipx_recvmsg function in net/ipx/af_ipx.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-7268/">CVE-2013-7268</cve>
	<bugzilla href="https://bugzilla.suse.com/854722">SUSE bug 854722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/857643">SUSE bug 857643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/882914">SUSE bug 882914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20137269" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-7269</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-7269" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7269" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-7269" ref_url="https://www.suse.com/security/cve/CVE-2013-7269" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
    <description>
    The nr_recvmsg function in net/netrom/af_netrom.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-17"/>
	<updated date="2023-05-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-7269/">CVE-2013-7269</cve>
	<bugzilla href="https://bugzilla.suse.com/854722">SUSE bug 854722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/857643">SUSE bug 857643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/882914">SUSE bug 882914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20137270" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-7270</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-7270" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7270" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-7270" ref_url="https://www.suse.com/security/cve/CVE-2013-7270" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
    <description>
    The packet_recvmsg function in net/packet/af_packet.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-17"/>
	<updated date="2023-05-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-7270/">CVE-2013-7270</cve>
	<bugzilla href="https://bugzilla.suse.com/854722">SUSE bug 854722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/857643">SUSE bug 857643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/882914">SUSE bug 882914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20137271" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-7271</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-7271" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7271" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-7271" ref_url="https://www.suse.com/security/cve/CVE-2013-7271" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
    <description>
    The x25_recvmsg function in net/x25/af_x25.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-20"/>
	<updated date="2023-05-20"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-7271/">CVE-2013-7271</cve>
	<bugzilla href="https://bugzilla.suse.com/854722">SUSE bug 854722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/857643">SUSE bug 857643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/882914">SUSE bug 882914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20137339" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-7339</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-7339" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7339" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-7339" ref_url="https://www.suse.com/security/cve/CVE-2013-7339" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0840-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0856-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00000.html" source="SUSE-SU"/>
    <description>
    The rds_ib_laddr_check function in net/rds/ib.c in the Linux kernel before 3.12.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS socket on a system that lacks RDS transports.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-7339/">CVE-2013-7339</cve>
	<bugzilla href="https://bugzilla.suse.com/869563">SUSE bug 869563</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20137446" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-7446</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-7446" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7446" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-7446" ref_url="https://www.suse.com/security/cve/CVE-2013-7446" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0585-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0746-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0747-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0749-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0751-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0752-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0753-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0754-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0755-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0756-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0757-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1961-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1994-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2000-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2001-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2002-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2006-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2009-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2014-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel before 4.3.3 allows local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2013-7446/">CVE-2013-7446</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/955654">SUSE bug 955654</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/955837">SUSE bug 955837</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20137470" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2013-7470</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2013-7470" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7470" source="CVE"/>
    <reference ref_id="SUSE CVE-2013-7470" ref_url="https://www.suse.com/security/cve/CVE-2013-7470" source="SUSE CVE"/>
    <description>
    cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2013-7470/">CVE-2013-7470</cve>
	<bugzilla href="https://bugzilla.suse.com/1133087">SUSE bug 1133087</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140012" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0012</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0012" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0012" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0012" ref_url="https://www.suse.com/security/cve/CVE-2014-0012" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-August/001522.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2465-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0244-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-0012/">CVE-2014-0012</cve>
	<bugzilla href="https://bugzilla.suse.com/858239">SUSE bug 858239</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481633" comment="python3-Jinja2-2.10.1-3.5.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140038" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0038</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0038" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0038" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0038" ref_url="https://www.suse.com/security/cve/CVE-2014-0038" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:3210-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3249-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0204-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0205-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html" source="SUSE-SU"/>
    <description>
    The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-0038/">CVE-2014-0038</cve>
	<bugzilla href="https://bugzilla.suse.com/860993">SUSE bug 860993</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140055" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0055</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0055" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0055" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0055" ref_url="https://www.suse.com/security/cve/CVE-2014-0055" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-September/000987.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0840-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0856-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1246-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00056.html" source="SUSE-SU"/>
    <description>
    The get_rx_bufs function in drivers/vhost/net.c in the vhost-net subsystem in the Linux kernel package before 2.6.32-431.11.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle vhost_get_vq_desc errors, which allows guest OS users to cause a denial of service (host OS crash) via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-16"/>
	<updated date="2023-05-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-0055/">CVE-2014-0055</cve>
	<bugzilla href="https://bugzilla.suse.com/870173">SUSE bug 870173</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140069" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0069</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0069" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0069" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0069" ref_url="https://www.suse.com/security/cve/CVE-2014-0069" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-03/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0531-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-04/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes, which allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory corruption and system crash), or possibly gain privileges via a writev system call with a crafted pointer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-0069/">CVE-2014-0069</cve>
	<bugzilla href="https://bugzilla.suse.com/864025">SUSE bug 864025</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140077" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0077</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0077" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0077" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0077" ref_url="https://www.suse.com/security/cve/CVE-2014-0077" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-September/000987.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0840-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0856-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1246-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00056.html" source="SUSE-SU"/>
    <description>
    drivers/vhost/net.c in the Linux kernel before 3.13.10, when mergeable buffers are disabled, does not properly validate packet lengths, which allows guest OS users to cause a denial of service (memory corruption and host OS crash) or possibly gain privileges on the host OS via crafted packets, related to the handle_rx and get_rx_bufs functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-0077/">CVE-2014-0077</cve>
	<bugzilla href="https://bugzilla.suse.com/870173">SUSE bug 870173</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/870576">SUSE bug 870576</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140131" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0131</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0131" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0131" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0131" ref_url="https://www.suse.com/security/cve/CVE-2014-0131" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0957-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-0131/">CVE-2014-0131</cve>
	<bugzilla href="https://bugzilla.suse.com/824295">SUSE bug 824295</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/867723">SUSE bug 867723</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/869564">SUSE bug 869564</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0155" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0155" ref_url="https://www.suse.com/security/cve/CVE-2014-0155" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
    <description>
    The ioapic_deliver function in virt/kvm/ioapic.c in the Linux kernel through 3.14.1 does not properly validate the kvm_irq_delivery_to_apic return value, which allows guest OS users to cause a denial of service (host OS crash) via a crafted entry in the redirection table of an I/O APIC. NOTE: the affected code was moved to the ioapic_service function before the vulnerability was announced.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-0155/">CVE-2014-0155</cve>
	<bugzilla href="https://bugzilla.suse.com/824295">SUSE bug 824295</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/872540">SUSE bug 872540</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140181" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0181</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0181" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0181" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0181" ref_url="https://www.suse.com/security/cve/CVE-2014-0181" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-0181/">CVE-2014-0181</cve>
	<bugzilla href="https://bugzilla.suse.com/875051">SUSE bug 875051</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140191" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0191</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0191" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0191" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0191" ref_url="https://www.suse.com/security/cve/CVE-2014-0191" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1366-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002905.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008797.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0645-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0701-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-05/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0716-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-05/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0741-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0753-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
    <description>
    The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-0191/">CVE-2014-0191</cve>
	<bugzilla href="https://bugzilla.suse.com/1014873">SUSE bug 1014873</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/876652">SUSE bug 876652</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/877506">SUSE bug 877506</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/996079">SUSE bug 996079</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140196" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0196</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0196" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0196" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0196" ref_url="https://www.suse.com/security/cve/CVE-2014-0196" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0667-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0683-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="TID7015061" ref_url="https://www.suse.com/support/kb/doc?id=7015061" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO &amp; !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-0196/">CVE-2014-0196</cve>
	<bugzilla href="https://bugzilla.suse.com/871252">SUSE bug 871252</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/875690">SUSE bug 875690</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/877345">SUSE bug 877345</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/879878">SUSE bug 879878</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933423">SUSE bug 933423</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140203" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0203</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0203" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0203" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0203" ref_url="https://www.suse.com/security/cve/CVE-2014-0203" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
    <description>
    The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and system crash) via an open system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-0203/">CVE-2014-0203</cve>
	<bugzilla href="https://bugzilla.suse.com/883526">SUSE bug 883526</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140222" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0222</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0222" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0222" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0222" ref_url="https://www.suse.com/security/cve/CVE-2014-0222" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-October/001032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0929-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1894-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1952-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1445-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1965-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-0222/">CVE-2014-0222</cve>
	<bugzilla href="https://bugzilla.suse.com/1072223">SUSE bug 1072223</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/877642">SUSE bug 877642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950367">SUSE bug 950367</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/964925">SUSE bug 964925</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20140223" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-0223</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-0223" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0223" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-0223" ref_url="https://www.suse.com/security/cve/CVE-2014-0223" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-October/001032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0929-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00021.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-0223/">CVE-2014-0223</cve>
	<bugzilla href="https://bugzilla.suse.com/877645">SUSE bug 877645</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20141569" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-1569</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-1569" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1569" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-1569" ref_url="https://www.suse.com/security/cve/CVE-2014-1569" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0076-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0171-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0173-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0404-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00000.html" source="SUSE-SU"/>
    <description>
    The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding of an ASN.1 length is properly formed, which allows remote attackers to conduct data-smuggling attacks by using a long byte sequence for an encoding, as demonstrated by the SEC_QuickDERDecodeItem function's improper handling of an arbitrary-length encoding of 0x00.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-1569/">CVE-2014-1569</cve>
	<bugzilla href="https://bugzilla.suse.com/910647">SUSE bug 910647</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/913096">SUSE bug 913096</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/917597">SUSE bug 917597</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20141737" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-1737</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-1737" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1737" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-1737" ref_url="https://www.suse.com/security/cve/CVE-2014-1737" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0667-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0683-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000880.html" source="SUSE-SU"/>
		<reference ref_id="TID7015062" ref_url="https://www.suse.com/support/kb/doc?id=7015062" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-12"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-1737/">CVE-2014-1737</cve>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/875798">SUSE bug 875798</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/877345">SUSE bug 877345</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20141738" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-1738</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-1738" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1738" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-1738" ref_url="https://www.suse.com/security/cve/CVE-2014-1738" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0667-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0683-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000880.html" source="SUSE-SU"/>
		<reference ref_id="TID7015062" ref_url="https://www.suse.com/support/kb/doc?id=7015062" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-12"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-1738/">CVE-2014-1738</cve>
	<bugzilla href="https://bugzilla.suse.com/875798">SUSE bug 875798</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/877345">SUSE bug 877345</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20142039" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-2039</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-2039" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2039" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-2039" ref_url="https://www.suse.com/security/cve/CVE-2014-2039" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
    <description>
    arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform does not properly handle attempted use of the linkage stack, which allows local users to cause a denial of service (system crash) by executing a crafted instruction.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-2039/">CVE-2014-2039</cve>
	<bugzilla href="https://bugzilla.suse.com/862796">SUSE bug 862796</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/865307">SUSE bug 865307</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20142240" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-2240</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-2240" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2240" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-2240" ref_url="https://www.suse.com/security/cve/CVE-2014-2240" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of stem hints in a font file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-2240/">CVE-2014-2240</cve>
	<bugzilla href="https://bugzilla.suse.com/867620">SUSE bug 867620</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/916867">SUSE bug 916867</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20142309" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-2309</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-2309" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2309" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-2309" ref_url="https://www.suse.com/security/cve/CVE-2014-2309" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0957-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The ip6_route_add function in net/ipv6/route.c in the Linux kernel through 3.13.6 does not properly count the addition of routes, which allows remote attackers to cause a denial of service (memory consumption) via a flood of ICMPv6 Router Advertisement packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-16"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-2309/">CVE-2014-2309</cve>
	<bugzilla href="https://bugzilla.suse.com/824295">SUSE bug 824295</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/867531">SUSE bug 867531</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20142525" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-2525</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-2525" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2525" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-2525" ref_url="https://www.suse.com/security/cve/CVE-2014-2525" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0456-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-March/000769.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0953-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0953-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001412.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0500-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-04/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0319-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1067-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-04/msg00050.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-2525/">CVE-2014-2525</cve>
	<bugzilla href="https://bugzilla.suse.com/868944">SUSE bug 868944</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/911782">SUSE bug 911782</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480828" comment="libyaml-0-2-0.1.7-1.17 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20142532" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-2532</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-2532" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2532" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-2532" ref_url="https://www.suse.com/security/cve/CVE-2014-2532" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000878.html" source="SUSE-SU"/>
    <description>
    sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.9/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2014-2532/">CVE-2014-2532</cve>
	<bugzilla href="https://bugzilla.suse.com/1074631">SUSE bug 1074631</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/869101">SUSE bug 869101</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/890850">SUSE bug 890850</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/916239">SUSE bug 916239</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/996040">SUSE bug 996040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333996" comment="openssh is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20142672" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-2672</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-2672" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2672" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-2672" ref_url="https://www.suse.com/security/cve/CVE-2014-2672" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-June/000882.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00010.html" source="SUSE-SU"/>
    <description>
    Race condition in the ath_tx_aggr_sleep function in drivers/net/wireless/ath/ath9k/xmit.c in the Linux kernel before 3.13.7 allows remote attackers to cause a denial of service (system crash) via a large amount of network traffic that triggers certain list deletions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-17"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-2672/">CVE-2014-2672</cve>
	<bugzilla href="https://bugzilla.suse.com/871148">SUSE bug 871148</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20142678" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-2678</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-2678" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2678" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-2678" ref_url="https://www.suse.com/security/cve/CVE-2014-2678" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0840-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0856-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00000.html" source="SUSE-SU"/>
    <description>
    The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS socket on a system that lacks RDS transports.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-2678/">CVE-2014-2678</cve>
	<bugzilla href="https://bugzilla.suse.com/871561">SUSE bug 871561</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20142706" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-2706</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-2706" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2706" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-2706" ref_url="https://www.suse.com/security/cve/CVE-2014-2706" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-September/000987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1316-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1246-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00056.html" source="SUSE-SU"/>
    <description>
    Race condition in the mac80211 subsystem in the Linux kernel before 3.13.7 allows remote attackers to cause a denial of service (system crash) via network traffic that improperly interacts with the WLAN_STA_PS_STA state (aka power-save mode), related to sta_info.c and tx.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-20"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-2706/">CVE-2014-2706</cve>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/871797">SUSE bug 871797</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143122" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3122</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3122" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3122" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3122" ref_url="https://www.suse.com/security/cve/CVE-2014-3122" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0766-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0840-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0856-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00000.html" source="SUSE-SU"/>
    <description>
    The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages must be locked, which allows local users to cause a denial of service (system crash) by triggering a memory-usage pattern that requires removal of page-table mappings.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3122/">CVE-2014-3122</cve>
	<bugzilla href="https://bugzilla.suse.com/824295">SUSE bug 824295</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/876102">SUSE bug 876102</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143144" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3144</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3144" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3144" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3144" ref_url="https://www.suse.com/security/cve/CVE-2014-3144" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-September/000987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0840-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0957-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1246-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00056.html" source="SUSE-SU"/>
    <description>
    The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is sufficiently large, which allows local users to cause a denial of service (integer underflow and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nlattr and __skb_get_nlattr_nest functions before the vulnerability was announced.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3144/">CVE-2014-3144</cve>
	<bugzilla href="https://bugzilla.suse.com/824295">SUSE bug 824295</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/877257">SUSE bug 877257</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/889071">SUSE bug 889071</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143145" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3145</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3145" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3145" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3145" ref_url="https://www.suse.com/security/cve/CVE-2014-3145" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-September/000987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0840-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0957-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1246-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00056.html" source="SUSE-SU"/>
    <description>
    The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nlattr_nest function before the vulnerability was announced.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-3145/">CVE-2014-3145</cve>
	<bugzilla href="https://bugzilla.suse.com/824295">SUSE bug 824295</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/877257">SUSE bug 877257</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143153" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3153</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3153" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3153" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3153" ref_url="https://www.suse.com/security/cve/CVE-2014-3153" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0775-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0796-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0837-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0837-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0840-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0856-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0878-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00006.html" source="SUSE-SU"/>
    <description>
    The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-3153/">CVE-2014-3153</cve>
	<bugzilla href="https://bugzilla.suse.com/877775">SUSE bug 877775</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/880892">SUSE bug 880892</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/882228">SUSE bug 882228</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143181" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3181</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3181" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3181" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3181" ref_url="https://www.suse.com/security/cve/CVE-2014-3181" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux kernel through 3.16.3 allow physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with an event.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3181/">CVE-2014-3181</cve>
	<bugzilla href="https://bugzilla.suse.com/896382">SUSE bug 896382</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143184" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3184</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3184" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3184" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3184" ref_url="https://www.suse.com/security/cve/CVE-2014-3184" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The report_fixup functions in the HID subsystem in the Linux kernel before 3.16.2 might allow physically proximate attackers to cause a denial of service (out-of-bounds write) via a crafted device that provides a small report descriptor, related to (1) drivers/hid/hid-cherry.c, (2) drivers/hid/hid-kye.c, (3) drivers/hid/hid-lg.c, (4) drivers/hid/hid-monterey.c, (5) drivers/hid/hid-petalynx.c, and (6) drivers/hid/hid-sunplus.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3184/">CVE-2014-3184</cve>
	<bugzilla href="https://bugzilla.suse.com/896390">SUSE bug 896390</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143185" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3185</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3185" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3185" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3185" ref_url="https://www.suse.com/security/cve/CVE-2014-3185" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0068-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3185/">CVE-2014-3185</cve>
	<bugzilla href="https://bugzilla.suse.com/896391">SUSE bug 896391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143186" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3186</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3186" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3186" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3186" ref_url="https://www.suse.com/security/cve/CVE-2014-3186" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that sends a large report.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3186/">CVE-2014-3186</cve>
	<bugzilla href="https://bugzilla.suse.com/896392">SUSE bug 896392</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143461" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3461</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3461" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3461" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3461" ref_url="https://www.suse.com/security/cve/CVE-2014-3461" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-October/001032.html" source="SUSE-SU"/>
    <description>
    hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, related to "USB post load checks."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3461/">CVE-2014-3461</cve>
	<bugzilla href="https://bugzilla.suse.com/878541">SUSE bug 878541</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143513" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3513</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3513" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3513" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3513" ref_url="https://www.suse.com/security/cve/CVE-2014-3513" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1357-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1386-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-November/001084.html" source="SUSE-SU"/>
		<reference ref_id="TID7010867" ref_url="https://www.suse.com/support/kb/doc/?id=7010867" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1331-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1426-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00059.html" source="SUSE-SU"/>
    <description>
    Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenSSL 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted handshake message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2014-3513/">CVE-2014-3513</cve>
	<bugzilla href="https://bugzilla.suse.com/901277">SUSE bug 901277</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143567" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3567</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3567" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3567" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3567" ref_url="https://www.suse.com/security/cve/CVE-2014-3567" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1357-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1361-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1386-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1387-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-November/001080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-November/001084.html" source="SUSE-SU"/>
		<reference ref_id="TID7010867" ref_url="https://www.suse.com/support/kb/doc/?id=7010867" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1331-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1426-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    Memory leak in the tls_decrypt_ticket function in t1_lib.c in OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted session ticket that triggers an integrity-check failure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-3567/">CVE-2014-3567</cve>
	<bugzilla href="https://bugzilla.suse.com/877506">SUSE bug 877506</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/901277">SUSE bug 901277</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/905106">SUSE bug 905106</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143568" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3568</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3568" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3568" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3568" ref_url="https://www.suse.com/security/cve/CVE-2014-3568" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1357-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1361-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1386-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1387-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1409-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-November/001080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-November/001084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1557-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001094.html" source="SUSE-SU"/>
		<reference ref_id="TID7010867" ref_url="https://www.suse.com/support/kb/doc/?id=7010867" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1331-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1426-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option, which allows remote attackers to bypass intended access restrictions via an SSL 3.0 handshake, related to s23_clnt.c and s23_srvr.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3568/">CVE-2014-3568</cve>
	<bugzilla href="https://bugzilla.suse.com/901277">SUSE bug 901277</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/905106">SUSE bug 905106</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/911399">SUSE bug 911399</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986238">SUSE bug 986238</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143569" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3569</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3569" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3569" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3569" ref_url="https://www.suse.com/security/cve/CVE-2014-3569" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="TID7016027" ref_url="https://www.suse.com/support/kb/doc/?id=7016027" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0130-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 0.9.8zc, 1.0.0o, and 1.0.1j does not properly handle attempts to use unsupported protocols, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unexpected handshake, as demonstrated by an SSLv3 handshake to a no-ssl3 application with certain error handling.  NOTE: this issue became relevant after the CVE-2014-3568 fix.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3569/">CVE-2014-3569</cve>
	<bugzilla href="https://bugzilla.suse.com/911399">SUSE bug 911399</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927623">SUSE bug 927623</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986238">SUSE bug 986238</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143570" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3570</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3570" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3570" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3570" ref_url="https://www.suse.com/security/cve/CVE-2014-3570" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001190.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0182-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0130-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calculate the square of a BIGNUM value, which might make it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors, related to crypto/bn/asm/mips.pl, crypto/bn/asm/x86_64-gcc.c, and crypto/bn/bn_asm.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3570/">CVE-2014-3570</cve>
	<bugzilla href="https://bugzilla.suse.com/912296">SUSE bug 912296</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/915848">SUSE bug 915848</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927623">SUSE bug 927623</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/944456">SUSE bug 944456</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143571" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3571</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3571" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3571" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3571" ref_url="https://www.suse.com/security/cve/CVE-2014-3571" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001190.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0130-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DTLS message that is processed with a different read operation for the handshake header than for the handshake body, related to the dtls1_get_record function in d1_pkt.c and the ssl3_read_n function in s3_pkt.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3571/">CVE-2014-3571</cve>
	<bugzilla href="https://bugzilla.suse.com/912294">SUSE bug 912294</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/915848">SUSE bug 915848</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927623">SUSE bug 927623</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143572" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3572</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3572" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3572" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3572" ref_url="https://www.suse.com/security/cve/CVE-2014-3572" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001190.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0182-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0130-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3572/">CVE-2014-3572</cve>
	<bugzilla href="https://bugzilla.suse.com/912015">SUSE bug 912015</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/915848">SUSE bug 915848</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927623">SUSE bug 927623</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143591" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3591</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3591" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3591" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3591" ref_url="https://www.suse.com/security/cve/CVE-2014-3591" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001602.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1503-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-09/msg00005.html" source="SUSE-SU"/>
    <description>
    Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2014-3591/">CVE-2014-3591</cve>
	<bugzilla href="https://bugzilla.suse.com/920057">SUSE bug 920057</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/949135">SUSE bug 949135</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482233" comment="libgcrypt20-1.8.2-8.36.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143601" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3601</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3601" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3601" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3601" ref_url="https://www.suse.com/security/cve/CVE-2014-3601" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3601/">CVE-2014-3601</cve>
	<bugzilla href="https://bugzilla.suse.com/892782">SUSE bug 892782</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/902675">SUSE bug 902675</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143610" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3610</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3610" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3610" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3610" ref_url="https://www.suse.com/security/cve/CVE-2014-3610" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0068-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the wrmsr_interception function in arch/x86/kvm/svm.c and the handle_wrmsr function in arch/x86/kvm/vmx.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-3610/">CVE-2014-3610</cve>
	<bugzilla href="https://bugzilla.suse.com/899192">SUSE bug 899192</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143631" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3631</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3631" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3631" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3631" ref_url="https://www.suse.com/security/cve/CVE-2014-3631" source="SUSE CVE"/>
    <description>
    The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via multiple "keyctl newring" operations followed by a "keyctl timeout" operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-3631/">CVE-2014-3631</cve>
	<bugzilla href="https://bugzilla.suse.com/896262">SUSE bug 896262</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143636" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3636</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3636" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3636" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3636" ref_url="https://www.suse.com/security/cve/CVE-2014-3636" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001137.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1228-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1239-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00049.html" source="SUSE-SU"/>
    <description>
    D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the allowed number of file descriptors for a single sendmsg call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3636/">CVE-2014-3636</cve>
	<bugzilla href="https://bugzilla.suse.com/896453">SUSE bug 896453</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/904017">SUSE bug 904017</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481908" comment="dbus-1-1.12.2-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481911" comment="libdbus-1-3-1.12.2-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143637" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3637</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3637" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3637" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3637" ref_url="https://www.suse.com/security/cve/CVE-2014-3637" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:1228-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1239-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00049.html" source="SUSE-SU"/>
    <description>
    D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial of service via a D-bus message containing a D-Bus connection file descriptor.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3637/">CVE-2014-3637</cve>
	<bugzilla href="https://bugzilla.suse.com/896453">SUSE bug 896453</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481908" comment="dbus-1-1.12.2-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481911" comment="libdbus-1-3-1.12.2-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143639" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3639</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3639" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3639" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3639" ref_url="https://www.suse.com/security/cve/CVE-2014-3639" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:1228-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1239-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00049.html" source="SUSE-SU"/>
    <description>
    The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection consumption and prevention of new connections) via a large number of incomplete connections.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3639/">CVE-2014-3639</cve>
	<bugzilla href="https://bugzilla.suse.com/896453">SUSE bug 896453</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/903055">SUSE bug 903055</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/903057">SUSE bug 903057</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481908" comment="dbus-1-1.12.2-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481911" comment="libdbus-1-3-1.12.2-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143640" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3640</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3640" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3640" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3640" ref_url="https://www.suse.com/security/cve/CVE-2014-3640" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001247.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
    <description>
    The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<cve href="https://www.suse.com/security/cve/CVE-2014-3640/">CVE-2014-3640</cve>
	<bugzilla href="https://bugzilla.suse.com/897654">SUSE bug 897654</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/965112">SUSE bug 965112</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143646" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3646</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3646" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3646" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3646" ref_url="https://www.suse.com/security/cve/CVE-2014-3646" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-3646/">CVE-2014-3646</cve>
	<bugzilla href="https://bugzilla.suse.com/899192">SUSE bug 899192</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143660" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3660</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3660" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3660" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3660" ref_url="https://www.suse.com/security/cve/CVE-2014-3660" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-November/001065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001142.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1330-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-10/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
    <description>
    parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3660/">CVE-2014-3660</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/901546">SUSE bug 901546</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143672" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3672</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3672" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3672" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3672" ref_url="https://www.suse.com/security/cve/CVE-2014-3672" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-3672/">CVE-2014-3672</cve>
	<bugzilla href="https://bugzilla.suse.com/981264">SUSE bug 981264</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143673" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3673</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3673" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3673" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3673" ref_url="https://www.suse.com/security/cve/CVE-2014-3673" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0068-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0529-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-3673/">CVE-2014-3673</cve>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/902346">SUSE bug 902346</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/902349">SUSE bug 902349</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/904899">SUSE bug 904899</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143675" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3675</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3675" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3675" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3675" ref_url="https://www.suse.com/security/cve/CVE-2014-3675" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1619-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00011.html" source="SUSE-SU"/>
    <description>
    Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-3675/">CVE-2014-3675</cve>
	<bugzilla href="https://bugzilla.suse.com/889332">SUSE bug 889332</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760862" comment="shim-15+git47-3.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143676" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3676</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3676" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3676" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3676" ref_url="https://www.suse.com/security/cve/CVE-2014-3676" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1619-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00011.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-3676/">CVE-2014-3676</cve>
	<bugzilla href="https://bugzilla.suse.com/889332">SUSE bug 889332</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760862" comment="shim-15+git47-3.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143677" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3677</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3677" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3677" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3677" ref_url="https://www.suse.com/security/cve/CVE-2014-3677" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1619-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00011.html" source="SUSE-SU"/>
    <description>
    Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-3677/">CVE-2014-3677</cve>
	<bugzilla href="https://bugzilla.suse.com/889332">SUSE bug 889332</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760862" comment="shim-15+git47-3.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143686" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3686</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3686" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3686" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3686" ref_url="https://www.suse.com/security/cve/CVE-2014-3686" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1356-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-11/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1013-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001423.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1313-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1314-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-10/msg00028.html" source="SUSE-SU"/>
    <description>
    wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3686/">CVE-2014-3686</cve>
	<bugzilla href="https://bugzilla.suse.com/1063667">SUSE bug 1063667</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/900611">SUSE bug 900611</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/915323">SUSE bug 915323</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143687" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3687</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3687" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3687" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3687" ref_url="https://www.suse.com/security/cve/CVE-2014-3687" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0178-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0529-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1489-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-3687/">CVE-2014-3687</cve>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/902349">SUSE bug 902349</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/904899">SUSE bug 904899</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/909208">SUSE bug 909208</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143688" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3688</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3688" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3688" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3688" ref_url="https://www.suse.com/security/cve/CVE-2014-3688" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2177-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20182177-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3688/">CVE-2014-3688</cve>
	<bugzilla href="https://bugzilla.suse.com/902351">SUSE bug 902351</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143690" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3690</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3690" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3690" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3690" ref_url="https://www.suse.com/security/cve/CVE-2014-3690" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0178-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm access, as demonstrated by PR_SET_TSC prctl calls within a modified copy of QEMU.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-3690/">CVE-2014-3690</cve>
	<bugzilla href="https://bugzilla.suse.com/902232">SUSE bug 902232</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143710" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3710</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3710" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3710" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3710" ref_url="https://www.suse.com/security/cve/CVE-2014-3710" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1473-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-November/001074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003580.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1516-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00113.html" source="SUSE-SU"/>
    <description>
    The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3710/">CVE-2014-3710</cve>
	<bugzilla href="https://bugzilla.suse.com/902367">SUSE bug 902367</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/910252">SUSE bug 910252</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628435" comment="file-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628437" comment="file-magic-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628438" comment="libmagic1-5.32-7.11.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20143917" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-3917</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-3917" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3917" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-3917" ref_url="https://www.suse.com/security/cve/CVE-2014-3917" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-September/000987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0957-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1246-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00056.html" source="SUSE-SU"/>
    <description>
    kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-3917/">CVE-2014-3917</cve>
	<bugzilla href="https://bugzilla.suse.com/880484">SUSE bug 880484</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20144040" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-4040</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-4040" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4040" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-4040" ref_url="https://www.suse.com/security/cve/CVE-2014-4040" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-September/001013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001210.html" source="SUSE-SU"/>
    <description>
    snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-4040/">CVE-2014-4040</cve>
	<bugzilla href="https://bugzilla.suse.com/883174">SUSE bug 883174</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760847" comment="powerpc-utils-1.3.7.1-3.27.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20144157" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-4157</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-4157" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4157" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-4157" ref_url="https://www.suse.com/security/cve/CVE-2014-4157" source="SUSE CVE"/>
    <description>
    arch/mips/include/asm/thread_info.h in the Linux kernel before 3.14.8 on the MIPS platform does not configure _TIF_SECCOMP checks on the fast system-call path, which allows local users to bypass intended PR_SET_SECCOMP restrictions by executing a crafted application without invoking a trace or audit subsystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-4157/">CVE-2014-4157</cve>
	<bugzilla href="https://bugzilla.suse.com/987709">SUSE bug 987709</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994755">SUSE bug 994755</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20144171" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-4171</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-4171" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4171" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-4171" ref_url="https://www.suse.com/security/cve/CVE-2014-4171" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1316-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0957-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
    <description>
    mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_FL_PUNCH_HOLE fallocate call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-03"/>
	<updated date="2023-04-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-4171/">CVE-2014-4171</cve>
	<bugzilla href="https://bugzilla.suse.com/883518">SUSE bug 883518</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20144508" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-4508</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-4508" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4508" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-4508" ref_url="https://www.suse.com/security/cve/CVE-2014-4508" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0910-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-September/000987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1316-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0957-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1246-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to cause a denial of service (OOPS and system crash) via an invalid syscall number, as demonstrated by number 1000.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-4508/">CVE-2014-4508</cve>
	<bugzilla href="https://bugzilla.suse.com/883724">SUSE bug 883724</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20144607" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-4607</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-4607" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4607" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-4607" ref_url="https://www.suse.com/security/cve/CVE-2014-4607" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:0904-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-07/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0932-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00034.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2014-4607/">CVE-2014-4607</cve>
	<bugzilla href="https://bugzilla.suse.com/883947">SUSE bug 883947</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480611" comment="liblzo2-2-2.10-2.22 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20144608" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-4608</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-4608" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4608" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-4608" ref_url="https://www.suse.com/security/cve/CVE-2014-4608" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Literal Run.  NOTE: the author of the LZO algorithms says "the Linux kernel is *not* affected; media hype."
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-4608/">CVE-2014-4608</cve>
	<bugzilla href="https://bugzilla.suse.com/883948">SUSE bug 883948</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20144611" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-4611</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-4611" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4611" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-4611" ref_url="https://www.suse.com/security/cve/CVE-2014-4611" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:0924-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-07/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-19"/>
	<updated date="2023-04-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-4611/">CVE-2014-4611</cve>
	<bugzilla href="https://bugzilla.suse.com/883949">SUSE bug 883949</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/885389">SUSE bug 885389</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20144650" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-4650</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-4650" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4650" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-4650" ref_url="https://www.suse.com/security/cve/CVE-2014-4650" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-August/000947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:0998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-August/000948.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1005-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-August/000952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1006-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-August/000953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1009-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-August/000955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-August/000957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1012-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-August/000958.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-August/001525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1041-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-08/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1042-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-08/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1046-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-08/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1070-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1734-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-12/msg00111.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2120-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00089.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2014-4650/">CVE-2014-4650</cve>
	<bugzilla href="https://bugzilla.suse.com/856835">SUSE bug 856835</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/856836">SUSE bug 856836</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/863741">SUSE bug 863741</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/885882">SUSE bug 885882</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/898572">SUSE bug 898572</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/912739">SUSE bug 912739</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20144667" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-4667</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-4667" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4667" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-4667" ref_url="https://www.suse.com/security/cve/CVE-2014-4667" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-September/000987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1316-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0957-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:0985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1246-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00056.html" source="SUSE-SU"/>
    <description>
    The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-4667/">CVE-2014-4667</cve>
	<bugzilla href="https://bugzilla.suse.com/885422">SUSE bug 885422</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20144715" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-4715</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-4715" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4715" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-4715" ref_url="https://www.suse.com/security/cve/CVE-2014-4715" source="SUSE CVE"/>
    <description>
    Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run, a different vulnerability than CVE-2014-4611.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-4715/">CVE-2014-4715</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009678603" comment="liblz4-1 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20144943" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-4943</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-4943" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4943" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-4943" ref_url="https://www.suse.com/security/cve/CVE-2014-4943" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1316-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-4943/">CVE-2014-4943</cve>
	<bugzilla href="https://bugzilla.suse.com/887082">SUSE bug 887082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20145033" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-5033</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-5033" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5033" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-5033" ref_url="https://www.suse.com/security/cve/CVE-2014-5033" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:0981-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-08/msg00012.html" source="SUSE-SU"/>
    <description>
    KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-5033/">CVE-2014-5033</cve>
	<bugzilla href="https://bugzilla.suse.com/864716">SUSE bug 864716</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/912121">SUSE bug 912121</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334933" comment="libvirt-daemon is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334936" comment="libvirt-daemon-driver-interface is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334939" comment="libvirt-daemon-driver-network is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334940" comment="libvirt-daemon-driver-nodedev is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334941" comment="libvirt-daemon-driver-nwfilter is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334942" comment="libvirt-daemon-driver-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334943" comment="libvirt-daemon-driver-secret is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334944" comment="libvirt-daemon-driver-storage is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336191" comment="libvirt-daemon-driver-storage-core is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336192" comment="libvirt-daemon-driver-storage-disk is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336193" comment="libvirt-daemon-driver-storage-iscsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336194" comment="libvirt-daemon-driver-storage-logical is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336195" comment="libvirt-daemon-driver-storage-mpath is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336196" comment="libvirt-daemon-driver-storage-rbd is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336197" comment="libvirt-daemon-driver-storage-scsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334946" comment="libvirt-daemon-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336198" comment="libvirt-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20145045" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-5045</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-5045" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5045" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-5045" ref_url="https://www.suse.com/security/cve/CVE-2014-5045" source="SUSE CVE"/>
    <description>
    The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the umount system call in conjunction with a symlink, which allows local users to cause a denial of service (memory consumption or use-after-free) or possibly have unspecified other impact via the umount program.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-5045/">CVE-2014-5045</cve>
	<bugzilla href="https://bugzilla.suse.com/889060">SUSE bug 889060</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20145077" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-5077</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-5077" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5077" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-5077" ref_url="https://www.suse.com/security/cve/CVE-2014-5077" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-September/000987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1316-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1246-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-09/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
    <description>
    The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an association between two endpoints immediately after an exchange of INIT and INIT ACK chunks to establish an earlier association between these endpoints in the opposite direction.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-5077/">CVE-2014-5077</cve>
	<bugzilla href="https://bugzilla.suse.com/889173">SUSE bug 889173</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20145277" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-5277</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-5277" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5277" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-5277" ref_url="https://www.suse.com/security/cve/CVE-2014-5277" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001112.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1411-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00048.html" source="SUSE-SU"/>
    <description>
    Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-5277/">CVE-2014-5277</cve>
	<bugzilla href="https://bugzilla.suse.com/904165">SUSE bug 904165</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20145351" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-5351</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-5351" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5351" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-5351" ref_url="https://www.suse.com/security/cve/CVE-2014-5351" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1410-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-November/001060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0290-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0255-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00044.html" source="SUSE-SU"/>
    <description>
    The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13 sends old keys in a response to a -randkey -keepold request, which allows remote authenticated users to forge tickets by leveraging administrative access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-5351/">CVE-2014-5351</cve>
	<bugzilla href="https://bugzilla.suse.com/897874">SUSE bug 897874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20145352" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-5352</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-5352" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5352" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-5352" ref_url="https://www.suse.com/security/cve/CVE-2014-5352" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0257-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0290-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0255-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00044.html" source="SUSE-SU"/>
    <description>
    The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_token.c in the libgssapi_krb5 library in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly maintain security-context handles, which allows remote authenticated users to cause a denial of service (use-after-free and double free, and daemon crash) or possibly execute arbitrary code via crafted GSSAPI traffic, as demonstrated by traffic to kadmind.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-5352/">CVE-2014-5352</cve>
	<bugzilla href="https://bugzilla.suse.com/1005509">SUSE bug 1005509</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/770172">SUSE bug 770172</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/912002">SUSE bug 912002</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20145353" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-5353</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-5353" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5353" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-5353" ref_url="https://www.suse.com/security/cve/CVE-2014-5353" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001507.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0542-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00061.html" source="SUSE-SU"/>
    <description>
    The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password policy.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-5353/">CVE-2014-5353</cve>
	<bugzilla href="https://bugzilla.suse.com/910457">SUSE bug 910457</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20145354" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-5354</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-5354" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5354" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-5354" ref_url="https://www.suse.com/security/cve/CVE-2014-5354" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001507.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0542-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00061.html" source="SUSE-SU"/>
    <description>
    plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by creating a database entry for a keyless principal, as demonstrated by a kadmin "add_principal -nokey" or "purgekeys -all" command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-5354/">CVE-2014-5354</cve>
	<bugzilla href="https://bugzilla.suse.com/910458">SUSE bug 910458</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20145355" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-5355</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-5355" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5355" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-5355" ref_url="https://www.suse.com/security/cve/CVE-2014-5355" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001507.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0542-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00061.html" source="SUSE-SU"/>
    <description>
    MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a string ending with a '\0' character, which allows remote attackers to (1) cause a denial of service (NULL pointer dereference) via a zero-byte version string or (2) cause a denial of service (out-of-bounds read) by omitting the '\0' character, related to appl/user_user/server.c and lib/krb5/krb/recvauth.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-5355/">CVE-2014-5355</cve>
	<bugzilla href="https://bugzilla.suse.com/770172">SUSE bug 770172</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/918595">SUSE bug 918595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20145471" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-5471</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-5471" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5471" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-5471" ref_url="https://www.suse.com/security/cve/CVE-2014-5471" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1316-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 image with a CL entry referring to a directory entry that has a CL entry.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-5471/">CVE-2014-5471</cve>
	<bugzilla href="https://bugzilla.suse.com/892490">SUSE bug 892490</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20145472" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-5472</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-5472" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5472" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-5472" ref_url="https://www.suse.com/security/cve/CVE-2014-5472" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1316-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-5472/">CVE-2014-5472</cve>
	<bugzilla href="https://bugzilla.suse.com/892490">SUSE bug 892490</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20146272" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-6272</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-6272" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6272" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-6272" ref_url="https://www.suse.com/security/cve/CVE-2014-6272" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-October/001034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0132-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-01/msg00070.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop.  NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2015-6525 for the functions that are only affected in 2.0 and later.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-6272/">CVE-2014-6272</cve>
	<bugzilla href="https://bugzilla.suse.com/897243">SUSE bug 897243</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/943011">SUSE bug 943011</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/947373">SUSE bug 947373</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480525" comment="libevent-2_1-8-2.1.8-2.23 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20146407" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-6407</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-6407" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6407" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-6407" ref_url="https://www.suse.com/security/cve/CVE-2014-6407" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001112.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1596-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00009.html" source="SUSE-SU"/>
    <description>
    Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-6407/">CVE-2014-6407</cve>
	<bugzilla href="https://bugzilla.suse.com/907012">SUSE bug 907012</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20146408" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-6408</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-6408" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6408" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-6408" ref_url="https://www.suse.com/security/cve/CVE-2014-6408" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001112.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1596-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00009.html" source="SUSE-SU"/>
    <description>
    Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-6408/">CVE-2014-6408</cve>
	<bugzilla href="https://bugzilla.suse.com/907014">SUSE bug 907014</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20146410" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-6410</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-6410" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6410" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-6410" ref_url="https://www.suse.com/security/cve/CVE-2014-6410" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
    <description>
    The __udf_read_inode function in fs/udf/inode.c in the Linux kernel through 3.16.3 does not restrict the amount of ICB indirection, which allows physically proximate attackers to cause a denial of service (infinite loop or stack consumption) via a UDF filesystem with a crafted inode.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-19"/>
	<updated date="2023-04-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-6410/">CVE-2014-6410</cve>
	<bugzilla href="https://bugzilla.suse.com/896689">SUSE bug 896689</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20146418" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-6418</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-6418" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6418" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-6418" ref_url="https://www.suse.com/security/cve/CVE-2014-6418" source="SUSE CVE"/>
    <description>
    net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-22"/>
	<updated date="2023-05-22"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-6418/">CVE-2014-6418</cve>
	<bugzilla href="https://bugzilla.suse.com/896384">SUSE bug 896384</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147202" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7202</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7202" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7202" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7202" ref_url="https://www.suse.com/security/cve/CVE-2014-7202" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:1381-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1493-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00101.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a crafted connection request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-7202/">CVE-2014-7202</cve>
	<bugzilla href="https://bugzilla.suse.com/898917">SUSE bug 898917</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628931" comment="libzmq5-4.2.3-3.15.4 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147203" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7203</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7203" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7203" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7203" ref_url="https://www.suse.com/security/cve/CVE-2014-7203" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:1381-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1493-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00101.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replay attacks via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-7203/">CVE-2014-7203</cve>
	<bugzilla href="https://bugzilla.suse.com/898917">SUSE bug 898917</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628931" comment="libzmq5-4.2.3-3.15.4 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147207" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7207</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7207" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7207" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7207" ref_url="https://www.suse.com/security/cve/CVE-2014-7207" source="SUSE CVE"/>
    <description>
    A certain Debian patch to the IPv6 implementation in the Linux kernel 3.2.x through 3.2.63 does not properly validate arguments in ipv6_select_ident function calls, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging (1) tun or (2) macvtap device access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-7207/">CVE-2014-7207</cve>
	<bugzilla href="https://bugzilla.suse.com/1139403">SUSE bug 1139403</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/902351">SUSE bug 902351</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147283" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7283</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7283" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7283" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7283" ref_url="https://www.suse.com/security/cve/CVE-2014-7283" source="SUSE CVE"/>
    <description>
    The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-7283/">CVE-2014-7283</cve>
	<bugzilla href="https://bugzilla.suse.com/899480">SUSE bug 899480</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147815" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7815</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7815" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7815" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7815" ref_url="https://www.suse.com/security/cve/CVE-2014-7815" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1782-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1445-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-7815/">CVE-2014-7815</cve>
	<bugzilla href="https://bugzilla.suse.com/902737">SUSE bug 902737</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962627">SUSE bug 962627</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147817" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7817</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7817" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7817" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7817" ref_url="https://www.suse.com/security/cve/CVE-2014-7817" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0439-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001304.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001305.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0351-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00089.html" source="SUSE-SU"/>
    <description>
    The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-7817/">CVE-2014-7817</cve>
	<bugzilla href="https://bugzilla.suse.com/906371">SUSE bug 906371</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147822" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7822</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7822" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7822" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7822" ref_url="https://www.suse.com/security/cve/CVE-2014-7822" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0529-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1488-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1489-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html" source="SUSE-SU"/>
    <description>
    The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted splice system call, as demonstrated by use of a file descriptor associated with an ext4 filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-7822/">CVE-2014-7822</cve>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/915322">SUSE bug 915322</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/915517">SUSE bug 915517</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/939240">SUSE bug 939240</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147823" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7823</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7823" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7823" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7823" ref_url="https://www.suse.com/security/cve/CVE-2014-7823" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001247.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1471-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00083.html" source="SUSE-SU"/>
    <description>
    The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-7823/">CVE-2014-7823</cve>
	<bugzilla href="https://bugzilla.suse.com/904176">SUSE bug 904176</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147824" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7824</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7824" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7824" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7824" ref_url="https://www.suse.com/security/cve/CVE-2014-7824" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1454-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1455-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00078.html" source="SUSE-SU"/>
    <description>
    D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-7824/">CVE-2014-7824</cve>
	<bugzilla href="https://bugzilla.suse.com/904017">SUSE bug 904017</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481908" comment="dbus-1-1.12.2-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481911" comment="libdbus-1-3-1.12.2-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147840" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7840</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7840" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7840" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7840" ref_url="https://www.suse.com/security/cve/CVE-2014-7840" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001243.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001247.html" source="SUSE-SU"/>
    <description>
    The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-7840/">CVE-2014-7840</cve>
	<bugzilla href="https://bugzilla.suse.com/905097">SUSE bug 905097</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147842" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7842</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7842" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7842" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7842" ref_url="https://www.suse.com/security/cve/CVE-2014-7842" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-7842/">CVE-2014-7842</cve>
	<bugzilla href="https://bugzilla.suse.com/905312">SUSE bug 905312</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/907822">SUSE bug 907822</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147970" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7970</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7970" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7970" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7970" ref_url="https://www.suse.com/security/cve/CVE-2014-7970" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
    <description>
    The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-7970/">CVE-2014-7970</cve>
	<bugzilla href="https://bugzilla.suse.com/900644">SUSE bug 900644</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20147975" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-7975</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-7975" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7975" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-7975" ref_url="https://www.suse.com/security/cve/CVE-2014-7975" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
    <description>
    The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-19"/>
	<updated date="2023-04-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-7975/">CVE-2014-7975</cve>
	<bugzilla href="https://bugzilla.suse.com/900392">SUSE bug 900392</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148086" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8086</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8086" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8086" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8086" ref_url="https://www.suse.com/security/cve/CVE-2014-8086" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1071-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1174-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1376-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1478-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html" source="SUSE-SU"/>
    <description>
    Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT flag.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-8086/">CVE-2014-8086</cve>
	<bugzilla href="https://bugzilla.suse.com/900881">SUSE bug 900881</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148106" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8106</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8106" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8106" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8106" ref_url="https://www.suse.com/security/cve/CVE-2014-8106" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001243.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001247.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-8106/">CVE-2014-8106</cve>
	<bugzilla href="https://bugzilla.suse.com/1023004">SUSE bug 1023004</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/907805">SUSE bug 907805</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148116" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8116</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8116" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8116" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8116" ref_url="https://www.suse.com/security/cve/CVE-2014-8116" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-November/003403.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003580.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1721-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-12/msg00105.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3067-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-11/msg00071.html" source="SUSE-SU"/>
    <description>
    The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-8116/">CVE-2014-8116</cve>
	<bugzilla href="https://bugzilla.suse.com/910252">SUSE bug 910252</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/910253">SUSE bug 910253</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/917152">SUSE bug 917152</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628435" comment="file-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628437" comment="file-magic-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628438" comment="libmagic1-5.32-7.11.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148117" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8117</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8117" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8117" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8117" ref_url="https://www.suse.com/security/cve/CVE-2014-8117" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-November/003403.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003580.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1721-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-12/msg00105.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3067-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-11/msg00071.html" source="SUSE-SU"/>
    <description>
    softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-8117/">CVE-2014-8117</cve>
	<bugzilla href="https://bugzilla.suse.com/910252">SUSE bug 910252</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/910253">SUSE bug 910253</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/917152">SUSE bug 917152</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628435" comment="file-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628437" comment="file-magic-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628438" comment="libmagic1-5.32-7.11.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148119" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8119</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8119" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8119" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8119" ref_url="https://www.suse.com/security/cve/CVE-2014-8119" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1792-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003801.html" source="SUSE-SU"/>
    <description>
    The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-8119/">CVE-2014-8119</cve>
	<bugzilla href="https://bugzilla.suse.com/925225">SUSE bug 925225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009480071" comment="augeas-1.10.1-1.11 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480073" comment="augeas-lenses-1.10.1-1.11 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480074" comment="libaugeas0-1.10.1-1.11 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148121" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8121</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8121" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8121" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8121" ref_url="https://www.suse.com/security/cve/CVE-2014-8121" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1424-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001651.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0955-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00084.html" source="SUSE-SU"/>
    <description>
    DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up on a database while iterating over it, which triggers the file pointer to be reset.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-8121/">CVE-2014-8121</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/918187">SUSE bug 918187</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/945779">SUSE bug 945779</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148131" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8131</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8131" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8131" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8131" ref_url="https://www.suse.com/security/cve/CVE-2014-8131" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2015:0008-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-01/msg00005.html" source="SUSE-SU"/>
    <description>
    The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segmentation fault and crash) via a request to access the users does not have privileges to access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-8131/">CVE-2014-8131</cve>
	<bugzilla href="https://bugzilla.suse.com/909274">SUSE bug 909274</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148132" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8132</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8132" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8132" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8132" ref_url="https://www.suse.com/security/cve/CVE-2014-8132" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001140.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0017-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-01/msg00007.html" source="SUSE-SU"/>
    <description>
    Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-8132/">CVE-2014-8132</cve>
	<bugzilla href="https://bugzilla.suse.com/910790">SUSE bug 910790</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928323">SUSE bug 928323</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482409" comment="libssh4-0.8.7-10.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148133" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8133</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8133" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8133" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8133" ref_url="https://www.suse.com/security/cve/CVE-2014-8133" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0068-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1735-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanism, via a crafted application that makes a set_thread_area system call and later reads a 16-bit value.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-13"/>
	<updated date="2022-11-13"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-8133/">CVE-2014-8133</cve>
	<bugzilla href="https://bugzilla.suse.com/817142">SUSE bug 817142</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/906545">SUSE bug 906545</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/907818">SUSE bug 907818</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/909077">SUSE bug 909077</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148134" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8134</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8134" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8134" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8134" ref_url="https://www.suse.com/security/cve/CVE-2014-8134" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0713-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html" source="SUSE-SU"/>
    <description>
    The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2014-8134/">CVE-2014-8134</cve>
	<bugzilla href="https://bugzilla.suse.com/907818">SUSE bug 907818</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/909077">SUSE bug 909077</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/909078">SUSE bug 909078</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148148" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8148</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8148" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8148" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8148" ref_url="https://www.suse.com/security/cve/CVE-2014-8148" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2015:0111-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-01/msg00051.html" source="SUSE-SU"/>
    <description>
    The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals to any process on the system bus and possibly execute arbitrary code with root privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-8148/">CVE-2014-8148</cve>
	<bugzilla href="https://bugzilla.suse.com/912023">SUSE bug 912023</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481908" comment="dbus-1-1.12.2-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481911" comment="libdbus-1-3-1.12.2-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148150" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8150</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8150" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8150" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8150" ref_url="https://www.suse.com/security/cve/CVE-2014-8150" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001164.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001199.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0248-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00040.html" source="SUSE-SU"/>
    <description>
    CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-8150/">CVE-2014-8150</cve>
	<bugzilla href="https://bugzilla.suse.com/911363">SUSE bug 911363</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951391">SUSE bug 951391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148160" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8160</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8160" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8160" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8160" ref_url="https://www.suse.com/security/cve/CVE-2014-8160" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0529-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="TID7016668" ref_url="https://www.suse.com/support/kb/doc?id=7016668" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0713-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html" source="SUSE-SU"/>
    <description>
    net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-17"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-8160/">CVE-2014-8160</cve>
	<bugzilla href="https://bugzilla.suse.com/857643">SUSE bug 857643</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/913059">SUSE bug 913059</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148178" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8178</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8178" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8178" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8178" ref_url="https://www.suse.com/security/cve/CVE-2014-8178" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1757-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1773-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-10/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2073-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00125.html" source="SUSE-SU"/>
    <description>
    Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2014-8178/">CVE-2014-8178</cve>
	<bugzilla href="https://bugzilla.suse.com/949660">SUSE bug 949660</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148179" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8179</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8179" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8179" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8179" ref_url="https://www.suse.com/security/cve/CVE-2014-8179" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1757-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1773-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-10/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2073-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00125.html" source="SUSE-SU"/>
    <description>
    Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2014-8179/">CVE-2014-8179</cve>
	<bugzilla href="https://bugzilla.suse.com/949660">SUSE bug 949660</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148242" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8242</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8242" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8242" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8242" ref_url="https://www.suse.com/security/cve/CVE-2014-8242" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001811.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001813.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1752-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-10/msg00034.html" source="SUSE-SU"/>
    <description>
    librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birthday attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-8242/">CVE-2014-8242</cve>
	<bugzilla href="https://bugzilla.suse.com/900914">SUSE bug 900914</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/922710">SUSE bug 922710</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482539" comment="rsync-3.1.3-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148275" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8275</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8275" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8275" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8275" ref_url="https://www.suse.com/security/cve/CVE-2014-8275" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001190.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0182-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="TID7021823" ref_url="https://www.suse.com/support/kb/doc/?id=7021823" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0130-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-8275/">CVE-2014-8275</cve>
	<bugzilla href="https://bugzilla.suse.com/912018">SUSE bug 912018</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/915848">SUSE bug 915848</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927623">SUSE bug 927623</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148369" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8369</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8369" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8369" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8369" ref_url="https://www.suse.com/security/cve/CVE-2014-8369" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS privileges.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2014-3601.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-17"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2014-8369/">CVE-2014-8369</cve>
	<bugzilla href="https://bugzilla.suse.com/892782">SUSE bug 892782</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/902675">SUSE bug 902675</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148559" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8559</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8559" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8559" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8559" ref_url="https://www.suse.com/security/cve/CVE-2014-8559" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0178-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0529-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0713-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html" source="SUSE-SU"/>
    <description>
    The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2014-8559/">CVE-2014-8559</cve>
	<bugzilla href="https://bugzilla.suse.com/903640">SUSE bug 903640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/915517">SUSE bug 915517</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148564" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8564</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8564" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8564" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8564" ref_url="https://www.suse.com/security/cve/CVE-2014-8564" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001110.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1472-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-11/msg00084.html" source="SUSE-SU"/>
    <description>
    The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) Elliptic Curve Cryptography (ECC) certificate or (2) certificate signing requests (CSR), related to generating key IDs.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-8564/">CVE-2014-8564</cve>
	<bugzilla href="https://bugzilla.suse.com/904603">SUSE bug 904603</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148709" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8709</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8709" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8709" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8709" ref_url="https://www.suse.com/security/cve/CVE-2014-8709" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-8709/">CVE-2014-8709</cve>
	<bugzilla href="https://bugzilla.suse.com/904700">SUSE bug 904700</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148884" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8884</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8884" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8884" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8884" ref_url="https://www.suse.com/security/cve/CVE-2014-8884" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2014:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1693-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1695-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2014-12/msg00019.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before 3.17.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via a large message length in an ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-8884/">CVE-2014-8884</cve>
	<bugzilla href="https://bugzilla.suse.com/904876">SUSE bug 904876</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/905522">SUSE bug 905522</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/905739">SUSE bug 905739</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/905744">SUSE bug 905744</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/905748">SUSE bug 905748</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/905764">SUSE bug 905764</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20148964" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-8964</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-8964" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8964" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-8964" ref_url="https://www.suse.com/security/cve/CVE-2014-8964" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3161-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002488.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0858-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1216-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3099-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00076.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-8964/">CVE-2014-8964</cve>
	<bugzilla href="https://bugzilla.suse.com/906574">SUSE bug 906574</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/924960">SUSE bug 924960</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933288">SUSE bug 933288</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936408">SUSE bug 936408</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958373">SUSE bug 958373</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009480657" comment="libpcre1-8.41-4.20 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480667" comment="libpcre2-8-0-10.31-1.14 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149087" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9087</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9087" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9087" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9087" ref_url="https://www.suse.com/security/cve/CVE-2014-9087" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001154.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1682-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-12/msg00081.html" source="SUSE-SU"/>
    <description>
    Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-9087/">CVE-2014-9087</cve>
	<bugzilla href="https://bugzilla.suse.com/907074">SUSE bug 907074</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/926826">SUSE bug 926826</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/996084">SUSE bug 996084</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480597" comment="libksba8-1.3.5-2.14 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149092" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9092</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9092" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9092" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9092" ref_url="https://www.suse.com/security/cve/CVE-2014-9092" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0029-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001153.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1637-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-12/msg00055.html" source="SUSE-SU"/>
    <description>
    libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9092/">CVE-2014-9092</cve>
	<bugzilla href="https://bugzilla.suse.com/906761">SUSE bug 906761</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628779" comment="libjpeg8-8.1.2-5.15.7 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149112" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9112</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9112" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9112" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9112" ref_url="https://www.suse.com/security/cve/CVE-2014-9112" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1652-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001118.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1643-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-12/msg00061.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9112/">CVE-2014-9112</cve>
	<bugzilla href="https://bugzilla.suse.com/907456">SUSE bug 907456</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/913479">SUSE bug 913479</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481843" comment="cpio-2.12-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149114" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9114</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9114" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9114" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9114" ref_url="https://www.suse.com/security/cve/CVE-2014-9114" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001313.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0066-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-01/msg00035.html" source="SUSE-SU"/>
    <description>
    Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2014-9114/">CVE-2014-9114</cve>
	<bugzilla href="https://bugzilla.suse.com/907434">SUSE bug 907434</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/908742">SUSE bug 908742</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760806" comment="libblkid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760807" comment="libfdisk1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760808" comment="libmount1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760809" comment="libsmartcols1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760810" comment="libuuid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760811" comment="util-linux-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760812" comment="util-linux-systemd-2.33.1-4.13.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149130" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9130</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9130" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9130" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9130" ref_url="https://www.suse.com/security/cve/CVE-2014-9130" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2014-December/001131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1699-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2014:1699-3" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0013-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-April/001341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0925-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0953-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0953-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001412.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1625-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0319-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1067-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-04/msg00050.html" source="SUSE-SU"/>
    <description>
    scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9130/">CVE-2014-9130</cve>
	<bugzilla href="https://bugzilla.suse.com/907809">SUSE bug 907809</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/911782">SUSE bug 911782</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/921588">SUSE bug 921588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480828" comment="libyaml-0-2-0.1.7-1.17 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149356" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9356</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9356" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9356" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9356" ref_url="https://www.suse.com/security/cve/CVE-2014-9356" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001163.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1722-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-12/msg00106.html" source="SUSE-SU"/>
    <description>
    Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="8.6/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2014-9356/">CVE-2014-9356</cve>
	<bugzilla href="https://bugzilla.suse.com/909712">SUSE bug 909712</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/909747">SUSE bug 909747</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149357" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9357</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9357" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9357" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9357" ref_url="https://www.suse.com/security/cve/CVE-2014-9357" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001163.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1722-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-12/msg00106.html" source="SUSE-SU"/>
    <description>
    Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2014-9357/">CVE-2014-9357</cve>
	<bugzilla href="https://bugzilla.suse.com/909710">SUSE bug 909710</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/909747">SUSE bug 909747</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149358" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9358</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9358" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9358" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9358" ref_url="https://www.suse.com/security/cve/CVE-2014-9358" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001163.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2014:1722-1" ref_url="https://lists.opensuse.org/opensuse-updates/2014-12/msg00106.html" source="SUSE-SU"/>
    <description>
    Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9358/">CVE-2014-9358</cve>
	<bugzilla href="https://bugzilla.suse.com/909709">SUSE bug 909709</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/909747">SUSE bug 909747</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149402" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9402</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9402" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9402" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9402" ref_url="https://www.suse.com/security/cve/CVE-2014-9402" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0439-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001304.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001305.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0351-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00089.html" source="SUSE-SU"/>
    <description>
    The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-9402/">CVE-2014-9402</cve>
	<bugzilla href="https://bugzilla.suse.com/910599">SUSE bug 910599</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149419" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9419</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9419" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9419" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9419" ref_url="https://www.suse.com/security/cve/CVE-2014-9419" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0529-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1174-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1376-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0713-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel through 3.18.1 does not ensure that Thread Local Storage (TLS) descriptors are loaded before proceeding with other steps, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted application that reads a TLS base address.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-02"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-9419/">CVE-2014-9419</cve>
	<bugzilla href="https://bugzilla.suse.com/911326">SUSE bug 911326</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149420" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9420</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9420" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9420" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9420" ref_url="https://www.suse.com/security/cve/CVE-2014-9420" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0178-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0713-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html" source="SUSE-SU"/>
    <description>
    The rock_continue function in fs/isofs/rock.c in the Linux kernel through 3.18.1 does not restrict the number of Rock Ridge continuation entries, which allows local users to cause a denial of service (infinite loop, and system crash or hang) via a crafted iso9660 image.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-9420/">CVE-2014-9420</cve>
	<bugzilla href="https://bugzilla.suse.com/906545">SUSE bug 906545</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/911325">SUSE bug 911325</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149421" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9421</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9421" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9421" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9421" ref_url="https://www.suse.com/security/cve/CVE-2014-9421" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0257-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0290-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0255-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00044.html" source="SUSE-SU"/>
    <description>
    The auth_gssapi_unwrap_data function in lib/rpc/auth_gssapi_misc.c in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly handle partial XDR deserialization, which allows remote authenticated users to cause a denial of service (use-after-free and double free, and daemon crash) or possibly execute arbitrary code via malformed XDR data, as demonstrated by data sent to kadmind.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9421/">CVE-2014-9421</cve>
	<bugzilla href="https://bugzilla.suse.com/1005509">SUSE bug 1005509</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/770172">SUSE bug 770172</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/912002">SUSE bug 912002</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149422" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9422</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9422" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9422" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9422" ref_url="https://www.suse.com/security/cve/CVE-2014-9422" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0257-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0290-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0255-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00044.html" source="SUSE-SU"/>
    <description>
    The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 allows remote authenticated users to bypass a kadmin/* authorization check and obtain administrative access by leveraging access to a two-component principal with an initial "kadmind" substring, as demonstrated by a "ka/x" principal.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9422/">CVE-2014-9422</cve>
	<bugzilla href="https://bugzilla.suse.com/1005509">SUSE bug 1005509</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/770172">SUSE bug 770172</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/912002">SUSE bug 912002</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149423" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9423</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9423" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9423" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9423" ref_url="https://www.suse.com/security/cve/CVE-2014-9423" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0257-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0290-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-02/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0255-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00044.html" source="SUSE-SU"/>
    <description>
    The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9423/">CVE-2014-9423</cve>
	<bugzilla href="https://bugzilla.suse.com/1005509">SUSE bug 1005509</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/912002">SUSE bug 912002</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149447" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9447</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9447" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9447" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9447" ref_url="https://www.suse.com/security/cve/CVE-2014-9447" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0292-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001269.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0123-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-01/msg00063.html" source="SUSE-SU"/>
    <description>
    Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9447/">CVE-2014-9447</cve>
	<bugzilla href="https://bugzilla.suse.com/911662">SUSE bug 911662</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/912408">SUSE bug 912408</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149488" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9488</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9488" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9488" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9488" ref_url="https://www.suse.com/security/cve/CVE-2014-9488" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:2687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007445.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0595-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00077.html" source="SUSE-SU"/>
    <description>
    The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2014-9488/">CVE-2014-9488</cve>
	<bugzilla href="https://bugzilla.suse.com/921719">SUSE bug 921719</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480353" comment="less-530-1.6 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149512" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9512</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9512" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9512" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9512" ref_url="https://www.suse.com/security/cve/CVE-2014-9512" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001811.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001813.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1866-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-July/002164.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002227.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0249-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1671-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00095.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1695-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00112.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0101-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00044.html" source="SUSE-SU"/>
    <description>
    rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9512/">CVE-2014-9512</cve>
	<bugzilla href="https://bugzilla.suse.com/915410">SUSE bug 915410</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960191">SUSE bug 960191</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482539" comment="rsync-3.1.3-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149556" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9556</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9556" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9556" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9556" ref_url="https://www.suse.com/security/cve/CVE-2014-9556" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0366-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-November/001703.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0187-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0449-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00021.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (hang) via a crafted CAB file, which triggers an infinite loop.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9556/">CVE-2014-9556</cve>
	<bugzilla href="https://bugzilla.suse.com/912214">SUSE bug 912214</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/919283">SUSE bug 919283</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/934533">SUSE bug 934533</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482310" comment="libmspack0-0.6-3.8.19 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149584" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9584</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9584" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9584" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9584" ref_url="https://www.suse.com/security/cve/CVE-2014-9584" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0529-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0713-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html" source="SUSE-SU"/>
    <description>
    The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9584/">CVE-2014-9584</cve>
	<bugzilla href="https://bugzilla.suse.com/912654">SUSE bug 912654</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149585" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9585</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9585" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9585" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9585" ref_url="https://www.suse.com/security/cve/CVE-2014-9585" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0178-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0713-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html" source="SUSE-SU"/>
    <description>
    The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2014-9585/">CVE-2014-9585</cve>
	<bugzilla href="https://bugzilla.suse.com/912705">SUSE bug 912705</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149656" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9656</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9656" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9656" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9656" ref_url="https://www.suse.com/security/cve/CVE-2014-9656" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer overflow, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted OpenType font.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9656/">CVE-2014-9656</cve>
	<bugzilla href="https://bugzilla.suse.com/916847">SUSE bug 916847</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149657" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9657</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9657" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9657" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9657" ref_url="https://www.suse.com/security/cve/CVE-2014-9657" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="TID7021823" ref_url="https://www.suse.com/support/kb/doc/?id=7021823" source="SUSE-SU"/>
		<reference ref_id="TID7021836" ref_url="https://www.suse.com/support/kb/doc/?id=7021836" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9657/">CVE-2014-9657</cve>
	<bugzilla href="https://bugzilla.suse.com/916856">SUSE bug 916856</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149658" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9658</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9658" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9658" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9658" ref_url="https://www.suse.com/security/cve/CVE-2014-9658" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="TID7021823" ref_url="https://www.suse.com/support/kb/doc/?id=7021823" source="SUSE-SU"/>
		<reference ref_id="TID7021836" ref_url="https://www.suse.com/support/kb/doc/?id=7021836" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9658/">CVE-2014-9658</cve>
	<bugzilla href="https://bugzilla.suse.com/916857">SUSE bug 916857</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149659" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9659</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9659" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9659" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9659" ref_url="https://www.suse.com/security/cve/CVE-2014-9659" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted OpenType font.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2240.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9659/">CVE-2014-9659</cve>
	<bugzilla href="https://bugzilla.suse.com/916867">SUSE bug 916867</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149660" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9660</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9660" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9660" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9660" ref_url="https://www.suse.com/security/cve/CVE-2014-9660" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9660/">CVE-2014-9660</cve>
	<bugzilla href="https://bugzilla.suse.com/916858">SUSE bug 916858</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149661" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9661</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9661" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9661" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9661" ref_url="https://www.suse.com/security/cve/CVE-2014-9661" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted Type42 font.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9661/">CVE-2014-9661</cve>
	<bugzilla href="https://bugzilla.suse.com/916859">SUSE bug 916859</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149662" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9662</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9662" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9662" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9662" ref_url="https://www.suse.com/security/cve/CVE-2014-9662" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted OTF font.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9662/">CVE-2014-9662</cve>
	<bugzilla href="https://bugzilla.suse.com/916860">SUSE bug 916860</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149663" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9663</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9663" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9663" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9663" ref_url="https://www.suse.com/security/cve/CVE-2014-9663" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely calculated, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted cmap SFNT table.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9663/">CVE-2014-9663</cve>
	<bugzilla href="https://bugzilla.suse.com/916865">SUSE bug 916865</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149664" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9664</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9664" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9664" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9664" ref_url="https://www.suse.com/security/cve/CVE-2014-9664" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9664/">CVE-2014-9664</cve>
	<bugzilla href="https://bugzilla.suse.com/916864">SUSE bug 916864</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149665" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9665</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9665" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9665" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9665" ref_url="https://www.suse.com/security/cve/CVE-2014-9665" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    The Load_SBit_Png function in sfnt/pngshim.c in FreeType before 2.5.4 does not restrict the rows and pitch values of PNG data, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact by embedding a PNG file in a .ttf font file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9665/">CVE-2014-9665</cve>
	<bugzilla href="https://bugzilla.suse.com/916863">SUSE bug 916863</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149666" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9666</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9666" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9666" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9666" ref_url="https://www.suse.com/security/cve/CVE-2014-9666" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted embedded bitmap.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9666/">CVE-2014-9666</cve>
	<bugzilla href="https://bugzilla.suse.com/916862">SUSE bug 916862</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149667" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9667</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9667" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9667" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9667" ref_url="https://www.suse.com/security/cve/CVE-2014-9667" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9667/">CVE-2014-9667</cve>
	<bugzilla href="https://bugzilla.suse.com/916861">SUSE bug 916861</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149668" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9668</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9668" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9668" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9668" ref_url="https://www.suse.com/security/cve/CVE-2014-9668" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Web Open Font Format (WOFF) file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9668/">CVE-2014-9668</cve>
	<bugzilla href="https://bugzilla.suse.com/916868">SUSE bug 916868</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149669" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9669</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9669" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9669" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9669" ref_url="https://www.suse.com/security/cve/CVE-2014-9669" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9669/">CVE-2014-9669</cve>
	<bugzilla href="https://bugzilla.suse.com/916870">SUSE bug 916870</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149670" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9670</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9670" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9670" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9670" ref_url="https://www.suse.com/security/cve/CVE-2014-9670" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9670/">CVE-2014-9670</cve>
	<bugzilla href="https://bugzilla.suse.com/916871">SUSE bug 916871</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933247">SUSE bug 933247</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149671" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9671</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9671" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9671" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9671" ref_url="https://www.suse.com/security/cve/CVE-2014-9671" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PCF file with a 0xffffffff size value that is improperly incremented.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9671/">CVE-2014-9671</cve>
	<bugzilla href="https://bugzilla.suse.com/916872">SUSE bug 916872</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933247">SUSE bug 933247</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149672" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9672</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9672" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9672" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9672" ref_url="https://www.suse.com/security/cve/CVE-2014-9672" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9672/">CVE-2014-9672</cve>
	<bugzilla href="https://bugzilla.suse.com/916873">SUSE bug 916873</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149673" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9673</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9673" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9673" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9673" ref_url="https://www.suse.com/security/cve/CVE-2014-9673" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9673/">CVE-2014-9673</cve>
	<bugzilla href="https://bugzilla.suse.com/916874">SUSE bug 916874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149674" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9674</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9674" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9674" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9674" ref_url="https://www.suse.com/security/cve/CVE-2014-9674" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9674/">CVE-2014-9674</cve>
	<bugzilla href="https://bugzilla.suse.com/916879">SUSE bug 916879</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149675" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9675</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9675" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9675" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9675" ref_url="https://www.suse.com/security/cve/CVE-2014-9675" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001277.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0627-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00091.html" source="SUSE-SU"/>
    <description>
    bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9675/">CVE-2014-9675</cve>
	<bugzilla href="https://bugzilla.suse.com/916881">SUSE bug 916881</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149680" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9680</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9680" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9680" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9680" ref_url="https://www.suse.com/security/cve/CVE-2014-9680" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0985-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001420.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002420.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1849-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-10/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1913-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2983-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3004-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00029.html" source="SUSE-SU"/>
    <description>
    sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-9680/">CVE-2014-9680</cve>
	<bugzilla href="https://bugzilla.suse.com/917806">SUSE bug 917806</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/919737">SUSE bug 919737</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/921999">SUSE bug 921999</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/953359">SUSE bug 953359</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760863" comment="sudo-1.8.22-4.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149710" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9710</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9710" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9710" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9710" ref_url="https://www.suse.com/security/cve/CVE-2014-9710" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1489-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005579.html" source="SUSE-SU"/>
    <description>
    The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9710/">CVE-2014-9710</cve>
	<bugzilla href="https://bugzilla.suse.com/923908">SUSE bug 923908</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/939260">SUSE bug 939260</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149717" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9717</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9717" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9717" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9717" ref_url="https://www.suse.com/security/cve/CVE-2014-9717" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1690-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
    <description>
    fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate to filesystem locations beneath a mount by calling umount2 within a user namespace.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-20"/>
	<updated date="2023-04-20"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-9717/">CVE-2014-9717</cve>
	<bugzilla href="https://bugzilla.suse.com/928547">SUSE bug 928547</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149721" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9721</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9721" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9721" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9721" ref_url="https://www.suse.com/security/cve/CVE-2014-9721" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001578.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1028-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanisms via a ZMTP v2 or earlier header.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2014-9721/">CVE-2014-9721</cve>
	<bugzilla href="https://bugzilla.suse.com/931978">SUSE bug 931978</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628931" comment="libzmq5-4.2.3-3.15.4 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149728" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9728</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9728" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9728" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9728" ref_url="https://www.suse.com/security/cve/CVE-2014-9728" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1324-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1592-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001611.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows local users to cause a denial of service (buffer over-read and system crash) via a crafted filesystem image, related to fs/udf/inode.c and fs/udf/symlink.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-08"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-9728/">CVE-2014-9728</cve>
	<bugzilla href="https://bugzilla.suse.com/911325">SUSE bug 911325</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933904">SUSE bug 933904</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149729" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9729</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9729" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9729" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9729" ref_url="https://www.suse.com/security/cve/CVE-2014-9729" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1324-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1592-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001611.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.18.2 does not ensure a certain data-structure size consistency, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-06"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-9729/">CVE-2014-9729</cve>
	<bugzilla href="https://bugzilla.suse.com/911325">SUSE bug 911325</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933904">SUSE bug 933904</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149730" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9730</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9730" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9730" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9730" ref_url="https://www.suse.com/security/cve/CVE-2014-9730" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1324-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1592-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001611.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-01"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-9730/">CVE-2014-9730</cve>
	<bugzilla href="https://bugzilla.suse.com/911325">SUSE bug 911325</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933904">SUSE bug 933904</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149731" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9731</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9731" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9731" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9731" ref_url="https://www.suse.com/security/cve/CVE-2014-9731" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1324-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1592-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001611.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The UDF filesystem implementation in the Linux kernel before 3.18.2 does not ensure that space is available for storing a symlink target's name along with a trailing \0 character, which allows local users to obtain sensitive information via a crafted filesystem image, related to fs/udf/symlink.c and fs/udf/unicode.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-31"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2014-9731/">CVE-2014-9731</cve>
	<bugzilla href="https://bugzilla.suse.com/911325">SUSE bug 911325</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933896">SUSE bug 933896</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149761" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9761</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9761" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9761" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9761" ref_url="https://www.suse.com/security/cve/CVE-2014-9761" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0472-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="TID7017287" ref_url="https://www.suse.com/support/kb/doc?id=7017287" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0490-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00042.html" source="SUSE-SU"/>
    <description>
    Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2014-9761/">CVE-2014-9761</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962738">SUSE bug 962738</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986086">SUSE bug 986086</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149766" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9766</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9766" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9766" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9766" ref_url="https://www.suse.com/security/cve/CVE-2014-9766" source="SUSE CVE"/>
    <description>
    Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via large height and stride values.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2014-9766/">CVE-2014-9766</cve>
	<bugzilla href="https://bugzilla.suse.com/968090">SUSE bug 968090</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009337724" comment="libpixman-1-0 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149904" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9904</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9904" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9904" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9904" ref_url="https://www.suse.com/security/cve/CVE-2014-9904" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2105-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html" source="SUSE-SU"/>
    <description>
    The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2014-9904/">CVE-2014-9904</cve>
	<bugzilla href="https://bugzilla.suse.com/986811">SUSE bug 986811</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986941">SUSE bug 986941</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149914" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9914</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9914" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9914" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9914" ref_url="https://www.suse.com/security/cve/CVE-2014-9914" source="SUSE CVE"/>
    <description>
    Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2014-9914/">CVE-2014-9914</cve>
	<bugzilla href="https://bugzilla.suse.com/1023997">SUSE bug 1023997</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20149922" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2014-9922</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2014-9922" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9922" source="CVE"/>
    <reference ref_id="SUSE CVE-2014-9922" ref_url="https://www.suse.com/security/cve/CVE-2014-9922" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
    <description>
    The eCryptfs subsystem in the Linux kernel before 3.18 allows local users to gain privileges via a large filesystem stack that includes an overlayfs layer, related to fs/ecryptfs/main.c and fs/overlayfs/super.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2014-9922/">CVE-2014-9922</cve>
	<bugzilla href="https://bugzilla.suse.com/1032340">SUSE bug 1032340</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150204" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0204</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0204" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0204" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0204" ref_url="https://www.suse.com/security/cve/CVE-2015-0204" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001190.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0182-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1086-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1086-3" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1086-4" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1161-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2166-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2168-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2192-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2216-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7014420" ref_url="https://www.suse.com/support/kb/doc/?id=7014420" source="SUSE-SU"/>
		<reference ref_id="TID7016252" ref_url="https://www.suse.com/support/kb/doc?id=7016252" source="SUSE-SU"/>
		<reference ref_id="TID7016260" ref_url="https://www.suse.com/support/kb/doc/?id=7016260" source="SUSE-SU"/>
		<reference ref_id="TID7016273" ref_url="https://www.suse.com/support/kb/doc/?id=7016273" source="SUSE-SU"/>
		<reference ref_id="TID7016312" ref_url="https://www.suse.com/support/kb/doc/?id=7016312" source="SUSE-SU"/>
		<reference ref_id="TID7016336" ref_url="https://www.suse.com/support/kb/doc/?id=7016336" source="SUSE-SU"/>
		<reference ref_id="TID7016340" ref_url="https://www.suse.com/support/kb/doc/?id=7016340" source="SUSE-SU"/>
		<reference ref_id="TID7016875" ref_url="https://www.suse.com/support/kb/doc/?id=7016875" source="SUSE-SU"/>
		<reference ref_id="TID7021279" ref_url="https://www.suse.com/support/kb/doc/?id=7021279" source="SUSE-SU"/>
		<reference ref_id="TID7021435" ref_url="https://www.suse.com/support/kb/doc/?id=7021435" source="SUSE-SU"/>
		<reference ref_id="TID7021518" ref_url="https://www.suse.com/support/kb/doc/?id=7021518" source="SUSE-SU"/>
		<reference ref_id="TID7021676" ref_url="https://www.suse.com/support/kb/doc/?id=7021676" source="SUSE-SU"/>
		<reference ref_id="TID7021714" ref_url="https://www.suse.com/support/kb/doc/?id=7021714" source="SUSE-SU"/>
		<reference ref_id="TID7021743" ref_url="https://www.suse.com/support/kb/doc/?id=7021743" source="SUSE-SU"/>
		<reference ref_id="TID7021744" ref_url="https://www.suse.com/support/kb/doc/?id=7021744" source="SUSE-SU"/>
		<reference ref_id="TID7021848" ref_url="https://www.suse.com/support/kb/doc/?id=7021848" source="SUSE-SU"/>
		<reference ref_id="TID7021863" ref_url="https://www.suse.com/support/kb/doc/?id=7021863" source="SUSE-SU"/>
		<reference ref_id="TID7021977" ref_url="https://www.suse.com/support/kb/doc/?id=7021977" source="SUSE-SU"/>
		<reference ref_id="TID7021993" ref_url="https://www.suse.com/support/kb/doc/?id=7021993" source="SUSE-SU"/>
		<reference ref_id="TID7021994" ref_url="https://www.suse.com/support/kb/doc/?id=7021994" source="SUSE-SU"/>
		<reference ref_id="TID7021995" ref_url="https://www.suse.com/support/kb/doc/?id=7021995" source="SUSE-SU"/>
		<reference ref_id="TID7022102" ref_url="https://www.suse.com/support/kb/doc/?id=7022102" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0130-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncompliant role, related to the "FREAK" issue.  NOTE: the scope of this CVE is only client code based on OpenSSL, not EXPORT_RSA issues associated with servers or other TLS implementations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2015-0204/">CVE-2015-0204</cve>
	<bugzilla href="https://bugzilla.suse.com/912014">SUSE bug 912014</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/920482">SUSE bug 920482</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/920484">SUSE bug 920484</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927591">SUSE bug 927591</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927623">SUSE bug 927623</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936787">SUSE bug 936787</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/952088">SUSE bug 952088</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150205" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0205</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0205" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0205" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0205" ref_url="https://www.suse.com/security/cve/CVE-2015-0205" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001190.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0172-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0182-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0130-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
    <description>
    The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-0205/">CVE-2015-0205</cve>
	<bugzilla href="https://bugzilla.suse.com/912293">SUSE bug 912293</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/915848">SUSE bug 915848</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927623">SUSE bug 927623</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150206" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0206</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0206" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0206" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0206" ref_url="https://www.suse.com/security/cve/CVE-2015-0206" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-January/001202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-February/001205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0130-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-01/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
    <description>
    Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate records for the next epoch, leading to failure of replay detection.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-0206/">CVE-2015-0206</cve>
	<bugzilla href="https://bugzilla.suse.com/912292">SUSE bug 912292</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927623">SUSE bug 927623</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150209" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0209</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0209" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0209" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0209" ref_url="https://www.suse.com/security/cve/CVE-2015-0209" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="TID7016336" ref_url="https://www.suse.com/support/kb/doc/?id=7016336" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0554-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the d2i_ECPrivateKey function in crypto/ec/ec_asn1.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed Elliptic Curve (EC) private-key file that is improperly handled during import.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2015-0209/">CVE-2015-0209</cve>
	<bugzilla href="https://bugzilla.suse.com/919648">SUSE bug 919648</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936586">SUSE bug 936586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150236" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0236</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0236" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0236" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0236" ref_url="https://www.suse.com/security/cve/CVE-2015-0236" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0304-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001840.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0225-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00028.html" source="SUSE-SU"/>
    <description>
    libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-0236/">CVE-2015-0236</cve>
	<bugzilla href="https://bugzilla.suse.com/914693">SUSE bug 914693</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150245" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0245</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0245" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0245" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0245" ref_url="https://www.suse.com/security/cve/CVE-2015-0245" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0457-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0300-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2736-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00017.html" source="SUSE-SU"/>
    <description>
    D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-0245/">CVE-2015-0245</cve>
	<bugzilla href="https://bugzilla.suse.com/1003898">SUSE bug 1003898</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/916343">SUSE bug 916343</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481908" comment="dbus-1-1.12.2-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481911" comment="libdbus-1-3-1.12.2-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150247" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0247</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0247" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0247" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0247" ref_url="https://www.suse.com/security/cve/CVE-2015-0247" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1341-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-August/001524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-August/001530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1987-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004281.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1006-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2133-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00050.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.5/CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2015-0247/">CVE-2015-0247</cve>
	<bugzilla href="https://bugzilla.suse.com/1123790">SUSE bug 1123790</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/915402">SUSE bug 915402</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/918346">SUSE bug 918346</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760777" comment="e2fsprogs-1.43.8-4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760778" comment="libcom_err2-1.43.8-4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760779" comment="libext2fs2-1.43.8-4.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150274" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0274</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0274" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0274" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0274" ref_url="https://www.suse.com/security/cve/CVE-2015-0274" source="SUSE CVE"/>
    <description>
    The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leveraging XFS filesystem access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-0274/">CVE-2015-0274</cve>
	<bugzilla href="https://bugzilla.suse.com/919655">SUSE bug 919655</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150275" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0275</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0275" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0275" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0275" ref_url="https://www.suse.com/security/cve/CVE-2015-0275" source="SUSE CVE"/>
    <description>
    The ext4_zero_range function in fs/ext4/extents.c in the Linux kernel before 4.1 allows local users to cause a denial of service (BUG) via a crafted fallocate zero-range request.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-0275/">CVE-2015-0275</cve>
	<bugzilla href="https://bugzilla.suse.com/919032">SUSE bug 919032</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150286" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0286</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0286" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0286" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0286" ref_url="https://www.suse.com/security/cve/CVE-2015-0286" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001739.html" source="SUSE-SU"/>
		<reference ref_id="TID7016336" ref_url="https://www.suse.com/support/kb/doc/?id=7016336" source="SUSE-SU"/>
		<reference ref_id="TID7021977" ref_url="https://www.suse.com/support/kb/doc/?id=7021977" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0554-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2243-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The ASN1_TYPE_cmp function in crypto/asn1/a_type.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly perform boolean-type comparisons, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted X.509 certificate to an endpoint that uses the certificate-verification feature.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2015-0286/">CVE-2015-0286</cve>
	<bugzilla href="https://bugzilla.suse.com/919648">SUSE bug 919648</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/922496">SUSE bug 922496</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936586">SUSE bug 936586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951391">SUSE bug 951391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150287" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0287</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0287" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0287" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0287" ref_url="https://www.suse.com/security/cve/CVE-2015-0287" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1410-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-August/001545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="TID7016336" ref_url="https://www.suse.com/support/kb/doc/?id=7016336" source="SUSE-SU"/>
		<reference ref_id="TID7021977" ref_url="https://www.suse.com/support/kb/doc/?id=7021977" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0554-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2015-0287/">CVE-2015-0287</cve>
	<bugzilla href="https://bugzilla.suse.com/919648">SUSE bug 919648</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/922499">SUSE bug 922499</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936586">SUSE bug 936586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968888">SUSE bug 968888</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/991722">SUSE bug 991722</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150288" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0288</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0288" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0288" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0288" ref_url="https://www.suse.com/security/cve/CVE-2015-0288" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001739.html" source="SUSE-SU"/>
		<reference ref_id="TID7016336" ref_url="https://www.suse.com/support/kb/doc/?id=7016336" source="SUSE-SU"/>
		<reference ref_id="TID7021977" ref_url="https://www.suse.com/support/kb/doc/?id=7021977" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0554-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2243-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The X509_to_X509_REQ function in crypto/x509/x509_req.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow attackers to cause a denial of service (NULL pointer dereference and application crash) via an invalid certificate key.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2015-0288/">CVE-2015-0288</cve>
	<bugzilla href="https://bugzilla.suse.com/919648">SUSE bug 919648</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/920236">SUSE bug 920236</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936586">SUSE bug 936586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951391">SUSE bug 951391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150289" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0289</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0289" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0289" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0289" ref_url="https://www.suse.com/security/cve/CVE-2015-0289" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001302.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001303.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0578-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016336" ref_url="https://www.suse.com/support/kb/doc/?id=7016336" source="SUSE-SU"/>
		<reference ref_id="TID7021279" ref_url="https://www.suse.com/support/kb/doc/?id=7021279" source="SUSE-SU"/>
		<reference ref_id="TID7021518" ref_url="https://www.suse.com/support/kb/doc/?id=7021518" source="SUSE-SU"/>
		<reference ref_id="TID7021676" ref_url="https://www.suse.com/support/kb/doc/?id=7021676" source="SUSE-SU"/>
		<reference ref_id="TID7021714" ref_url="https://www.suse.com/support/kb/doc/?id=7021714" source="SUSE-SU"/>
		<reference ref_id="TID7021743" ref_url="https://www.suse.com/support/kb/doc/?id=7021743" source="SUSE-SU"/>
		<reference ref_id="TID7021744" ref_url="https://www.suse.com/support/kb/doc/?id=7021744" source="SUSE-SU"/>
		<reference ref_id="TID7021848" ref_url="https://www.suse.com/support/kb/doc/?id=7021848" source="SUSE-SU"/>
		<reference ref_id="TID7021863" ref_url="https://www.suse.com/support/kb/doc/?id=7021863" source="SUSE-SU"/>
		<reference ref_id="TID7021977" ref_url="https://www.suse.com/support/kb/doc/?id=7021977" source="SUSE-SU"/>
		<reference ref_id="TID7021993" ref_url="https://www.suse.com/support/kb/doc/?id=7021993" source="SUSE-SU"/>
		<reference ref_id="TID7021994" ref_url="https://www.suse.com/support/kb/doc/?id=7021994" source="SUSE-SU"/>
		<reference ref_id="TID7021995" ref_url="https://www.suse.com/support/kb/doc/?id=7021995" source="SUSE-SU"/>
		<reference ref_id="TID7022095" ref_url="https://www.suse.com/support/kb/doc/?id=7022095" source="SUSE-SU"/>
		<reference ref_id="TID7022096" ref_url="https://www.suse.com/support/kb/doc/?id=7022096" source="SUSE-SU"/>
		<reference ref_id="TID7022102" ref_url="https://www.suse.com/support/kb/doc/?id=7022102" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0554-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly handle a lack of outer ContentInfo, which allows attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an application that processes arbitrary PKCS#7 data and providing malformed data with ASN.1 encoding, related to crypto/pkcs7/pk7_doit.c and crypto/pkcs7/pk7_lib.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2015-0289/">CVE-2015-0289</cve>
	<bugzilla href="https://bugzilla.suse.com/919648">SUSE bug 919648</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/922500">SUSE bug 922500</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936586">SUSE bug 936586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150293" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0293</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0293" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0293" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0293" ref_url="https://www.suse.com/security/cve/CVE-2015-0293" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0545-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0546-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001302.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001303.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0553-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0578-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0617-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0620-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0621-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0624-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0631-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1057-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016336" ref_url="https://www.suse.com/support/kb/doc/?id=7016336" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0554-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0628-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0637-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0638-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0720-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html" source="SUSE-SU"/>
    <description>
    The SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (s2_lib.c assertion failure and daemon exit) via a crafted CLIENT-MASTER-KEY message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2015-0293/">CVE-2015-0293</cve>
	<bugzilla href="https://bugzilla.suse.com/919648">SUSE bug 919648</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/922488">SUSE bug 922488</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936586">SUSE bug 936586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968044">SUSE bug 968044</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968051">SUSE bug 968051</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968053">SUSE bug 968053</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986238">SUSE bug 986238</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150777" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0777</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0777" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0777" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0777" ref_url="https://www.suse.com/security/cve/CVE-2015-0777" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1174-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1376-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1478-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1592-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001611.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0713-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    drivers/xen/usbback/usbback.c in linux-2.6.18-xen-3.4.0 (aka the Xen 3.4.x support patches for the Linux kernel 2.6.18), as used in the Linux kernel 2.6.x and 3.x in SUSE Linux distributions, allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-0777/">CVE-2015-0777</cve>
	<bugzilla href="https://bugzilla.suse.com/917830">SUSE bug 917830</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150837" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0837</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0837" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0837" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0837" ref_url="https://www.suse.com/security/cve/CVE-2015-0837" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001602.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1503-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-09/msg00005.html" source="SUSE-SU"/>
    <description>
    The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2015-0837/">CVE-2015-0837</cve>
	<bugzilla href="https://bugzilla.suse.com/920057">SUSE bug 920057</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482233" comment="libgcrypt20-1.8.2-8.36.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20150840" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-0840</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-0840" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0840" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-0840" ref_url="https://www.suse.com/security/cve/CVE-2015-0840" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2015:1058-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00029.html" source="SUSE-SU"/>
    <description>
    The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-0840/">CVE-2015-0840</cve>
	<bugzilla href="https://bugzilla.suse.com/926749">SUSE bug 926749</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480953" comment="update-alternatives-1.19.0.4-2.48 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151283" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1283</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1283" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1283" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1283" ref_url="https://www.suse.com/security/cve/CVE-2015-1283" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1508-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1512-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1287-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1441-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1523-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00010.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1283/">CVE-2015-1283</cve>
	<bugzilla href="https://bugzilla.suse.com/1034050">SUSE bug 1034050</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/939077">SUSE bug 939077</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979441">SUSE bug 979441</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980391">SUSE bug 980391</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983985">SUSE bug 983985</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481944" comment="libexpat1-2.2.5-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151345" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1345</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1345" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1345" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1345" ref_url="https://www.suse.com/security/cve/CVE-2015-1345" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2015:0243-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00037.html" source="SUSE-SU"/>
    <description>
    The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-1345/">CVE-2015-1345</cve>
	<bugzilla href="https://bugzilla.suse.com/914695">SUSE bug 914695</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482006" comment="grep-3.1-4.3.12 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151420" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1420</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1420" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1420" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1420" ref_url="https://www.suse.com/security/cve/CVE-2015-1420" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1478-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1592-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2167-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001706.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1420/">CVE-2015-1420</cve>
	<bugzilla href="https://bugzilla.suse.com/915517">SUSE bug 915517</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151472" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1472</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1472" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1472" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1472" ref_url="https://www.suse.com/security/cve/CVE-2015-1472" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0439-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001304.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-March/001305.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0351-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-02/msg00089.html" source="SUSE-SU"/>
    <description>
    The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly handled in a wscanf call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1472/">CVE-2015-1472</cve>
	<bugzilla href="https://bugzilla.suse.com/916222">SUSE bug 916222</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/920341">SUSE bug 920341</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/922243">SUSE bug 922243</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151473" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1473</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1473" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1473" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1473" ref_url="https://www.suse.com/security/cve/CVE-2015-1473" source="SUSE CVE"/>
    <description>
    The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1473/">CVE-2015-1473</cve>
	<bugzilla href="https://bugzilla.suse.com/916222">SUSE bug 916222</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/920341">SUSE bug 920341</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/922243">SUSE bug 922243</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151545" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1545</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1545" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1545" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1545" ref_url="https://www.suse.com/security/cve/CVE-2015-1545" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001443.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1325-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-07/msg00069.html" source="SUSE-SU"/>
    <description>
    The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1545/">CVE-2015-1545</cve>
	<bugzilla href="https://bugzilla.suse.com/846389">SUSE bug 846389</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/916897">SUSE bug 916897</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/916914">SUSE bug 916914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151546" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1546</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1546" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1546" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1546" ref_url="https://www.suse.com/security/cve/CVE-2015-1546" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001443.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1325-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-07/msg00069.html" source="SUSE-SU"/>
    <description>
    Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1546/">CVE-2015-1546</cve>
	<bugzilla href="https://bugzilla.suse.com/916914">SUSE bug 916914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151572" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1572</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1572" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1572" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1572" ref_url="https://www.suse.com/security/cve/CVE-2015-1572" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1341-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-August/001524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-August/001530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1987-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004281.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1002-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1006-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2133-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00050.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-1572/">CVE-2015-1572</cve>
	<bugzilla href="https://bugzilla.suse.com/1123790">SUSE bug 1123790</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/915402">SUSE bug 915402</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/918346">SUSE bug 918346</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760777" comment="e2fsprogs-1.43.8-4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760778" comment="libcom_err2-1.43.8-4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760779" comment="libext2fs2-1.43.8-4.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151593" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1593</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1593" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1593" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1593" ref_url="https://www.suse.com/security/cve/CVE-2015-1593" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0713-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.html" source="SUSE-SU"/>
    <description>
    The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift operations, which makes it easier for attackers to bypass the ASLR protection mechanism by predicting the address of the top of the stack, related to the randomize_stack_top function in fs/binfmt_elf.c and the stack_maxrandom_size function in arch/x86/mm/mmap.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-11"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-1593/">CVE-2015-1593</cve>
	<bugzilla href="https://bugzilla.suse.com/1044934">SUSE bug 1044934</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/917839">SUSE bug 917839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151779" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1779</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1779" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1779" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1779" ref_url="https://www.suse.com/security/cve/CVE-2015-1779" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0870-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.6/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-1779/">CVE-2015-1779</cve>
	<bugzilla href="https://bugzilla.suse.com/924018">SUSE bug 924018</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962632">SUSE bug 962632</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151781" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1781</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1781" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1781" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1781" ref_url="https://www.suse.com/security/cve/CVE-2015-1781" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1424-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001651.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0955-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00084.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1781/">CVE-2015-1781</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927080">SUSE bug 927080</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979109">SUSE bug 979109</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151782" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1782</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1782" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1782" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1782" ref_url="https://www.suse.com/security/cve/CVE-2015-1782" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0669-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-April/001330.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-April/001334.html" source="SUSE-SU"/>
		<reference ref_id="TID7021300" ref_url="https://www.suse.com/support/kb/doc/?id=7021300" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0534-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-03/msg00057.html" source="SUSE-SU"/>
    <description>
    The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1782/">CVE-2015-1782</cve>
	<bugzilla href="https://bugzilla.suse.com/921070">SUSE bug 921070</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151788" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1788</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1788" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1788" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1788" ref_url="https://www.suse.com/security/cve/CVE-2015-1788" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1143-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1150-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1181-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1185-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="TID7016539" ref_url="https://www.suse.com/support/kb/doc/?id=7016539" source="SUSE-SU"/>
		<reference ref_id="TID7016602" ref_url="https://www.suse.com/support/kb/doc/?id=7016602" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1139-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m.c in OpenSSL before 0.9.8s, 1.0.0 before 1.0.0e, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b does not properly handle ECParameters structures in which the curve is over a malformed binary polynomial field, which allows remote attackers to cause a denial of service (infinite loop) via a session that uses an Elliptic Curve algorithm, as demonstrated by an attack against a server that supports client authentication.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1788/">CVE-2015-1788</cve>
	<bugzilla href="https://bugzilla.suse.com/934487">SUSE bug 934487</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/934666">SUSE bug 934666</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936586">SUSE bug 936586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938432">SUSE bug 938432</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151789" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1789</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1789" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1789" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1789" ref_url="https://www.suse.com/security/cve/CVE-2015-1789" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1143-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1150-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1181-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1183-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1183-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1185-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001739.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016539" ref_url="https://www.suse.com/support/kb/doc/?id=7016539" source="SUSE-SU"/>
		<reference ref_id="TID7016602" ref_url="https://www.suse.com/support/kb/doc/?id=7016602" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1139-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2243-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted length field in ASN1_TIME data, as demonstrated by an attack against a server that supports client authentication with a custom verification callback.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-1789/">CVE-2015-1789</cve>
	<bugzilla href="https://bugzilla.suse.com/934489">SUSE bug 934489</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/934666">SUSE bug 934666</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936586">SUSE bug 936586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938432">SUSE bug 938432</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951391">SUSE bug 951391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151790" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1790</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1790" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1790" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1790" ref_url="https://www.suse.com/security/cve/CVE-2015-1790" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1143-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1150-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1181-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1183-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1183-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1185-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016539" ref_url="https://www.suse.com/support/kb/doc/?id=7016539" source="SUSE-SU"/>
		<reference ref_id="TID7016602" ref_url="https://www.suse.com/support/kb/doc/?id=7016602" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1139-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PKCS#7 blob that uses ASN.1 encoding and lacks inner EncryptedContent data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1790/">CVE-2015-1790</cve>
	<bugzilla href="https://bugzilla.suse.com/934491">SUSE bug 934491</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/934666">SUSE bug 934666</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936586">SUSE bug 936586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938432">SUSE bug 938432</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151791" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1791</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1791" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1791" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1791" ref_url="https://www.suse.com/security/cve/CVE-2015-1791" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1143-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1150-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1185-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="TID7016539" ref_url="https://www.suse.com/support/kb/doc/?id=7016539" source="SUSE-SU"/>
		<reference ref_id="TID7016602" ref_url="https://www.suse.com/support/kb/doc/?id=7016602" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1139-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b, when used for a multi-threaded client, allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact by providing a NewSessionTicket during an attempt to reuse a ticket that had been obtained earlier.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1791/">CVE-2015-1791</cve>
	<bugzilla href="https://bugzilla.suse.com/933911">SUSE bug 933911</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/934666">SUSE bug 934666</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986238">SUSE bug 986238</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/989464">SUSE bug 989464</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151792" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1792</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1792" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1792" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1792" ref_url="https://www.suse.com/security/cve/CVE-2015-1792" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1143-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1150-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1185-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="TID7016539" ref_url="https://www.suse.com/support/kb/doc/?id=7016539" source="SUSE-SU"/>
		<reference ref_id="TID7016602" ref_url="https://www.suse.com/support/kb/doc/?id=7016602" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1139-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
    <description>
    The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (infinite loop) via vectors that trigger a NULL value of a BIO data structure, as demonstrated by an unrecognized X.660 OID for a hash function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1792/">CVE-2015-1792</cve>
	<bugzilla href="https://bugzilla.suse.com/934493">SUSE bug 934493</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/934666">SUSE bug 934666</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937891">SUSE bug 937891</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986238">SUSE bug 986238</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151793" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1793</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1793" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1793" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1793" ref_url="https://www.suse.com/security/cve/CVE-2015-1793" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001739.html" source="SUSE-SU"/>
		<reference ref_id="TID7016662" ref_url="https://www.suse.com/support/kb/doc/?id=7016662" source="SUSE-SU"/>
		<reference ref_id="TID7016686" ref_url="https://www.suse.com/support/kb/doc/?id=7016686" source="SUSE-SU"/>
		<reference ref_id="TID7016693" ref_url="https://www.suse.com/support/kb/doc/?id=7016693" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2243-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00009.html" source="SUSE-SU"/>
    <description>
    The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1793/">CVE-2015-1793</cve>
	<bugzilla href="https://bugzilla.suse.com/936746">SUSE bug 936746</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937637">SUSE bug 937637</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951391">SUSE bug 951391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151794" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1794</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1794" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1794" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1794" ref_url="https://www.suse.com/security/cve/CVE-2015-1794" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2016:0637-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html" source="SUSE-SU"/>
    <description>
    The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-Hellman (DH) ServerKeyExchange message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-1794/">CVE-2015-1794</cve>
	<bugzilla href="https://bugzilla.suse.com/957984">SUSE bug 957984</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151805" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1805</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1805" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1805" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1805" ref_url="https://www.suse.com/security/cve/CVE-2015-1805" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1324-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1478-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1487-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1488-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1489-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1490-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1491-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1592-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001611.html" source="SUSE-SU"/>
    <description>
    The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun."
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-12"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-1805/">CVE-2015-1805</cve>
	<bugzilla href="https://bugzilla.suse.com/917839">SUSE bug 917839</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933429">SUSE bug 933429</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/939270">SUSE bug 939270</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/964730">SUSE bug 964730</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/964732">SUSE bug 964732</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151819" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1819</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1819" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1819" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1819" ref_url="https://www.suse.com/security/cve/CVE-2015-1819" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html" source="SUSE-SU"/>
    <description>
    The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1819/">CVE-2015-1819</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928193">SUSE bug 928193</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969769">SUSE bug 969769</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151821" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1821</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1821" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1821" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1821" ref_url="https://www.suse.com/security/cve/CVE-2015-1821" source="SUSE CVE"/>
    <description>
    Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisible by four and an address with a nonzero bit in the subnet remainder.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1821/">CVE-2015-1821</cve>
	<bugzilla href="https://bugzilla.suse.com/926323">SUSE bug 926323</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009342637" comment="chrony is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348255" comment="chrony-pool-suse is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151822" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1822</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1822" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1822" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1822" ref_url="https://www.suse.com/security/cve/CVE-2015-1822" source="SUSE CVE"/>
    <description>
    chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or possibly execute arbitrary code via a large number of command requests.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-1822/">CVE-2015-1822</cve>
	<bugzilla href="https://bugzilla.suse.com/926323">SUSE bug 926323</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009342637" comment="chrony is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348255" comment="chrony-pool-suse is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151853" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1853</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1853" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1853" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1853" ref_url="https://www.suse.com/security/cve/CVE-2015-1853" source="SUSE CVE"/>
    <description>
    chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-1853/">CVE-2015-1853</cve>
	<bugzilla href="https://bugzilla.suse.com/926323">SUSE bug 926323</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009342637" comment="chrony is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348255" comment="chrony-pool-suse is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20151863" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-1863</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-1863" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1863" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-1863" ref_url="https://www.suse.com/security/cve/CVE-2015-1863" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1013-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001423.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0813-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2P entries.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-1863/">CVE-2015-1863</cve>
	<bugzilla href="https://bugzilla.suse.com/915323">SUSE bug 915323</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927558">SUSE bug 927558</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152059" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2059</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2059" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2059" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2059" ref_url="https://www.suse.com/security/cve/CVE-2015-2059" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2226-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1261-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-07/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2135-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00098.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2277-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00041.html" source="SUSE-SU"/>
    <description>
    The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-2059/">CVE-2015-2059</cve>
	<bugzilla href="https://bugzilla.suse.com/1173590">SUSE bug 1173590</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/919214">SUSE bug 919214</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/923241">SUSE bug 923241</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937096">SUSE bug 937096</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937097">SUSE bug 937097</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482248" comment="libidn11-1.34-3.2.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628747" comment="libidn2-0-2.2.0-3.6.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152296" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2296</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2296" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2296" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2296" ref_url="https://www.suse.com/security/cve/CVE-2015-2296" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-November/001704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001801.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1792-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007049.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-2296/">CVE-2015-2296</cve>
	<bugzilla href="https://bugzilla.suse.com/922448">SUSE bug 922448</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/926396">SUSE bug 926396</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482524" comment="python3-requests-2.20.1-6.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152325" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2325</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2325" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2325" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2325" ref_url="https://www.suse.com/security/cve/CVE-2015-2325" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3161-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002488.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0858-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1216-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3099-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00076.html" source="SUSE-SU"/>
    <description>
    The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-2325/">CVE-2015-2325</cve>
	<bugzilla href="https://bugzilla.suse.com/924960">SUSE bug 924960</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933288">SUSE bug 933288</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936408">SUSE bug 936408</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958373">SUSE bug 958373</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009480657" comment="libpcre1-8.41-4.20 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480667" comment="libpcre2-8-0-10.31-1.14 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152326" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2326</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2326" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2326" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2326" ref_url="https://www.suse.com/security/cve/CVE-2015-2326" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0858-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1216-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00020.html" source="SUSE-SU"/>
    <description>
    The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-2326/">CVE-2015-2326</cve>
	<bugzilla href="https://bugzilla.suse.com/924960">SUSE bug 924960</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/924961">SUSE bug 924961</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933288">SUSE bug 933288</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936408">SUSE bug 936408</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958373">SUSE bug 958373</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009480657" comment="libpcre1-8.41-4.20 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480667" comment="libpcre2-8-0-10.31-1.14 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152666" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2666</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2666" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2666" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2666" ref_url="https://www.suse.com/security/cve/CVE-2015-2666" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1071-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to the initrd.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-2666/">CVE-2015-2666</cve>
	<bugzilla href="https://bugzilla.suse.com/922944">SUSE bug 922944</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/939044">SUSE bug 939044</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152694" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2694</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2694" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2694" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2694" ref_url="https://www.suse.com/security/cve/CVE-2015-2694" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001505.html" source="SUSE-SU"/>
    <description>
    The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validated, which allows remote attackers to bypass an intended preauthentication requirement by providing (1) zero bytes of data or (2) an arbitrary realm name, related to plugins/preauth/otp/main.c and plugins/preauth/pkinit/pkinit_srv.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-2694/">CVE-2015-2694</cve>
	<bugzilla href="https://bugzilla.suse.com/928978">SUSE bug 928978</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152695" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2695</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2695" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2695" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2695" ref_url="https://www.suse.com/security/cve/CVE-2015-2695" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1897-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1898-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1898-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001737.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1928-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1997-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.html" source="SUSE-SU"/>
    <description>
    lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-2695/">CVE-2015-2695</cve>
	<bugzilla href="https://bugzilla.suse.com/770172">SUSE bug 770172</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/952188">SUSE bug 952188</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969771">SUSE bug 969771</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152696" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2696</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2696" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2696" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2696" ref_url="https://www.suse.com/security/cve/CVE-2015-2696" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1897-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1928-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1997-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.html" source="SUSE-SU"/>
    <description>
    lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mishandled during a gss_inquire_context call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-2696/">CVE-2015-2696</cve>
	<bugzilla href="https://bugzilla.suse.com/770172">SUSE bug 770172</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/952189">SUSE bug 952189</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/954204">SUSE bug 954204</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152697" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2697</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2697" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2697" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2697" ref_url="https://www.suse.com/security/cve/CVE-2015-2697" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1897-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1928-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1997-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00022.html" source="SUSE-SU"/>
    <description>
    The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-2697/">CVE-2015-2697</cve>
	<bugzilla href="https://bugzilla.suse.com/770172">SUSE bug 770172</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/952190">SUSE bug 952190</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152698" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2698</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2698" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2698" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2698" ref_url="https://www.suse.com/security/cve/CVE-2015-2698" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001738.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2055-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00116.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2376-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00124.html" source="SUSE-SU"/>
    <description>
    The iakerb_gss_export_sec_context function in lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) 1.14 pre-release 2015-09-14 improperly accesses a certain pointer, which allows remote authenticated users to cause a denial of service (memory corruption) or possibly have unspecified other impact by interacting with an application that calls the gss_export_sec_context function.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-2696.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-2698/">CVE-2015-2698</cve>
	<bugzilla href="https://bugzilla.suse.com/770172">SUSE bug 770172</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/954204">SUSE bug 954204</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152721" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2721</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2721" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2721" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2721" ref_url="https://www.suse.com/security/cve/CVE-2015-2721" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1268-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1268-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1269-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1449-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1229-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1266-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html" source="SUSE-SU"/>
    <description>
    Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2015-2721/">CVE-2015-2721</cve>
	<bugzilla href="https://bugzilla.suse.com/935979">SUSE bug 935979</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152806" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2806</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2806" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2806" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2806" ref_url="https://www.suse.com/security/cve/CVE-2015-2806" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0901-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001791.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0854-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00010.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Critical</severity>
	<cve impact="critical" href="https://www.suse.com/security/cve/CVE-2015-2806/">CVE-2015-2806</cve>
	<bugzilla href="https://bugzilla.suse.com/924828">SUSE bug 924828</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/929414">SUSE bug 929414</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961491">SUSE bug 961491</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969208">SUSE bug 969208</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482427" comment="libtasn1-4.13-4.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482428" comment="libtasn1-6-4.13-4.5.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20152924" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-2924</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-2924" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2924" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-2924" ref_url="https://www.suse.com/security/cve/CVE-2015-2924" source="SUSE CVE"/>
    <description>
    The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-2924/">CVE-2015-2924</cve>
	<bugzilla href="https://bugzilla.suse.com/926223">SUSE bug 926223</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760817" comment="libnm0-1.22.10-3.3.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760818" comment="typelib-1_0-NM-1_0-1.22.10-3.3.4 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153143" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3143</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3143" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3143" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3143" ref_url="https://www.suse.com/security/cve/CVE-2015-3143" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0990-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001421.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-04/msg00057.html" source="SUSE-SU"/>
    <description>
    cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3143/">CVE-2015-3143</cve>
	<bugzilla href="https://bugzilla.suse.com/927556">SUSE bug 927556</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153144" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3144</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3144" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3144" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3144" ref_url="https://www.suse.com/security/cve/CVE-2015-3144" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0990-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001421.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-04/msg00057.html" source="SUSE-SU"/>
    <description>
    The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-3144/">CVE-2015-3144</cve>
	<bugzilla href="https://bugzilla.suse.com/927608">SUSE bug 927608</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951391">SUSE bug 951391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153145" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3145</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3145" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3145" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3145" ref_url="https://www.suse.com/security/cve/CVE-2015-3145" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0990-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001421.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-04/msg00057.html" source="SUSE-SU"/>
    <description>
    The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-3145/">CVE-2015-3145</cve>
	<bugzilla href="https://bugzilla.suse.com/927607">SUSE bug 927607</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153146" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3146</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3146" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3146" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3146" ref_url="https://www.suse.com/security/cve/CVE-2015-3146" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1707-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1707-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001624.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0860-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00016.html" source="SUSE-SU"/>
    <description>
    The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted SSH packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3146/">CVE-2015-3146</cve>
	<bugzilla href="https://bugzilla.suse.com/928323">SUSE bug 928323</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482409" comment="libssh4-0.8.7-10.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153148" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3148</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3148" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3148" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3148" ref_url="https://www.suse.com/security/cve/CVE-2015-3148" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0990-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001421.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0799-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-04/msg00057.html" source="SUSE-SU"/>
    <description>
    cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3148/">CVE-2015-3148</cve>
	<bugzilla href="https://bugzilla.suse.com/1092962">SUSE bug 1092962</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927746">SUSE bug 927746</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153153" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3153</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3153" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3153" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3153" ref_url="https://www.suse.com/security/cve/CVE-2015-3153" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-May/001414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0990-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001421.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0861-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00017.html" source="SUSE-SU"/>
    <description>
    The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3153/">CVE-2015-3153</cve>
	<bugzilla href="https://bugzilla.suse.com/928533">SUSE bug 928533</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951391">SUSE bug 951391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153193" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3193</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3193" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3193" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3193" ref_url="https://www.suse.com/security/cve/CVE-2015-3193" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
    <description>
    The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote attackers to obtain sensitive private-key information via an attack against use of a (1) Diffie-Hellman (DH) or (2) Diffie-Hellman Ephemeral (DHE) ciphersuite.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2015-3193/">CVE-2015-3193</cve>
	<bugzilla href="https://bugzilla.suse.com/1022086">SUSE bug 1022086</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1066242">SUSE bug 1066242</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1071906">SUSE bug 1071906</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957814">SUSE bug 957814</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960151">SUSE bug 960151</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990370">SUSE bug 990370</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153194" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3194</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3194" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3194" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3194" ref_url="https://www.suse.com/security/cve/CVE-2015-3194" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2253-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="TID7017046" ref_url="https://www.suse.com/support/kb/doc/?id=7017046" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2288-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2289-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2318-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0637-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1327-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-05/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1332-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html" source="SUSE-SU"/>
    <description>
    crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-3194/">CVE-2015-3194</cve>
	<bugzilla href="https://bugzilla.suse.com/957812">SUSE bug 957812</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957815">SUSE bug 957815</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958768">SUSE bug 958768</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/976341">SUSE bug 976341</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990370">SUSE bug 990370</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153195" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3195</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3195" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3195" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3195" ref_url="https://www.suse.com/security/cve/CVE-2015-3195" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2251-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001730.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2253-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001758.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7014420" ref_url="https://www.suse.com/support/kb/doc/?id=7014420" source="SUSE-SU"/>
		<reference ref_id="TID7016875" ref_url="https://www.suse.com/support/kb/doc/?id=7016875" source="SUSE-SU"/>
		<reference ref_id="TID7017047" ref_url="https://www.suse.com/support/kb/doc/?id=7017047" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2288-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2289-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2318-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2349-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00103.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0637-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1327-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-05/msg00073.html" source="SUSE-SU"/>
    <description>
    The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2015-3195/">CVE-2015-3195</cve>
	<bugzilla href="https://bugzilla.suse.com/923755">SUSE bug 923755</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957812">SUSE bug 957812</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957815">SUSE bug 957815</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958768">SUSE bug 958768</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963977">SUSE bug 963977</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986238">SUSE bug 986238</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153196" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3196</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3196" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3196" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3196" ref_url="https://www.suse.com/security/cve/CVE-2015-3196" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2253-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2288-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2289-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00071.html" source="SUSE-SU"/>
    <description>
    ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3196/">CVE-2015-3196</cve>
	<bugzilla href="https://bugzilla.suse.com/957813">SUSE bug 957813</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153197" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3197</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3197" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3197" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3197" ref_url="https://www.suse.com/security/cve/CVE-2015-3197" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0617-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0620-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0621-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0624-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0631-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1057-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7017297" ref_url="https://www.suse.com/support/kb/doc?id=7017297" source="SUSE-SU"/>
		<reference ref_id="TID7017315" ref_url="https://www.suse.com/support/kb/doc/?id=7017315" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0362-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0442-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00082.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0628-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0637-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0720-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1239-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html" source="SUSE-SU"/>
    <description>
    ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2015-3197/">CVE-2015-3197</cve>
	<bugzilla href="https://bugzilla.suse.com/963410">SUSE bug 963410</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963415">SUSE bug 963415</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968044">SUSE bug 968044</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968046">SUSE bug 968046</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153202" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3202</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3202" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3202" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3202" ref_url="https://www.suse.com/security/cve/CVE-2015-3202" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1024-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001438.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0997-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1003-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00007.html" source="SUSE-SU"/>
    <description>
    fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3202/">CVE-2015-3202</cve>
	<bugzilla href="https://bugzilla.suse.com/931452">SUSE bug 931452</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481128" comment="fuse-2.9.7-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481131" comment="libfuse2-2.9.7-3.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153209" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3209</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3209" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3209" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3209" ref_url="https://www.suse.com/security/cve/CVE-2015-3209" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1042-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1045-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1152-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1157-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1426-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1519-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1643-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="TID7016590" ref_url="https://www.suse.com/support/kb/doc?id=7016590" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1092-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1094-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00017.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-3209/">CVE-2015-3209</cve>
	<bugzilla href="https://bugzilla.suse.com/932267">SUSE bug 932267</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/932770">SUSE bug 932770</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/932823">SUSE bug 932823</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153217" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3217</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3217" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3217" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3217" ref_url="https://www.suse.com/security/cve/CVE-2015-3217" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3161-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002488.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2805-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3099-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00076.html" source="SUSE-SU"/>
    <description>
    PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3217/">CVE-2015-3217</cve>
	<bugzilla href="https://bugzilla.suse.com/933878">SUSE bug 933878</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958373">SUSE bug 958373</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009480657" comment="libpcre1-8.41-4.20 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009654598" comment="libpcre2-8-0 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153218" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3218</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3218" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3218" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3218" ref_url="https://www.suse.com/security/cve/CVE-2015-3218" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001649.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1734-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00042.html" source="SUSE-SU"/>
    <description>
    The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (NULL pointer dereference and polkitd daemon crash) by calling RegisterAuthenticationAgent with an invalid object path.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3218/">CVE-2015-3218</cve>
	<bugzilla href="https://bugzilla.suse.com/933922">SUSE bug 933922</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/943816">SUSE bug 943816</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482356" comment="libpolkit0-0.116-1.51 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482357" comment="polkit-0.116-1.51 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153236" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3236</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3236" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3236" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3236" ref_url="https://www.suse.com/security/cve/CVE-2015-3236" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2015:1135-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00054.html" source="SUSE-SU"/>
    <description>
    cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3236/">CVE-2015-3236</cve>
	<bugzilla href="https://bugzilla.suse.com/934501">SUSE bug 934501</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951391">SUSE bug 951391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153237" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3237</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3237" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3237" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3237" ref_url="https://www.suse.com/security/cve/CVE-2015-3237" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2015:1135-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00054.html" source="SUSE-SU"/>
    <description>
    The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3237/">CVE-2015-3237</cve>
	<bugzilla href="https://bugzilla.suse.com/934502">SUSE bug 934502</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153238" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3238</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3238" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3238" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3238" ref_url="https://www.suse.com/security/cve/CVE-2015-3238" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1645-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1398-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
    <description>
    The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2015-3238/">CVE-2015-3238</cve>
	<bugzilla href="https://bugzilla.suse.com/1123794">SUSE bug 1123794</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/934920">SUSE bug 934920</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628960" comment="pam-1.3.0-6.29.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153239" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3239</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3239" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3239" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3239" ref_url="https://www.suse.com/security/cve/CVE-2015-3239" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005095.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1245-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-07/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1245-2" ref_url="https://lists.opensuse.org/opensuse-updates/2015-07/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0061-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00022.html" source="SUSE-SU"/>
    <description>
    Off-by-one error in the dwarf_to_unw_regnum function in include/dwarf_i.h in libunwind 1.1 allows local users to have unspecified impact via invalid dwarf opcodes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2015-3239/">CVE-2015-3239</cve>
	<bugzilla href="https://bugzilla.suse.com/1122012">SUSE bug 1122012</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936786">SUSE bug 936786</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760834" comment="libunwind-1.2.1-4.2.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153247" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3247</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3247" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3247" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3247" ref_url="https://www.suse.com/security/cve/CVE-2015-3247" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1259-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-May/002048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1566-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-09/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1750-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-10/msg00032.html" source="SUSE-SU"/>
    <description>
    Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-3247/">CVE-2015-3247</cve>
	<bugzilla href="https://bugzilla.suse.com/944460">SUSE bug 944460</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153255" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3255</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3255" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3255" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3255" ref_url="https://www.suse.com/security/cve/CVE-2015-3255" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001649.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1734-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00042.html" source="SUSE-SU"/>
    <description>
    The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in action descriptions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3255/">CVE-2015-3255</cve>
	<bugzilla href="https://bugzilla.suse.com/939246">SUSE bug 939246</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/943816">SUSE bug 943816</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482356" comment="libpolkit0-0.116-1.51 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482357" comment="polkit-0.116-1.51 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153256" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3256</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3256" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3256" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3256" ref_url="https://www.suse.com/security/cve/CVE-2015-3256" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001649.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1734-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00042.html" source="SUSE-SU"/>
    <description>
    PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (memory corruption and polkitd daemon crash) and possibly gain privileges via unspecified vectors, related to "javascript rule evaluation."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3256/">CVE-2015-3256</cve>
	<bugzilla href="https://bugzilla.suse.com/943816">SUSE bug 943816</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482356" comment="libpolkit0-0.116-1.51 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482357" comment="polkit-0.116-1.51 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153259" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3259</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3259" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3259" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3259" ref_url="https://www.suse.com/security/cve/CVE-2015-3259" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1299-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1302-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1479-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1479-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2249-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00052.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long configuration argument.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3259/">CVE-2015-3259</cve>
	<bugzilla href="https://bugzilla.suse.com/935634">SUSE bug 935634</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/936281">SUSE bug 936281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937018">SUSE bug 937018</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950367">SUSE bug 950367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153288" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3288</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3288" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3288" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3288" ref_url="https://www.suse.com/security/cve/CVE-2015-3288" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1613-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
    <description>
    mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (page tainting) via a crafted application that triggers writing to page zero.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-3288/">CVE-2015-3288</cve>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979021">SUSE bug 979021</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153290" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3290</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3290" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3290" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3290" ref_url="https://www.suse.com/security/cve/CVE-2015-3290" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2015:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1842-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00024.html" source="SUSE-SU"/>
    <description>
    arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during nested NMI processing, which allows local users to gain privileges by triggering an NMI within a certain instruction window.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-3290/">CVE-2015-3290</cve>
	<bugzilla href="https://bugzilla.suse.com/937969">SUSE bug 937969</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937970">SUSE bug 937970</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938706">SUSE bug 938706</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/939207">SUSE bug 939207</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/939269">SUSE bug 939269</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153291" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3291</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3291" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3291" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3291" ref_url="https://www.suse.com/security/cve/CVE-2015-3291" source="SUSE CVE"/>
    <description>
    arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform does not properly determine when nested NMI processing is occurring, which allows local users to cause a denial of service (skipped NMI) by modifying the rsp register, issuing a syscall instruction, and triggering an NMI.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2015-3291/">CVE-2015-3291</cve>
	<bugzilla href="https://bugzilla.suse.com/937969">SUSE bug 937969</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937970">SUSE bug 937970</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938706">SUSE bug 938706</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153331" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3331</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3331" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3331" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3331" ref_url="https://www.suse.com/security/cve/CVE-2015-3331" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1071-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1174-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1376-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1478-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1487-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1488-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1489-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1491-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.html" source="SUSE-SU"/>
    <description>
    The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attackers to cause a denial of service (buffer overflow and system crash) or possibly execute arbitrary code by triggering a crypto API call, as demonstrated by use of a libkcapi test program with an AF_ALG(aead) socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3331/">CVE-2015-3331</cve>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/927257">SUSE bug 927257</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/931231">SUSE bug 931231</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/939262">SUSE bug 939262</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153340" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3340</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3340" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3340" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3340" ref_url="https://www.suse.com/security/cve/CVE-2015-3340" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0923-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0940-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0944-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0983-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1092-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00016.html" source="SUSE-SU"/>
    <description>
    Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-3340/">CVE-2015-3340</cve>
	<bugzilla href="https://bugzilla.suse.com/927967">SUSE bug 927967</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/929339">SUSE bug 929339</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153414" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3414</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3414" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3414" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3414" ref_url="https://www.suse.com/security/cve/CVE-2015-3414" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-3414/">CVE-2015-3414</cve>
	<bugzilla href="https://bugzilla.suse.com/1085790">SUSE bug 1085790</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190372">SUSE bug 1190372</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193078">SUSE bug 1193078</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928700">SUSE bug 928700</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928701">SUSE bug 928701</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928702">SUSE bug 928702</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153415" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3415</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3415" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3415" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3415" ref_url="https://www.suse.com/security/cve/CVE-2015-3415" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&amp;O&gt;O) in a CREATE TABLE statement.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-3415/">CVE-2015-3415</cve>
	<bugzilla href="https://bugzilla.suse.com/1190372">SUSE bug 1190372</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928700">SUSE bug 928700</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928701">SUSE bug 928701</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928702">SUSE bug 928702</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153416" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3416</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3416" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3416" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3416" ref_url="https://www.suse.com/security/cve/CVE-2015-3416" source="SUSE CVE"/>
    <description>
    The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-3416/">CVE-2015-3416</cve>
	<bugzilla href="https://bugzilla.suse.com/1190372">SUSE bug 1190372</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928700">SUSE bug 928700</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928701">SUSE bug 928701</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928702">SUSE bug 928702</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335190" comment="libsqlite3-0 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153456" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3456</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3456" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3456" ref_url="https://www.suse.com/security/cve/CVE-2015-3456" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0889-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0889-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0923-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0927-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0929-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0940-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0943-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:0944-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="TID7016497" ref_url="https://www.suse.com/support/kb/doc?id=7016497" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0893-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0894-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0983-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1092-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1400-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-08/msg00021.html" source="SUSE-SU"/>
    <description>
    The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3456/">CVE-2015-3456</cve>
	<bugzilla href="https://bugzilla.suse.com/929339">SUSE bug 929339</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/932770">SUSE bug 932770</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/935900">SUSE bug 935900</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153622" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3622</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3622" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3622" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3622" ref_url="https://www.suse.com/security/cve/CVE-2015-3622" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1518-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-08/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1567-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1674-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00097.html" source="SUSE-SU"/>
    <description>
    The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-3622/">CVE-2015-3622</cve>
	<bugzilla href="https://bugzilla.suse.com/929414">SUSE bug 929414</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482427" comment="libtasn1-4.13-4.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482428" comment="libtasn1-6-4.13-4.5.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153627" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3627</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3627" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3627" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3627" ref_url="https://www.suse.com/security/cve/CVE-2015-3627" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0905-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00023.html" source="SUSE-SU"/>
    <description>
    Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-3627/">CVE-2015-3627</cve>
	<bugzilla href="https://bugzilla.suse.com/930235">SUSE bug 930235</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/945060">SUSE bug 945060</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153629" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3629</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3629" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3629" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3629" ref_url="https://www.suse.com/security/cve/CVE-2015-3629" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0905-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00023.html" source="SUSE-SU"/>
    <description>
    Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-24"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-3629/">CVE-2015-3629</cve>
	<bugzilla href="https://bugzilla.suse.com/930235">SUSE bug 930235</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/945060">SUSE bug 945060</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153630" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3630</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3630" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3630" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3630" ref_url="https://www.suse.com/security/cve/CVE-2015-3630" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0905-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00023.html" source="SUSE-SU"/>
    <description>
    Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-3630/">CVE-2015-3630</cve>
	<bugzilla href="https://bugzilla.suse.com/930235">SUSE bug 930235</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/945060">SUSE bug 945060</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153631" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3631</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3631" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3631" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3631" ref_url="https://www.suse.com/security/cve/CVE-2015-3631" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:0984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-June/001419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:0905-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-05/msg00023.html" source="SUSE-SU"/>
    <description>
    Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-3631/">CVE-2015-3631</cve>
	<bugzilla href="https://bugzilla.suse.com/930235">SUSE bug 930235</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/945060">SUSE bug 945060</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20153636" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-3636</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-3636" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3636" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-3636" ref_url="https://www.suse.com/security/cve/CVE-2015-3636" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1071-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1174-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-July/001471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1376-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1478-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1487-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1488-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1489-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1491-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) by leveraging the ability to make a SOCK_DGRAM socket system call for the IPPROTO_ICMP or IPPROTO_ICMPV6 protocol, and then making a connect system call after a disconnect.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-3636/">CVE-2015-3636</cve>
	<bugzilla href="https://bugzilla.suse.com/929525">SUSE bug 929525</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/939277">SUSE bug 939277</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994624">SUSE bug 994624</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154000" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4000</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4000" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4000" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4000" ref_url="https://www.suse.com/security/cve/CVE-2015-4000" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1143-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1150-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1177-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1177-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1181-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1182-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1183-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1183-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1184-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1185-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1268-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1268-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1269-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1320-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1329-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1331-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1345-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1375-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1449-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1509-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1547-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1581-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1663-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1840-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0224-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0262-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1618-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0586-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013955.html" source="SUSE-SU"/>
		<reference ref_id="TID7010166" ref_url="https://www.suse.com/support/kb/doc/?id=7010166" source="SUSE-SU"/>
		<reference ref_id="TID7016528" ref_url="https://www.suse.com/support/kb/doc/?id=7016528" source="SUSE-SU"/>
		<reference ref_id="TID7016529" ref_url="https://www.suse.com/support/kb/doc?id=7016529" source="SUSE-SU"/>
		<reference ref_id="TID7016539" ref_url="https://www.suse.com/support/kb/doc/?id=7016539" source="SUSE-SU"/>
		<reference ref_id="TID7016657" ref_url="https://www.suse.com/support/kb/doc/?id=7016657" source="SUSE-SU"/>
		<reference ref_id="TID7016694" ref_url="https://www.suse.com/support/kb/doc/?id=7016694" source="SUSE-SU"/>
		<reference ref_id="TID7016726" ref_url="https://www.suse.com/support/kb/doc/?id=7016726" source="SUSE-SU"/>
		<reference ref_id="TID7016795" ref_url="https://www.suse.com/support/kb/doc/?id=7016795" source="SUSE-SU"/>
		<reference ref_id="TID7021279" ref_url="https://www.suse.com/support/kb/doc/?id=7021279" source="SUSE-SU"/>
		<reference ref_id="TID7021300" ref_url="https://www.suse.com/support/kb/doc/?id=7021300" source="SUSE-SU"/>
		<reference ref_id="TID7021433" ref_url="https://www.suse.com/support/kb/doc/?id=7021433" source="SUSE-SU"/>
		<reference ref_id="TID7021435" ref_url="https://www.suse.com/support/kb/doc/?id=7021435" source="SUSE-SU"/>
		<reference ref_id="TID7021518" ref_url="https://www.suse.com/support/kb/doc/?id=7021518" source="SUSE-SU"/>
		<reference ref_id="TID7021676" ref_url="https://www.suse.com/support/kb/doc/?id=7021676" source="SUSE-SU"/>
		<reference ref_id="TID7021743" ref_url="https://www.suse.com/support/kb/doc/?id=7021743" source="SUSE-SU"/>
		<reference ref_id="TID7021744" ref_url="https://www.suse.com/support/kb/doc/?id=7021744" source="SUSE-SU"/>
		<reference ref_id="TID7021823" ref_url="https://www.suse.com/support/kb/doc/?id=7021823" source="SUSE-SU"/>
		<reference ref_id="TID7021836" ref_url="https://www.suse.com/support/kb/doc/?id=7021836" source="SUSE-SU"/>
		<reference ref_id="TID7021848" ref_url="https://www.suse.com/support/kb/doc/?id=7021848" source="SUSE-SU"/>
		<reference ref_id="TID7021978" ref_url="https://www.suse.com/support/kb/doc/?id=7021978" source="SUSE-SU"/>
		<reference ref_id="TID7021993" ref_url="https://www.suse.com/support/kb/doc/?id=7021993" source="SUSE-SU"/>
		<reference ref_id="TID7021994" ref_url="https://www.suse.com/support/kb/doc/?id=7021994" source="SUSE-SU"/>
		<reference ref_id="TID7021995" ref_url="https://www.suse.com/support/kb/doc/?id=7021995" source="SUSE-SU"/>
		<reference ref_id="TID7022026" ref_url="https://www.suse.com/support/kb/doc/?id=7022026" source="SUSE-SU"/>
		<reference ref_id="TID7022077" ref_url="https://www.suse.com/support/kb/doc/?id=7022077" source="SUSE-SU"/>
		<reference ref_id="TID7022095" ref_url="https://www.suse.com/support/kb/doc/?id=7022095" source="SUSE-SU"/>
		<reference ref_id="TID7022096" ref_url="https://www.suse.com/support/kb/doc/?id=7022096" source="SUSE-SU"/>
		<reference ref_id="TID7022102" ref_url="https://www.suse.com/support/kb/doc/?id=7022102" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1139-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1209-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1216-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1229-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1266-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1277-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1288-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1289-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1684-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0255-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0261-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0478-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0483-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00097.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2267-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00034.html" source="SUSE-SU"/>
    <description>
    The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-03"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2015-4000/">CVE-2015-4000</cve>
	<bugzilla href="https://bugzilla.suse.com/1074631">SUSE bug 1074631</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1211968">SUSE bug 1211968</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/931600">SUSE bug 931600</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/931698">SUSE bug 931698</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/931723">SUSE bug 931723</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/931845">SUSE bug 931845</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/932026">SUSE bug 932026</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/932483">SUSE bug 932483</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/934789">SUSE bug 934789</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/935033">SUSE bug 935033</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/935540">SUSE bug 935540</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/935979">SUSE bug 935979</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937202">SUSE bug 937202</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937766">SUSE bug 937766</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938248">SUSE bug 938248</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938432">SUSE bug 938432</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938895">SUSE bug 938895</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938905">SUSE bug 938905</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938906">SUSE bug 938906</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938913">SUSE bug 938913</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938945">SUSE bug 938945</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/943664">SUSE bug 943664</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/944729">SUSE bug 944729</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/945582">SUSE bug 945582</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/955589">SUSE bug 955589</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980406">SUSE bug 980406</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990592">SUSE bug 990592</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994144">SUSE bug 994144</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154037" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4037</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4037" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4037" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4037" ref_url="https://www.suse.com/security/cve/CVE-2015-4037" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1519-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1894-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1952-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="TID7016590" ref_url="https://www.suse.com/support/kb/doc?id=7016590" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1965-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
    <description>
    The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-4037/">CVE-2015-4037</cve>
	<bugzilla href="https://bugzilla.suse.com/932267">SUSE bug 932267</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950367">SUSE bug 950367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154041" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4041</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4041" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4041" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4041" ref_url="https://www.suse.com/security/cve/CVE-2015-4041" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001604.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1059-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00030.html" source="SUSE-SU"/>
    <description>
    The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via long UTF-8 strings.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-4041/">CVE-2015-4041</cve>
	<bugzilla href="https://bugzilla.suse.com/928749">SUSE bug 928749</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480143" comment="coreutils-8.29-2.12 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154042" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4042</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4042" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4042" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4042" ref_url="https://www.suse.com/security/cve/CVE-2015-4042" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001604.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1059-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00030.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-4042/">CVE-2015-4042</cve>
	<bugzilla href="https://bugzilla.suse.com/1167100">SUSE bug 1167100</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/928749">SUSE bug 928749</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480143" comment="coreutils-8.29-2.12 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154103" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4103</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4103" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4103" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4103" ref_url="https://www.suse.com/security/cve/CVE-2015-4103" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1042-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1045-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1157-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="TID7016590" ref_url="https://www.suse.com/support/kb/doc?id=7016590" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1092-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1094-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00017.html" source="SUSE-SU"/>
    <description>
    Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest administrators to cause a denial of service (host interrupt handling confusion) via vectors related to qemu and accessing spanning multiple fields.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-4103/">CVE-2015-4103</cve>
	<bugzilla href="https://bugzilla.suse.com/931625">SUSE bug 931625</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154104" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4104</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4104" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4104" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4104" ref_url="https://www.suse.com/security/cve/CVE-2015-4104" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1042-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1045-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1157-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="TID7016590" ref_url="https://www.suse.com/support/kb/doc?id=7016590" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1092-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1094-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00017.html" source="SUSE-SU"/>
    <description>
    Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected interrupt and host crash) via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-4104/">CVE-2015-4104</cve>
	<bugzilla href="https://bugzilla.suse.com/931626">SUSE bug 931626</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154105" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4105</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4105" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4105" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4105" ref_url="https://www.suse.com/security/cve/CVE-2015-4105" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1042-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1045-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1157-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="TID7016590" ref_url="https://www.suse.com/support/kb/doc?id=7016590" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1092-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1094-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00017.html" source="SUSE-SU"/>
    <description>
    Xen 3.3.x through 4.5.x enables logging for PCI MSI-X pass-through error messages, which allows local x86 HVM guests to cause a denial of service (host disk consumption) via certain invalid operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-4105/">CVE-2015-4105</cve>
	<bugzilla href="https://bugzilla.suse.com/931627">SUSE bug 931627</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154106" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4106</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4106" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4106" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4106" ref_url="https://www.suse.com/security/cve/CVE-2015-4106" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1042-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1045-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1157-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="TID7016590" ref_url="https://www.suse.com/support/kb/doc?id=7016590" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1092-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1094-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2249-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00052.html" source="SUSE-SU"/>
    <description>
    QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-4106/">CVE-2015-4106</cve>
	<bugzilla href="https://bugzilla.suse.com/931628">SUSE bug 931628</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154141" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4141</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4141" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4141" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4141" ref_url="https://www.suse.com/security/cve/CVE-2015-4141" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001725.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1030-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2357-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-4141/">CVE-2015-4141</cve>
	<bugzilla href="https://bugzilla.suse.com/915323">SUSE bug 915323</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/930077">SUSE bug 930077</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154142" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4142</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4142" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4142" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4142" ref_url="https://www.suse.com/security/cve/CVE-2015-4142" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001725.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1030-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2357-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-4142/">CVE-2015-4142</cve>
	<bugzilla href="https://bugzilla.suse.com/915323">SUSE bug 915323</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/930078">SUSE bug 930078</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154143" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4143</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4143" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4143" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4143" ref_url="https://www.suse.com/security/cve/CVE-2015-4143" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1030-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-06/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2357-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) Commit or (2) Confirm message payload.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-4143/">CVE-2015-4143</cve>
	<bugzilla href="https://bugzilla.suse.com/930079">SUSE bug 930079</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154144" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4144</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4144" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4144" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4144" ref_url="https://www.suse.com/security/cve/CVE-2015-4144" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
    <description>
    The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a message is long enough to contain the Total-Length field, which allows remote attackers to cause a denial of service (crash) via a crafted message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-4144/">CVE-2015-4144</cve>
	<bugzilla href="https://bugzilla.suse.com/930079">SUSE bug 930079</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154145" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4145</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4145" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4145" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4145" ref_url="https://www.suse.com/security/cve/CVE-2015-4145" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
    <description>
    The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate a fragment is already being processed, which allows remote attackers to cause a denial of service (memory leak) via a crafted message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-4145/">CVE-2015-4145</cve>
	<bugzilla href="https://bugzilla.suse.com/930079">SUSE bug 930079</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154146" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4146</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4146" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4146" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4146" ref_url="https://www.suse.com/security/cve/CVE-2015-4146" source="SUSE CVE"/>
    <description>
    The EAP-pwd peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not clear the L (Length) and M (More) flags before determining if a response should be fragmented, which allows remote attackers to cause a denial of service (crash) via a crafted message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-4146/">CVE-2015-4146</cve>
	<bugzilla href="https://bugzilla.suse.com/930079">SUSE bug 930079</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154167" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4167</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4167" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4167" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4167" ref_url="https://www.suse.com/security/cve/CVE-2015-4167" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1324-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1592-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001611.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a denial of service (incorrect data representation or integer overflow, and OOPS) via a crafted UDF filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-4167/">CVE-2015-4167</cve>
	<bugzilla href="https://bugzilla.suse.com/917839">SUSE bug 917839</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/933907">SUSE bug 933907</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154625" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4625</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4625" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4625" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4625" ref_url="https://www.suse.com/security/cve/CVE-2015-4625" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001649.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1734-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1927-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00042.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-4625/">CVE-2015-4625</cve>
	<bugzilla href="https://bugzilla.suse.com/935119">SUSE bug 935119</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/943816">SUSE bug 943816</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482356" comment="libpolkit0-0.116-1.51 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482357" comment="polkit-0.116-1.51 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20154692" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-4692</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-4692" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4692" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-4692" ref_url="https://www.suse.com/security/cve/CVE-2015-4692" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1324-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
    <description>
    The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-16"/>
	<updated date="2023-02-16"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-4692/">CVE-2015-4692</cve>
	<bugzilla href="https://bugzilla.suse.com/935542">SUSE bug 935542</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155154" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5154</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5154" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5154" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5154" ref_url="https://www.suse.com/security/cve/CVE-2015-5154" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1299-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1302-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-07/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-August/001543.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1409-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1421-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1426-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1455-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1472-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1479-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1479-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1643-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1782-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2249-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00052.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-5154/">CVE-2015-5154</cve>
	<bugzilla href="https://bugzilla.suse.com/938344">SUSE bug 938344</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950367">SUSE bug 950367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155156" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5156</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5156" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5156" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5156" ref_url="https://www.suse.com/security/cve/CVE-2015-5156" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1727-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2292-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1080-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1172-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004055.html" source="SUSE-SU"/>
    <description>
    The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-5156/">CVE-2015-5156</cve>
	<bugzilla href="https://bugzilla.suse.com/1091815">SUSE bug 1091815</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123903">SUSE bug 1123903</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/940776">SUSE bug 940776</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/945048">SUSE bug 945048</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951638">SUSE bug 951638</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155157" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5157</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5157" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5157" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5157" ref_url="https://www.suse.com/security/cve/CVE-2015-5157" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1727-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2108-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2350-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0354-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00005.html" source="SUSE-SU"/>
    <description>
    arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by triggering an NMI.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-5157/">CVE-2015-5157</cve>
	<bugzilla href="https://bugzilla.suse.com/1072204">SUSE bug 1072204</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937969">SUSE bug 937969</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/937970">SUSE bug 937970</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/938706">SUSE bug 938706</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/939207">SUSE bug 939207</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155165" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5165</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5165" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5165" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5165" ref_url="https://www.suse.com/security/cve/CVE-2015-5165" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1384-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-August/001541.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1404-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-August/001542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-August/001543.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1421-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-08/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1479-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1479-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1643-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
    <description>
    The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2015-5165/">CVE-2015-5165</cve>
	<bugzilla href="https://bugzilla.suse.com/939712">SUSE bug 939712</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950367">SUSE bug 950367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155180" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5180</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5180" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5180" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5180" ref_url="https://www.suse.com/security/cve/CVE-2015-5180" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2883-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2886-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011984.html" source="SUSE-SU"/>
    <description>
    res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-22"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-5180/">CVE-2015-5180</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1215582">SUSE bug 1215582</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/941234">SUSE bug 941234</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155186" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5186</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5186" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5186" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5186" ref_url="https://www.suse.com/security/cve/CVE-2015-5186" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0563-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190563-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005428.html" source="SUSE-SU"/>
    <description>
    Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-5186/">CVE-2015-5186</cve>
	<bugzilla href="https://bugzilla.suse.com/941922">SUSE bug 941922</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760804" comment="libaudit1-2.8.1-12.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760805" comment="libauparse0-2.8.1-12.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155191" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5191</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5191" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5191" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5191" ref_url="https://www.suse.com/security/cve/CVE-2015-5191" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0701-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002696.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0705-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002699.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0509-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00088.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0827-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-03/msg00092.html" source="SUSE-SU"/>
    <description>
    VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-5191/">CVE-2015-5191</cve>
	<bugzilla href="https://bugzilla.suse.com/1007600">SUSE bug 1007600</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760836" comment="libvmtools0-11.2.5-4.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760837" comment="open-vm-tools-11.2.5-4.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155218" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5218</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5218" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5218" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5218" ref_url="https://www.suse.com/security/cve/CVE-2015-5218" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14693-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008640.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1910-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00035.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of service (crash) via a crafted file, related to the page global variable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-5218/">CVE-2015-5218</cve>
	<bugzilla href="https://bugzilla.suse.com/949754">SUSE bug 949754</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760806" comment="libblkid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760807" comment="libfdisk1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760808" comment="libmount1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760809" comment="libsmartcols1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760810" comment="libuuid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760811" comment="util-linux-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760812" comment="util-linux-systemd-2.33.1-4.13.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155225" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5225</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5225" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5225" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5225" ref_url="https://www.suse.com/security/cve/CVE-2015-5225" source="SUSE CVE"/>
    <description>
    Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-5225/">CVE-2015-5225</cve>
	<bugzilla href="https://bugzilla.suse.com/942845">SUSE bug 942845</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155239" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5239</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5239" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5239" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5239" ref_url="https://www.suse.com/security/cve/CVE-2015-5239" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1894-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1952-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2249-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-5239/">CVE-2015-5239</cve>
	<bugzilla href="https://bugzilla.suse.com/944463">SUSE bug 944463</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950367">SUSE bug 950367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155245" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5245</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5245" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5245" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5245" ref_url="https://www.suse.com/security/cve/CVE-2015-5245" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-March/001952.html" source="SUSE-SU"/>
    <description>
    CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-5245/">CVE-2015-5245</cve>
	<bugzilla href="https://bugzilla.suse.com/945206">SUSE bug 945206</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009335684" comment="librados2 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335686" comment="librbd1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155247" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5247</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5247" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5247" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5247" ref_url="https://www.suse.com/security/cve/CVE-2015-5247" source="SUSE CVE"/>
    <description>
    The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-5247/">CVE-2015-5247</cve>
	<bugzilla href="https://bugzilla.suse.com/945645">SUSE bug 945645</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155260" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5260</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5260" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5260" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5260" ref_url="https://www.suse.com/security/cve/CVE-2015-5260" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1259-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-May/002048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002108.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1750-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-10/msg00032.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-5260/">CVE-2015-5260</cve>
	<bugzilla href="https://bugzilla.suse.com/944787">SUSE bug 944787</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155261" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5261</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5261" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5261" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5261" ref_url="https://www.suse.com/security/cve/CVE-2015-5261" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1259-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-May/002048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002108.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1750-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-10/msg00032.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2015-5261/">CVE-2015-5261</cve>
	<bugzilla href="https://bugzilla.suse.com/948976">SUSE bug 948976</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/982386">SUSE bug 982386</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155278" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5278</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5278" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5278" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5278" ref_url="https://www.suse.com/security/cve/CVE-2015-5278" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1782-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1445-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-5278/">CVE-2015-5278</cve>
	<bugzilla href="https://bugzilla.suse.com/945989">SUSE bug 945989</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/964947">SUSE bug 964947</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155279" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5279</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5279" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5279" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5279" ref_url="https://www.suse.com/security/cve/CVE-2015-5279" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1782-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-5279/">CVE-2015-5279</cve>
	<bugzilla href="https://bugzilla.suse.com/945987">SUSE bug 945987</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155297" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5297</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5297" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5297" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5297" ref_url="https://www.suse.com/security/cve/CVE-2015-5297" source="SUSE CVE"/>
    <description>
    An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to crash or, potentially, execute arbitrary code.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2015-5297/">CVE-2015-5297</cve>
	<bugzilla href="https://bugzilla.suse.com/1117000">SUSE bug 1117000</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009337724" comment="libpixman-1-0 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155307" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5307</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5307" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5307" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5307" ref_url="https://www.suse.com/security/cve/CVE-2015-5307" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2108-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2350-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0354-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2232-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2249-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2250-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-5307/">CVE-2015-5307</cve>
	<bugzilla href="https://bugzilla.suse.com/953527">SUSE bug 953527</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/954018">SUSE bug 954018</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/954404">SUSE bug 954404</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/954405">SUSE bug 954405</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962977">SUSE bug 962977</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155310" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5310</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5310" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5310" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5310" ref_url="https://www.suse.com/security/cve/CVE-2015-5310" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002272.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2357-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00075.html" source="SUSE-SU"/>
    <description>
    The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or cause a denial of service (ignored packets) via a WNM Sleep Mode response.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-5310/">CVE-2015-5310</cve>
	<bugzilla href="https://bugzilla.suse.com/952254">SUSE bug 952254</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/953115">SUSE bug 953115</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155312" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5312</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5312" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5312" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5312" ref_url="https://www.suse.com/security/cve/CVE-2015-5312" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html" source="SUSE-SU"/>
    <description>
    The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-5312/">CVE-2015-5312</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957105">SUSE bug 957105</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/959469">SUSE bug 959469</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969769">SUSE bug 969769</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155313" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5313</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5313" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5313" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5313" ref_url="https://www.suse.com/security/cve/CVE-2015-5313" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0304-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-March/001975.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-April/001977.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0209-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0216-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00082.html" source="SUSE-SU"/>
    <description>
    Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not domain:write permission to write to arbitrary files via a .. (dot dot) in a volume name.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2015-5313/">CVE-2015-5313</cve>
	<bugzilla href="https://bugzilla.suse.com/953110">SUSE bug 953110</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155315" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5315</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5315" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5315" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5315" ref_url="https://www.suse.com/security/cve/CVE-2015-5315" source="SUSE CVE"/>
    <description>
    The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pwd is enabled in a network configuration profile, which allows remote attackers to cause a denial of service (process termination) via a large final fragment in an EAP-pwd message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-5315/">CVE-2015-5315</cve>
	<bugzilla href="https://bugzilla.suse.com/953115">SUSE bug 953115</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155316" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5316</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5316" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5316" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5316" ref_url="https://www.suse.com/security/cve/CVE-2015-5316" source="SUSE CVE"/>
    <description>
    The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an EAP-pwd Confirm message followed by the Identity exchange.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-5316/">CVE-2015-5316</cve>
	<bugzilla href="https://bugzilla.suse.com/953115">SUSE bug 953115</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155738" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5738</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5738" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5738" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5738" ref_url="https://www.suse.com/security/cve/CVE-2015-5738" source="SUSE CVE"/>
    <description>
    The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2015-5738/">CVE-2015-5738</cve>
	<bugzilla href="https://bugzilla.suse.com/944456">SUSE bug 944456</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/944835">SUSE bug 944835</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/944836">SUSE bug 944836</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482233" comment="libgcrypt20-1.8.2-8.36.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20155745" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-5745</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-5745" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5745" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-5745" ref_url="https://www.suse.com/security/cve/CVE-2015-5745" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-5745/">CVE-2015-5745</cve>
	<bugzilla href="https://bugzilla.suse.com/940929">SUSE bug 940929</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950367">SUSE bug 950367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20156251" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-6251</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-6251" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6251" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-6251" ref_url="https://www.suse.com/security/cve/CVE-2015-6251" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1518-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-September/001582.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1499-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-09/msg00001.html" source="SUSE-SU"/>
    <description>
    Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-6251/">CVE-2015-6251</cve>
	<bugzilla href="https://bugzilla.suse.com/941794">SUSE bug 941794</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20156525" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-6525</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-6525" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6525" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-6525" ref_url="https://www.suse.com/security/cve/CVE-2015-6525" source="SUSE CVE"/>
    <description>
    Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_prepend, (3) evbuffer_expand, (4) exbuffer_reserve_space, or (5) evbuffer_read function, which triggers a heap-based buffer overflow or an infinite loop.  NOTE: this identifier was SPLIT from CVE-2014-6272 per ADT3 due to different affected versions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-6525/">CVE-2015-6525</cve>
	<bugzilla href="https://bugzilla.suse.com/897243">SUSE bug 897243</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/943011">SUSE bug 943011</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009654580" comment="libevent-2_1-8 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20156815" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-6815</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-6815" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6815" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-6815" ref_url="https://www.suse.com/security/cve/CVE-2015-6815" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1894-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1952-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2249-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2015-6815/">CVE-2015-6815</cve>
	<bugzilla href="https://bugzilla.suse.com/944697">SUSE bug 944697</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950367">SUSE bug 950367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20156855" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-6855</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-6855" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6855" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-6855" ref_url="https://www.suse.com/security/cve/CVE-2015-6855" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1782-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-6855/">CVE-2015-6855</cve>
	<bugzilla href="https://bugzilla.suse.com/945404">SUSE bug 945404</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/965156">SUSE bug 965156</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20156908" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-6908</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-6908" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6908" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-6908" ref_url="https://www.suse.com/security/cve/CVE-2015-6908" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0224-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0262-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0255-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0261-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00039.html" source="SUSE-SU"/>
    <description>
    The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-6908/">CVE-2015-6908</cve>
	<bugzilla href="https://bugzilla.suse.com/945582">SUSE bug 945582</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20156937" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-6937</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-6937" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6937" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-6937" ref_url="https://www.suse.com/security/cve/CVE-2015-6937" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1727-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2108-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2350-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0335-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0337-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0354-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0380-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0381-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0383-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0384-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0386-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0434-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2232-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-6937/">CVE-2015-6937</cve>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/923755">SUSE bug 923755</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/945825">SUSE bug 945825</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/952384">SUSE bug 952384</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/953052">SUSE bug 953052</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963994">SUSE bug 963994</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157181" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7181</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7181" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7181" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7181" ref_url="https://www.suse.com/security/cve/CVE-2015-7181" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1926-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1978-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1981-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2081-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1942-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2229-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2245-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00049.html" source="SUSE-SU"/>
    <description>
    The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-7181/">CVE-2015-7181</cve>
	<bugzilla href="https://bugzilla.suse.com/952810">SUSE bug 952810</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157182" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7182</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7182" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7182" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7182" ref_url="https://www.suse.com/security/cve/CVE-2015-7182" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1926-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1978-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1981-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2081-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1942-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2229-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2245-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00049.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-7182/">CVE-2015-7182</cve>
	<bugzilla href="https://bugzilla.suse.com/952810">SUSE bug 952810</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157183" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7183</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7183" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7183" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7183" ref_url="https://www.suse.com/security/cve/CVE-2015-7183" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1926-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1978-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1981-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2081-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1942-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2229-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2245-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00049.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-7183/">CVE-2015-7183</cve>
	<bugzilla href="https://bugzilla.suse.com/952810">SUSE bug 952810</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962977">SUSE bug 962977</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760840" comment="mozilla-nspr-4.25.1-3.15.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157236" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7236</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7236" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7236" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7236" ref_url="https://www.suse.com/security/cve/CVE-2015-7236" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1705-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1705-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1706-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-October/001623.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-7236/">CVE-2015-7236</cve>
	<bugzilla href="https://bugzilla.suse.com/940191">SUSE bug 940191</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/946204">SUSE bug 946204</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979097">SUSE bug 979097</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482535" comment="rpcbind-0.2.3-5.9.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157295" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7295</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7295" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7295" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7295" ref_url="https://www.suse.com/security/cve/CVE-2015-7295" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
    <description>
    hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-7295/">CVE-2015-7295</cve>
	<bugzilla href="https://bugzilla.suse.com/947159">SUSE bug 947159</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950367">SUSE bug 950367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157311" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7311</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7311" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7311" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7311" ref_url="https://www.suse.com/security/cve/CVE-2015-7311" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1894-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2249-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2250-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
    <description>
    libxl in Xen 4.1.x through 4.6.x does not properly handle the readonly flag on disks when using the qemu-xen device model, which allows local guest users to write to a read-only disk image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-7311/">CVE-2015-7311</cve>
	<bugzilla href="https://bugzilla.suse.com/947165">SUSE bug 947165</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950367">SUSE bug 950367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157497" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7497</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7497" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7497" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7497" ref_url="https://www.suse.com/security/cve/CVE-2015-7497" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-7497/">CVE-2015-7497</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957106">SUSE bug 957106</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/959469">SUSE bug 959469</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969769">SUSE bug 969769</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157498" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7498</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7498" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7498" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7498" ref_url="https://www.suse.com/security/cve/CVE-2015-7498" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-7498/">CVE-2015-7498</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957107">SUSE bug 957107</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/959469">SUSE bug 959469</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969769">SUSE bug 969769</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157499" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7499</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7499" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7499" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7499" ref_url="https://www.suse.com/security/cve/CVE-2015-7499" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-7499/">CVE-2015-7499</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957109">SUSE bug 957109</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/959469">SUSE bug 959469</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969769">SUSE bug 969769</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157500" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7500</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7500" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7500" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7500" ref_url="https://www.suse.com/security/cve/CVE-2015-7500" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html" source="SUSE-SU"/>
    <description>
    The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-7500/">CVE-2015-7500</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957110">SUSE bug 957110</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/959469">SUSE bug 959469</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969769">SUSE bug 969769</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157504" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7504</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7504" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7504" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7504" ref_url="https://www.suse.com/security/cve/CVE-2015-7504" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets in loopback mode.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-7504/">CVE-2015-7504</cve>
	<bugzilla href="https://bugzilla.suse.com/956411">SUSE bug 956411</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157510" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7510</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7510" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7510" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7510" ref_url="https://www.suse.com/security/cve/CVE-2015-7510" source="SUSE CVE"/>
    <description>
    Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-7510/">CVE-2015-7510</cve>
	<bugzilla href="https://bugzilla.suse.com/956712">SUSE bug 956712</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157511" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7511</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7511" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7511" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7511" ref_url="https://www.suse.com/security/cve/CVE-2015-7511" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-April/002017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0575-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00151.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1227-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-05/msg00027.html" source="SUSE-SU"/>
    <description>
    Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-7511/">CVE-2015-7511</cve>
	<bugzilla href="https://bugzilla.suse.com/965902">SUSE bug 965902</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482233" comment="libgcrypt20-1.8.2-8.36.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157512" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7512</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7512" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7512" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7512" ref_url="https://www.suse.com/security/cve/CVE-2015-7512" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0020-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0021-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-7512/">CVE-2015-7512</cve>
	<bugzilla href="https://bugzilla.suse.com/957162">SUSE bug 957162</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962360">SUSE bug 962360</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157513" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7513</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7513" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7513" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7513" ref_url="https://www.suse.com/security/cve/CVE-2015-7513" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2976-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3069-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00048.html" source="SUSE-SU"/>
    <description>
    arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_vm_ioctl_set_pit and kvm_vm_ioctl_set_pit2 functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-7513/">CVE-2015-7513</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960689">SUSE bug 960689</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/987709">SUSE bug 987709</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157547" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7547</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7547" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7547" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7547" ref_url="https://www.suse.com/security/cve/CVE-2015-7547" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0472-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="TID7017265" ref_url="https://www.suse.com/support/kb/doc?id=7017265" source="SUSE-SU"/>
		<reference ref_id="TID7017273" ref_url="https://www.suse.com/support/kb/doc/?id=7017273" source="SUSE-SU"/>
		<reference ref_id="TID7017287" ref_url="https://www.suse.com/support/kb/doc?id=7017287" source="SUSE-SU"/>
		<reference ref_id="TID7017315" ref_url="https://www.suse.com/support/kb/doc/?id=7017315" source="SUSE-SU"/>
		<reference ref_id="TID7017329" ref_url="https://www.suse.com/support/kb/doc/?id=7017329" source="SUSE-SU"/>
		<reference ref_id="TID7021300" ref_url="https://www.suse.com/support/kb/doc/?id=7021300" source="SUSE-SU"/>
		<reference ref_id="TID7021823" ref_url="https://www.suse.com/support/kb/doc/?id=7021823" source="SUSE-SU"/>
		<reference ref_id="TID7022077" ref_url="https://www.suse.com/support/kb/doc/?id=7022077" source="SUSE-SU"/>
		<reference ref_id="TID7022102" ref_url="https://www.suse.com/support/kb/doc/?id=7022102" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0490-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0511-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0512-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00044.html" source="SUSE-SU"/>
    <description>
    Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-7547/">CVE-2015-7547</cve>
	<bugzilla href="https://bugzilla.suse.com/1077097">SUSE bug 1077097</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/847227">SUSE bug 847227</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961721">SUSE bug 961721</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/967023">SUSE bug 967023</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/967061">SUSE bug 967061</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/967072">SUSE bug 967072</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/967496">SUSE bug 967496</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969216">SUSE bug 969216</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969241">SUSE bug 969241</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969591">SUSE bug 969591</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986086">SUSE bug 986086</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157549" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7549</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7549" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7549" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7549" ref_url="https://www.suse.com/security/cve/CVE-2015-7549" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
    <description>
    The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by leveraging failure to define the .write method.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-7549/">CVE-2015-7549</cve>
	<bugzilla href="https://bugzilla.suse.com/958917">SUSE bug 958917</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958918">SUSE bug 958918</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157566" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7566</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7566" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7566" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7566" ref_url="https://www.suse.com/security/cve/CVE-2015-7566" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1764-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-7566/">CVE-2015-7566</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961512">SUSE bug 961512</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157575" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7575</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7575" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7575" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7575" ref_url="https://www.suse.com/security/cve/CVE-2015-7575" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001807.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001818.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0256-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0269-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0390-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0399-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0401-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0428-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0431-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0433-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001894.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0636-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0770-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0776-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2405-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00139.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0007-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0161-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0162-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0263-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0268-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0270-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0272-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0279-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0307-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0308-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0488-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00101.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0605-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00166.html" source="SUSE-SU"/>
    <description>
    Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-7575/">CVE-2015-7575</cve>
	<bugzilla href="https://bugzilla.suse.com/959888">SUSE bug 959888</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960402">SUSE bug 960402</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960996">SUSE bug 960996</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961280">SUSE bug 961280</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961281">SUSE bug 961281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961282">SUSE bug 961282</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961283">SUSE bug 961283</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961284">SUSE bug 961284</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961290">SUSE bug 961290</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961357">SUSE bug 961357</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962743">SUSE bug 962743</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963937">SUSE bug 963937</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/967521">SUSE bug 967521</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981087">SUSE bug 981087</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157613" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7613</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7613" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7613" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7613" ref_url="https://www.suse.com/security/cve/CVE-2015-7613" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1727-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2085-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2087-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2089-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2090-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2091-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00032.html" source="SUSE-SU"/>
    <description>
    Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-7613/">CVE-2015-7613</cve>
	<bugzilla href="https://bugzilla.suse.com/923755">SUSE bug 923755</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/948536">SUSE bug 948536</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/948701">SUSE bug 948701</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963994">SUSE bug 963994</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157799" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7799</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7799" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7799" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7799" ref_url="https://www.suse.com/security/cve/CVE-2015-7799" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2292-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2350-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0585-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2232-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-7799/">CVE-2015-7799</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1052256">SUSE bug 1052256</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/949936">SUSE bug 949936</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951638">SUSE bug 951638</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157833" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7833</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7833" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7833" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7833" ref_url="https://www.suse.com/security/cve/CVE-2015-7833" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2105-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html" source="SUSE-SU"/>
    <description>
    The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-7833/">CVE-2015-7833</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950998">SUSE bug 950998</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157835" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7835</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7835" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7835" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7835" ref_url="https://www.suse.com/security/cve/CVE-2015-7835" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1894-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1952-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1965-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2249-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2250-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00053.html" source="SUSE-SU"/>
    <description>
    The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-7835/">CVE-2015-7835</cve>
	<bugzilla href="https://bugzilla.suse.com/940929">SUSE bug 940929</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/947159">SUSE bug 947159</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950367">SUSE bug 950367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157884" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7884</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7884" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7884" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7884" ref_url="https://www.suse.com/security/cve/CVE-2015-7884" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2016:1008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.html" source="SUSE-SU"/>
    <description>
    The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-7884/">CVE-2015-7884</cve>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951626">SUSE bug 951626</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951627">SUSE bug 951627</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157885" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7885</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7885" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7885" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7885" ref_url="https://www.suse.com/security/cve/CVE-2015-7885" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00005.html" source="SUSE-SU"/>
    <description>
    The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-7885/">CVE-2015-7885</cve>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951626">SUSE bug 951626</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951627">SUSE bug 951627</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157941" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7941</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7941" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7941" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7941" ref_url="https://www.suse.com/security/cve/CVE-2015-7941" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html" source="SUSE-SU"/>
    <description>
    libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-7941/">CVE-2015-7941</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951734">SUSE bug 951734</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951735">SUSE bug 951735</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969769">SUSE bug 969769</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157942" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7942</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7942" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7942" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7942" ref_url="https://www.suse.com/security/cve/CVE-2015-7942" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html" source="SUSE-SU"/>
    <description>
    The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-7942/">CVE-2015-7942</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951735">SUSE bug 951735</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969769">SUSE bug 969769</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157969" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7969</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7969" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7969" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7969" ref_url="https://www.suse.com/security/cve/CVE-2015-7969" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1894-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1952-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1965-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
    <description>
    Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROF_get_buffer or (3) XENOPROF_set_passive hypercall.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-7969/">CVE-2015-7969</cve>
	<bugzilla href="https://bugzilla.suse.com/950703">SUSE bug 950703</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950705">SUSE bug 950705</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157970" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7970</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7970" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7970" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7970" ref_url="https://www.suse.com/security/cve/CVE-2015-7970" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2249-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2250-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
    <description>
    The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-consuming linear scan," related to Populate-on-Demand.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-7970/">CVE-2015-7970</cve>
	<bugzilla href="https://bugzilla.suse.com/950704">SUSE bug 950704</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157971" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7971</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7971" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7971" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7971" ref_url="https://www.suse.com/security/cve/CVE-2015-7971" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1894-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:1952-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1965-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
    <description>
    Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hypercalls, which allows local guests to cause a denial of service via a sequence of crafted (1) HYPERCALL_xenoprof_op hypercalls, which are not properly handled in the do_xenoprof_op function in common/xenoprof.c, or (2) HYPERVISOR_xenpmu_op hypercalls, which are not properly handled in the do_xenpmu_op function in arch/x86/cpu/vpmu.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-7971/">CVE-2015-7971</cve>
	<bugzilla href="https://bugzilla.suse.com/950706">SUSE bug 950706</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157972" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7972</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7972" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7972" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7972" ref_url="https://www.suse.com/security/cve/CVE-2015-7972" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:1965-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00023.html" source="SUSE-SU"/>
    <description>
    The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to "heavy memory pressure."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-7972/">CVE-2015-7972</cve>
	<bugzilla href="https://bugzilla.suse.com/950704">SUSE bug 950704</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951845">SUSE bug 951845</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157990" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7990</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7990" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7990" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7990" ref_url="https://www.suse.com/security/cve/CVE-2015-7990" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2108-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2292-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2350-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0335-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0337-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0354-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0380-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0381-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0383-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0384-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0386-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0434-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2232-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6937.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-7990/">CVE-2015-7990</cve>
	<bugzilla href="https://bugzilla.suse.com/945825">SUSE bug 945825</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/952384">SUSE bug 952384</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/953052">SUSE bug 953052</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20157995" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-7995</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-7995" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7995" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-7995" ref_url="https://www.suse.com/security/cve/CVE-2015-7995" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1439-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-05/msg00123.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1390-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00079.html" source="SUSE-SU"/>
    <description>
    The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-7995/">CVE-2015-7995</cve>
	<bugzilla href="https://bugzilla.suse.com/1123130">SUSE bug 1123130</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/952474">SUSE bug 952474</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482467" comment="libxslt1-1.1.32-3.8.24 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158019" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8019</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8019" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8019" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8019" ref_url="https://www.suse.com/security/cve/CVE-2015-8019" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1961-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1994-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2009-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html" source="SUSE-SU"/>
    <description>
    The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a write system call followed by a recvmsg system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-01"/>
	<updated date="2023-07-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8019/">CVE-2015-8019</cve>
	<bugzilla href="https://bugzilla.suse.com/1032268">SUSE bug 1032268</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/951199">SUSE bug 951199</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/952587">SUSE bug 952587</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979078">SUSE bug 979078</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158035" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8035</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8035" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8035" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8035" ref_url="https://www.suse.com/security/cve/CVE-2015-8035" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html" source="SUSE-SU"/>
    <description>
    The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-8035/">CVE-2015-8035</cve>
	<bugzilla href="https://bugzilla.suse.com/1088279">SUSE bug 1088279</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105166">SUSE bug 1105166</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/954429">SUSE bug 954429</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158041" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8041</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8041" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8041" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8041" ref_url="https://www.suse.com/security/cve/CVE-2015-8041" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2357-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in the NDEF record parser in hostapd before 2.5 and wpa_supplicant before 2.5 allow remote attackers to cause a denial of service (process crash or infinite loop) via a large payload length field value in an (1) WPS or (2) P2P NFC NDEF record, which triggers an out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8041/">CVE-2015-8041</cve>
	<bugzilla href="https://bugzilla.suse.com/937419">SUSE bug 937419</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158104" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8104</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8104" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8104" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8104" ref_url="https://www.suse.com/security/cve/CVE-2015-8104" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2108-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2350-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0354-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2232-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2249-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2250-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8104/">CVE-2015-8104</cve>
	<bugzilla href="https://bugzilla.suse.com/1215748">SUSE bug 1215748</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/953527">SUSE bug 953527</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/954018">SUSE bug 954018</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/954404">SUSE bug 954404</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/954405">SUSE bug 954405</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962977">SUSE bug 962977</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158126" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8126</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8126" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8126" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8126" ref_url="https://www.suse.com/security/cve/CVE-2015-8126" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2013-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-November/001681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2017-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-November/001682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2024-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-November/001683.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0041-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001783.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001790.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0256-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0269-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0390-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0399-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0401-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0428-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0431-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0433-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0636-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0665-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0770-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0776-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2099-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-11/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2135-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00159.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2136-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-11/msg00160.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2262-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2263-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0103-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0104-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0105-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0263-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0268-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0270-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0272-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0279-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0664-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0684-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0729-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1652-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00046.html" source="SUSE-SU"/>
    <description>
    Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8126/">CVE-2015-8126</cve>
	<bugzilla href="https://bugzilla.suse.com/954980">SUSE bug 954980</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958198">SUSE bug 958198</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960402">SUSE bug 960402</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962743">SUSE bug 962743</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963937">SUSE bug 963937</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969333">SUSE bug 969333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482352" comment="libpng16-16-1.6.34-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158242" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8242</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8242" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8242" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8242" ref_url="https://www.suse.com/security/cve/CVE-2015-8242" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2372-1" ref_url="https://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-01/msg00031.html" source="SUSE-SU"/>
    <description>
    The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8242/">CVE-2015-8242</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/956021">SUSE bug 956021</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/959469">SUSE bug 959469</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969769">SUSE bug 969769</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158324" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8324</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8324" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8324" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8324" ref_url="https://www.suse.com/security/cve/CVE-2015-8324" source="SUSE CVE"/>
    <description>
    The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8324/">CVE-2015-8324</cve>
	<bugzilla href="https://bugzilla.suse.com/956707">SUSE bug 956707</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158325" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8325</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8325" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8325" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8325" ref_url="https://www.suse.com/security/cve/CVE-2015-8325" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-May/002080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002338.html" source="SUSE-SU"/>
		<reference ref_id="TID7022102" ref_url="https://www.suse.com/support/kb/doc/?id=7022102" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1455-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-05/msg00132.html" source="SUSE-SU"/>
    <description>
    The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-8325/">CVE-2015-8325</cve>
	<bugzilla href="https://bugzilla.suse.com/1138392">SUSE bug 1138392</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/975865">SUSE bug 975865</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/996040">SUSE bug 996040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158339" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8339</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8339" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8339" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8339" ref_url="https://www.suse.com/security/cve/CVE-2015-8339" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
    <description>
    The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain, which might allow guest OS administrators to cause a denial of service (host crash) via unspecified vectors related to domain teardown.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8339/">CVE-2015-8339</cve>
	<bugzilla href="https://bugzilla.suse.com/956408">SUSE bug 956408</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158340" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8340</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8340" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8340" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8340" ref_url="https://www.suse.com/security/cve/CVE-2015-8340" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
    <description>
    The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly release locks, which might allow guest OS administrators to cause a denial of service (deadlock or host crash) via unspecified vectors, related to XENMEM_exchange error handling.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8340/">CVE-2015-8340</cve>
	<bugzilla href="https://bugzilla.suse.com/956408">SUSE bug 956408</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158341" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8341</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8341" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8341" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8341" ref_url="https://www.suse.com/security/cve/CVE-2015-8341" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
    <description>
    The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8341/">CVE-2015-8341</cve>
	<bugzilla href="https://bugzilla.suse.com/956409">SUSE bug 956409</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158345" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8345</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8345" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8345" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8345" ref_url="https://www.suse.com/security/cve/CVE-2015-8345" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2015-December/001754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0020-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0021-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-January/001778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0536-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) via vectors involving the command block list.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8345/">CVE-2015-8345</cve>
	<bugzilla href="https://bugzilla.suse.com/956829">SUSE bug 956829</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/956832">SUSE bug 956832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158370" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8370</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8370" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8370" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8370" ref_url="https://www.suse.com/security/cve/CVE-2015-8370" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2015:2385-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2386-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2015:2399-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2375-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2015:2392-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2015-12/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0036-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00003.html" source="SUSE-SU"/>
    <description>
    Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an "Off-by-two" or "Out of bounds overwrite" memory error.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8370/">CVE-2015-8370</cve>
	<bugzilla href="https://bugzilla.suse.com/956631">SUSE bug 956631</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760789" comment="grub2-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760790" comment="grub2-arm64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760791" comment="grub2-i386-pc-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760792" comment="grub2-powerpc-ieee1275-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760793" comment="grub2-s390x-emu-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760794" comment="grub2-snapper-plugin-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760795" comment="grub2-x86_64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760796" comment="grub2-x86_64-xen-2.04-9.30.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158374" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8374</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8374" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8374" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8374" ref_url="https://www.suse.com/security/cve/CVE-2015-8374" source="SUSE CVE"/>
    <description>
    fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-13"/>
	<updated date="2023-05-13"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-8374/">CVE-2015-8374</cve>
	<bugzilla href="https://bugzilla.suse.com/923755">SUSE bug 923755</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/956053">SUSE bug 956053</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963994">SUSE bug 963994</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158504" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8504</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8504" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8504" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8504" ref_url="https://www.suse.com/security/cve/CVE-2015-8504" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
    <description>
    Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8504/">CVE-2015-8504</cve>
	<bugzilla href="https://bugzilla.suse.com/958491">SUSE bug 958491</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958493">SUSE bug 958493</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158539" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8539</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8539" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8539" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8539" ref_url="https://www.suse.com/security/cve/CVE-2015-8539" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0335-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0337-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0380-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0381-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0383-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0384-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0386-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0434-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0585-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0280-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-8539/">CVE-2015-8539</cve>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/781018">SUSE bug 781018</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958463">SUSE bug 958463</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958601">SUSE bug 958601</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158543" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8543</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8543" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8543" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8543" ref_url="https://www.suse.com/security/cve/CVE-2015-8543" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0585-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0280-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer dereference and system crash) or possibly gain privileges by leveraging CLONE_NEWUSER support to execute a crafted SOCK_RAW application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-08"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-8543/">CVE-2015-8543</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1052256">SUSE bug 1052256</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/923755">SUSE bug 923755</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/958886">SUSE bug 958886</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963994">SUSE bug 963994</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969522">SUSE bug 969522</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158550" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8550</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8550" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8550" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8550" ref_url="https://www.suse.com/security/cve/CVE-2015-8550" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0585-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1764-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0280-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00005.html" source="SUSE-SU"/>
    <description>
    Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8550/">CVE-2015-8550</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1052256">SUSE bug 1052256</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957988">SUSE bug 957988</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158551" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8551</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8551" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8551" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8551" ref_url="https://www.suse.com/security/cve/CVE-2015-8551" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0585-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1764-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2105-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0280-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html" source="SUSE-SU"/>
    <description>
    The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and a crafted sequence of XEN_PCI_OP_* operations, aka "Linux pciback missing sanity checks."
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8551/">CVE-2015-8551</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957990">SUSE bug 957990</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158552" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8552</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8552" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8552" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8552" ref_url="https://www.suse.com/security/cve/CVE-2015-8552" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1764-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2105-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0280-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html" source="SUSE-SU"/>
    <description>
    The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and XEN_PCI_OP_enable_msi operations, aka "Linux pciback missing sanity checks."
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8552/">CVE-2015-8552</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957990">SUSE bug 957990</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158553" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8553</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8553" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8553" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8553" ref_url="https://www.suse.com/security/cve/CVE-2015-8553" source="SUSE CVE"/>
    <description>
    Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2015-8553/">CVE-2015-8553</cve>
	<bugzilla href="https://bugzilla.suse.com/903967">SUSE bug 903967</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957990">SUSE bug 957990</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158554" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8554</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8554" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8554" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8554" ref_url="https://www.suse.com/security/cve/CVE-2015-8554" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8554/">CVE-2015-8554</cve>
	<bugzilla href="https://bugzilla.suse.com/958007">SUSE bug 958007</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158555" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8555</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8555" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8555" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8555" ref_url="https://www.suse.com/security/cve/CVE-2015-8555" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0658-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
    <description>
    Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8555/">CVE-2015-8555</cve>
	<bugzilla href="https://bugzilla.suse.com/958009">SUSE bug 958009</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158558" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8558</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8558" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8558" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8558" ref_url="https://www.suse.com/security/cve/CVE-2015-8558" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
    <description>
    The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular isochronous transfer descriptor (iTD) list.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8558/">CVE-2015-8558</cve>
	<bugzilla href="https://bugzilla.suse.com/959005">SUSE bug 959005</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/959006">SUSE bug 959006</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/976109">SUSE bug 976109</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/976111">SUSE bug 976111</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158567" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8567</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8567" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8567" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8567" ref_url="https://www.suse.com/security/cve/CVE-2015-8567" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
    <description>
    Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.7/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8567/">CVE-2015-8567</cve>
	<bugzilla href="https://bugzilla.suse.com/959386">SUSE bug 959386</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/959387">SUSE bug 959387</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158568" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8568</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8568" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8568" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8568" ref_url="https://www.suse.com/security/cve/CVE-2015-8568" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
    <description>
    Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8568/">CVE-2015-8568</cve>
	<bugzilla href="https://bugzilla.suse.com/959386">SUSE bug 959386</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/959387">SUSE bug 959387</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158613" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8613</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8613" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8613" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8613" ref_url="https://www.suse.com/security/cve/CVE-2015-8613" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRL_GET_INFO command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8613/">CVE-2015-8613</cve>
	<bugzilla href="https://bugzilla.suse.com/961358">SUSE bug 961358</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961556">SUSE bug 961556</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158615" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8615</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8615" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8615" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8615" ref_url="https://www.suse.com/security/cve/CVE-2015-8615" source="SUSE CVE"/>
    <description>
    The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages when logging the new callback method, which allows local HVM guest OS users to cause a denial of service via a large number of changes to the callback method (HVM_PARAM_CALLBACK_IRQ).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-8615/">CVE-2015-8615</cve>
	<bugzilla href="https://bugzilla.suse.com/960093">SUSE bug 960093</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158619" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8619</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8619" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8619" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8619" ref_url="https://www.suse.com/security/cve/CVE-2015-8619" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
    <description>
    The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8619/">CVE-2015-8619</cve>
	<bugzilla href="https://bugzilla.suse.com/960334">SUSE bug 960334</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/965269">SUSE bug 965269</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158629" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8629</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8629" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8629" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8629" ref_url="https://www.suse.com/security/cve/CVE-2015-8629" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001870.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001871.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0406-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0501-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00110.html" source="SUSE-SU"/>
    <description>
    The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.3/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2015-8629/">CVE-2015-8629</cve>
	<bugzilla href="https://bugzilla.suse.com/770172">SUSE bug 770172</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963968">SUSE bug 963968</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158630" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8630</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8630" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8630" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8630" ref_url="https://www.suse.com/security/cve/CVE-2015-8630" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001870.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0406-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0501-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00110.html" source="SUSE-SU"/>
    <description>
    The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by specifying KADM5_POLICY with a NULL policy name.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8630/">CVE-2015-8630</cve>
	<bugzilla href="https://bugzilla.suse.com/963964">SUSE bug 963964</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158631" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8631</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8631" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8631" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8631" ref_url="https://www.suse.com/security/cve/CVE-2015-8631" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001870.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001871.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0406-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0501-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00110.html" source="SUSE-SU"/>
    <description>
    Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8631/">CVE-2015-8631</cve>
	<bugzilla href="https://bugzilla.suse.com/963975">SUSE bug 963975</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158660" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8660</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8660" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8660" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8660" ref_url="https://www.suse.com/security/cve/CVE-2015-8660" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0585-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0751-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0752-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0755-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00043.html" source="SUSE-SU"/>
    <description>
    The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-08"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-8660/">CVE-2015-8660</cve>
	<bugzilla href="https://bugzilla.suse.com/923755">SUSE bug 923755</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960281">SUSE bug 960281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960329">SUSE bug 960329</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963994">SUSE bug 963994</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158743" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8743</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8743" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8743" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8743" ref_url="https://www.suse.com/security/cve/CVE-2015-8743" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1445-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w operations. A privileged (CAP_SYS_RAWIO) user/process could use this flaw to leak or corrupt QEMU memory bytes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2015-8743/">CVE-2015-8743</cve>
	<bugzilla href="https://bugzilla.suse.com/960725">SUSE bug 960725</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960726">SUSE bug 960726</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158744" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8744</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8744" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8744" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8744" ref_url="https://www.suse.com/security/cve/CVE-2015-8744" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a Layer-2 packet smaller than 22 bytes. A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8744/">CVE-2015-8744</cve>
	<bugzilla href="https://bugzilla.suse.com/960835">SUSE bug 960835</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960836">SUSE bug 960836</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158745" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8745</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8745" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8745" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8745" ref_url="https://www.suse.com/security/cve/CVE-2015-8745" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8745/">CVE-2015-8745</cve>
	<bugzilla href="https://bugzilla.suse.com/960707">SUSE bug 960707</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960708">SUSE bug 960708</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158776" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8776</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8776" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8776" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8776" ref_url="https://www.suse.com/security/cve/CVE-2015-8776" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0472-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="TID7017287" ref_url="https://www.suse.com/support/kb/doc?id=7017287" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0490-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00042.html" source="SUSE-SU"/>
    <description>
    The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-8776/">CVE-2015-8776</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962736">SUSE bug 962736</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986086">SUSE bug 986086</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158777" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8777</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8777" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8777" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8777" ref_url="https://www.suse.com/security/cve/CVE-2015-8777" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0472-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="TID7017287" ref_url="https://www.suse.com/support/kb/doc?id=7017287" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0490-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00041.html" source="SUSE-SU"/>
    <description>
    The process_envvars function in elf/rtld.c in the GNU C Library (aka glibc or libc6) before 2.23 allows local users to bypass a pointer-guarding protection mechanism via a zero value of the LD_POINTER_GUARD environment variable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-8777/">CVE-2015-8777</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/950944">SUSE bug 950944</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962735">SUSE bug 962735</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158778" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8778</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8778" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8778" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8778" ref_url="https://www.suse.com/security/cve/CVE-2015-8778" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0472-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="TID7017287" ref_url="https://www.suse.com/support/kb/doc?id=7017287" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0490-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00042.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-8778/">CVE-2015-8778</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962737">SUSE bug 962737</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986086">SUSE bug 986086</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158779" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8779</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8779" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8779" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8779" ref_url="https://www.suse.com/security/cve/CVE-2015-8779" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0472-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="TID7017287" ref_url="https://www.suse.com/support/kb/doc?id=7017287" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0490-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00042.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-8779/">CVE-2015-8779</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962739">SUSE bug 962739</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/965453">SUSE bug 965453</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986086">SUSE bug 986086</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158785" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8785</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8785" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8785" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8785" ref_url="https://www.suse.com/security/cve/CVE-2015-8785" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0585-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-02/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1764-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8785/">CVE-2015-8785</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963765">SUSE bug 963765</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158803" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8803</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8803" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8803" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8803" ref_url="https://www.suse.com/security/cve/CVE-2015-8803" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001877.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0475-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00091.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0477-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00093.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0486-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00100.html" source="SUSE-SU"/>
    <description>
    The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8803/">CVE-2015-8803</cve>
	<bugzilla href="https://bugzilla.suse.com/964845">SUSE bug 964845</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482241" comment="libhogweed4-3.4.1-4.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482244" comment="libnettle6-3.4.1-4.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158804" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8804</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8804" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8804" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8804" ref_url="https://www.suse.com/security/cve/CVE-2015-8804" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001877.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0475-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00091.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0477-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00093.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0486-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00100.html" source="SUSE-SU"/>
    <description>
    x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8804/">CVE-2015-8804</cve>
	<bugzilla href="https://bugzilla.suse.com/964847">SUSE bug 964847</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482241" comment="libhogweed4-3.4.1-4.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482244" comment="libnettle6-3.4.1-4.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158805" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8805</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8805" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8805" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8805" ref_url="https://www.suse.com/security/cve/CVE-2015-8805" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001877.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0475-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00091.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0477-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00093.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0486-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00100.html" source="SUSE-SU"/>
    <description>
    The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8805/">CVE-2015-8805</cve>
	<bugzilla href="https://bugzilla.suse.com/964849">SUSE bug 964849</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482241" comment="libhogweed4-3.4.1-4.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482244" comment="libnettle6-3.4.1-4.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158816" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8816</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8816" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8816" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8816" ref_url="https://www.suse.com/security/cve/CVE-2015-8816" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1019-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1690-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1764-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1961-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1994-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2001-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2002-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2006-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2009-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2014-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-8816/">CVE-2015-8816</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968010">SUSE bug 968010</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979064">SUSE bug 979064</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158830" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8830</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8830" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8830" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8830" ref_url="https://www.suse.com/security/cve/CVE-2015-8830" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the aio_setup_single_vector function in fs/aio.c in the Linux kernel 4.0 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec.  NOTE: this vulnerability exists because of a CVE-2012-6701 regression.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-20"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2015-8830/">CVE-2015-8830</cve>
	<bugzilla href="https://bugzilla.suse.com/969354">SUSE bug 969354</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969355">SUSE bug 969355</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158839" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8839</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8839" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8839" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8839" ref_url="https://www.suse.com/security/cve/CVE-2015-8839" source="SUSE CVE"/>
    <description>
    Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page that is associated with a different user's file after unsynchronized hole punching and page-fault handling.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8839/">CVE-2015-8839</cve>
	<bugzilla href="https://bugzilla.suse.com/972174">SUSE bug 972174</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158844" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8844</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8844" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8844" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8844" ref_url="https://www.suse.com/security/cve/CVE-2015-8844" source="SUSE CVE"/>
    <description>
    The signal implementation in the Linux kernel before 4.3.5 on powerpc platforms does not check for an MSR with both the S and T bits set, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8844/">CVE-2015-8844</cve>
	<bugzilla href="https://bugzilla.suse.com/975531">SUSE bug 975531</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/975533">SUSE bug 975533</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158845" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8845</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8845" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8845" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8845" ref_url="https://www.suse.com/security/cve/CVE-2015-8845" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1690-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2105-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html" source="SUSE-SU"/>
    <description>
    The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2015-8845/">CVE-2015-8845</cve>
	<bugzilla href="https://bugzilla.suse.com/975531">SUSE bug 975531</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/975533">SUSE bug 975533</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158948" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8948</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8948" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8948" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8948" ref_url="https://www.suse.com/security/cve/CVE-2015-8948" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1924-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2135-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00098.html" source="SUSE-SU"/>
    <description>
    idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2015-8948/">CVE-2015-8948</cve>
	<bugzilla href="https://bugzilla.suse.com/1014473">SUSE bug 1014473</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173590">SUSE bug 1173590</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190777">SUSE bug 1190777</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990189">SUSE bug 990189</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482248" comment="libidn11-1.34-3.2.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628747" comment="libidn2-0-2.2.0-3.6.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158950" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8950</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8950" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8950" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8950" ref_url="https://www.suse.com/security/cve/CVE-2015-8950" source="SUSE CVE"/>
    <description>
    arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggering a dma_mmap call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-8950/">CVE-2015-8950</cve>
	<bugzilla href="https://bugzilla.suse.com/1003931">SUSE bug 1003931</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1004045">SUSE bug 1004045</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158952" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8952</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8952" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8952" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8952" ref_url="https://www.suse.com/security/cve/CVE-2015-8952" source="SUSE CVE"/>
    <description>
    The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use many attributes, as demonstrated by Ceph and Samba.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2015-8952/">CVE-2015-8952</cve>
	<bugzilla href="https://bugzilla.suse.com/995759">SUSE bug 995759</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158953" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8953</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8953" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8953" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8953" ref_url="https://www.suse.com/security/cve/CVE-2015-8953" source="SUSE CVE"/>
    <description>
    fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to cause a denial of service (dentry reference leak) via filesystem operations on a large file in a lower overlayfs layer.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-8953/">CVE-2015-8953</cve>
	<bugzilla href="https://bugzilla.suse.com/995763">SUSE bug 995763</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158955" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8955</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8955" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8955" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8955" ref_url="https://www.suse.com/security/cve/CVE-2015-8955" source="SUSE CVE"/>
    <description>
    arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via vectors involving events that are mishandled during a span of multiple HW PMUs.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-8955/">CVE-2015-8955</cve>
	<bugzilla href="https://bugzilla.suse.com/1003931">SUSE bug 1003931</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158962" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8962</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8962" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8962" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8962" ref_url="https://www.suse.com/security/cve/CVE-2015-8962" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0464-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3061-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00029.html" source="SUSE-SU"/>
    <description>
    Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (memory corruption and system crash) by detaching a device during an SG_IO ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-8962/">CVE-2015-8962</cve>
	<bugzilla href="https://bugzilla.suse.com/1010501">SUSE bug 1010501</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158963" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8963</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8963" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8963" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8963" ref_url="https://www.suse.com/security/cve/CVE-2015-8963" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0464-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3061-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00029.html" source="SUSE-SU"/>
    <description>
    Race condition in kernel/events/core.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect handling of an swevent data structure during a CPU unplug operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-8963/">CVE-2015-8963</cve>
	<bugzilla href="https://bugzilla.suse.com/1010502">SUSE bug 1010502</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158970" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8970</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8970" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8970" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8970" ref_url="https://www.suse.com/security/cve/CVE-2015-8970" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
    <description>
    crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted application that does not supply a key, related to the lrw_crypt function in crypto/lrw.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8970/">CVE-2015-8970</cve>
	<bugzilla href="https://bugzilla.suse.com/1008374">SUSE bug 1008374</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1008850">SUSE bug 1008850</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158982" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8982</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8982" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8982" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8982" ref_url="https://www.suse.com/security/cve/CVE-2015-8982" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:14923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010489.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2015-8982/">CVE-2015-8982</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193616">SUSE bug 1193616</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199869">SUSE bug 1199869</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200203">SUSE bug 1200203</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/920169">SUSE bug 920169</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/920338">SUSE bug 920338</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333938" comment="glibc is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334828" comment="glibc-locale is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009339499" comment="glibc-locale-base is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158983" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8983</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8983" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8983" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8983" ref_url="https://www.suse.com/security/cve/CVE-2015-8983" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:14923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010489.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to computing a size in bytes, which triggers a heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2015-8983/">CVE-2015-8983</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193615">SUSE bug 1193615</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199869">SUSE bug 1199869</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/920169">SUSE bug 920169</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/920338">SUSE bug 920338</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333938" comment="glibc is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334828" comment="glibc-locale is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009339499" comment="glibc-locale-base is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20158985" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-8985</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-8985" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8985" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-8985" ref_url="https://www.suse.com/security/cve/CVE-2015-8985" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:286-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010468.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:290-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2938-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2974-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010514.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012879.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3942-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013175.html" source="SUSE-SU"/>
    <description>
    The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion failure and application crash) via vectors related to extended regular expression processing.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2015-8985/">CVE-2015-8985</cve>
	<bugzilla href="https://bugzilla.suse.com/1193625">SUSE bug 1193625</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/920169">SUSE bug 920169</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/920338">SUSE bug 920338</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669024" comment="glibc-2.26-13.65.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669032" comment="glibc-locale-2.26-13.65.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669033" comment="glibc-locale-base-2.26-13.65.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20159019" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-9019</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-9019" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9019" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-9019" ref_url="https://www.suse.com/security/cve/CVE-2015-9019" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1390-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00079.html" source="SUSE-SU"/>
    <description>
    In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2015-9019/">CVE-2015-9019</cve>
	<bugzilla href="https://bugzilla.suse.com/1123130">SUSE bug 1123130</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/934119">SUSE bug 934119</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482467" comment="libxslt1-1.1.32-3.8.24 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20159251" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-9251</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-9251" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9251" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-9251" ref_url="https://www.suse.com/security/cve/CVE-2015-9251" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006630.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html" source="SUSE-SU"/>
    <description>
    jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2015-9251/">CVE-2015-9251</cve>
	<bugzilla href="https://bugzilla.suse.com/1099458">SUSE bug 1099458</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1100133">SUSE bug 1100133</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1111660">SUSE bug 1111660</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20159289" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-9289</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-9289" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9289" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-9289" ref_url="https://www.suse.com/security/cve/CVE-2015-9289" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14157-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005859.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-16"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2015-9289/">CVE-2015-9289</cve>
	<bugzilla href="https://bugzilla.suse.com/1143179">SUSE bug 1143179</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20159290" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-9290</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-9290" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9290" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-9290" ref_url="https://www.suse.com/security/cve/CVE-2015-9290" source="SUSE CVE"/>
    <description>
    In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2015-9290/">CVE-2015-9290</cve>
	<bugzilla href="https://bugzilla.suse.com/1143564">SUSE bug 1143564</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336128" comment="libfreetype6 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20159381" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-9381</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-9381" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9381" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-9381" ref_url="https://www.suse.com/security/cve/CVE-2015-9381" source="SUSE CVE"/>
    <description>
    FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2015-9381/">CVE-2015-9381</cve>
	<bugzilla href="https://bugzilla.suse.com/1149384">SUSE bug 1149384</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336128" comment="libfreetype6 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20159382" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-9382</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-9382" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9382" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-9382" ref_url="https://www.suse.com/security/cve/CVE-2015-9382" source="SUSE CVE"/>
    <description>
    FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2015-9382/">CVE-2015-9382</cve>
	<bugzilla href="https://bugzilla.suse.com/1149395">SUSE bug 1149395</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336128" comment="libfreetype6 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20159383" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2015-9383</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2015-9383" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9383" source="CVE"/>
    <reference ref_id="SUSE CVE-2015-9383" ref_url="https://www.suse.com/security/cve/CVE-2015-9383" source="SUSE CVE"/>
    <description>
    FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2015-9383/">CVE-2015-9383</cve>
	<bugzilla href="https://bugzilla.suse.com/1149397">SUSE bug 1149397</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336128" comment="libfreetype6 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160701" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0701</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0701" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0701" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0701" ref_url="https://www.suse.com/security/cve/CVE-2016-0701" source="SUSE CVE"/>
		<reference ref_id="TID7022627" ref_url="https://www.suse.com/support/kb/doc/?id=7022627" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0637-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html" source="SUSE-SU"/>
    <description>
    The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-0701/">CVE-2016-0701</cve>
	<bugzilla href="https://bugzilla.suse.com/1071906">SUSE bug 1071906</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1176331">SUSE bug 1176331</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195379">SUSE bug 1195379</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963410">SUSE bug 963410</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963413">SUSE bug 963413</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160702" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0702</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0702" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0702" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0702" ref_url="https://www.suse.com/security/cve/CVE-2016-0702" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0617-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0620-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0621-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0624-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0631-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1057-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1267-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7021744" ref_url="https://www.suse.com/support/kb/doc/?id=7021744" source="SUSE-SU"/>
		<reference ref_id="TID7021994" ref_url="https://www.suse.com/support/kb/doc/?id=7021994" source="SUSE-SU"/>
		<reference ref_id="TID7021995" ref_url="https://www.suse.com/support/kb/doc/?id=7021995" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0627-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0628-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0637-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0720-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1239-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1242-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1211-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1212-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00027.html" source="SUSE-SU"/>
    <description>
    The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and leveraging cache-bank conflicts, aka a "CacheBleed" attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-0702/">CVE-2016-0702</cve>
	<bugzilla href="https://bugzilla.suse.com/1007806">SUSE bug 1007806</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968044">SUSE bug 968044</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968050">SUSE bug 968050</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/971238">SUSE bug 971238</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990370">SUSE bug 990370</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160705" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0705</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0705" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0705" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0705" ref_url="https://www.suse.com/security/cve/CVE-2016-0705" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0617-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0620-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0621-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0624-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1057-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2839-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004658.html" source="SUSE-SU"/>
		<reference ref_id="TID7021744" ref_url="https://www.suse.com/support/kb/doc/?id=7021744" source="SUSE-SU"/>
		<reference ref_id="TID7021994" ref_url="https://www.suse.com/support/kb/doc/?id=7021994" source="SUSE-SU"/>
		<reference ref_id="TID7021995" ref_url="https://www.suse.com/support/kb/doc/?id=7021995" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0627-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0628-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0637-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1332-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00019.html" source="SUSE-SU"/>
    <description>
    Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-0705/">CVE-2016-0705</cve>
	<bugzilla href="https://bugzilla.suse.com/968044">SUSE bug 968044</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968047">SUSE bug 968047</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/971238">SUSE bug 971238</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/976341">SUSE bug 976341</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160718" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0718</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0718" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0718" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0718" ref_url="https://www.suse.com/security/cve/CVE-2016-0718" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1508-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1512-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006536.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1441-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1523-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1964-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2026-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00029.html" source="SUSE-SU"/>
    <description>
    Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-0718/">CVE-2016-0718</cve>
	<bugzilla href="https://bugzilla.suse.com/979441">SUSE bug 979441</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/991809">SUSE bug 991809</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481944" comment="libexpat1-2.2.5-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160749" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0749</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0749" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0749" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0749" ref_url="https://www.suse.com/security/cve/CVE-2016-0749" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002108.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1561-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002110.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1725-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1726-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-07/msg00004.html" source="SUSE-SU"/>
    <description>
    The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-0749/">CVE-2016-0749</cve>
	<bugzilla href="https://bugzilla.suse.com/982385">SUSE bug 982385</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/982386">SUSE bug 982386</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160755" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0755</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0755" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0755" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0755" ref_url="https://www.suse.com/security/cve/CVE-2016-0755" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0340-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-February/001852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0360-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0373-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0376-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-02/msg00047.html" source="SUSE-SU"/>
    <description>
    The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2016-0755/">CVE-2016-0755</cve>
	<bugzilla href="https://bugzilla.suse.com/962983">SUSE bug 962983</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160764" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0764</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0764" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0764" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0764" ref_url="https://www.suse.com/security/cve/CVE-2016-0764" source="SUSE CVE"/>
    <description>
    Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and keyfile changes.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-0764/">CVE-2016-0764</cve>
	<bugzilla href="https://bugzilla.suse.com/974072">SUSE bug 974072</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760817" comment="libnm0-1.22.10-3.3.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760818" comment="typelib-1_0-NM-1_0-1.22.10-3.3.4 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160772" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0772</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0772" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0772" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0772" ref_url="https://www.suse.com/security/cve/CVE-2016-0772" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002263.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002407.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1885-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-07/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2120-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00089.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-0772/">CVE-2016-0772</cve>
	<bugzilla href="https://bugzilla.suse.com/984751">SUSE bug 984751</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160777" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0777</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0777" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0777" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0777" ref_url="https://www.suse.com/security/cve/CVE-2016-0777" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0117-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0118-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0120-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="TID7017154" ref_url="https://www.suse.com/support/kb/doc?id=7017154" source="SUSE-SU"/>
		<reference ref_id="TID7017155" ref_url="https://www.suse.com/support/kb/doc?id=7017155" source="SUSE-SU"/>
		<reference ref_id="TID7017180" ref_url="https://www.suse.com/support/kb/doc/?id=7017180" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0128-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0145-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00016.html" source="SUSE-SU"/>
    <description>
    The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-0777/">CVE-2016-0777</cve>
	<bugzilla href="https://bugzilla.suse.com/961642">SUSE bug 961642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/996040">SUSE bug 996040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160778" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0778</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0778" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0778" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0778" ref_url="https://www.suse.com/security/cve/CVE-2016-0778" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0117-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0118-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0120-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="TID7017154" ref_url="https://www.suse.com/support/kb/doc?id=7017154" source="SUSE-SU"/>
		<reference ref_id="TID7017155" ref_url="https://www.suse.com/support/kb/doc?id=7017155" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0128-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0145-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-01/msg00016.html" source="SUSE-SU"/>
    <description>
    The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-0778/">CVE-2016-0778</cve>
	<bugzilla href="https://bugzilla.suse.com/961645">SUSE bug 961645</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/996040">SUSE bug 996040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160787" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0787</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0787" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0787" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0787" ref_url="https://www.suse.com/security/cve/CVE-2016-0787" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-March/001922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-March/001923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0639-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-03/msg00008.html" source="SUSE-SU"/>
    <description>
    The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-0787/">CVE-2016-0787</cve>
	<bugzilla href="https://bugzilla.suse.com/1149968">SUSE bug 1149968</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/967026">SUSE bug 967026</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968174">SUSE bug 968174</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/974691">SUSE bug 974691</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160797" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0797</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0797" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0797" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0797" ref_url="https://www.suse.com/security/cve/CVE-2016-0797" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0617-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0620-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0621-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0624-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0631-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1057-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0627-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0628-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0637-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0720-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1239-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00019.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit string that is mishandled by the (1) BN_dec2bn or (2) BN_hex2bn function, related to crypto/bn/bn.h and crypto/bn/bn_print.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-0797/">CVE-2016-0797</cve>
	<bugzilla href="https://bugzilla.suse.com/968044">SUSE bug 968044</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968048">SUSE bug 968048</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990370">SUSE bug 990370</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160798" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0798</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0798" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0798" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0798" ref_url="https://www.suse.com/security/cve/CVE-2016-0798" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0617-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0620-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0621-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0627-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0628-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0637-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html" source="SUSE-SU"/>
    <description>
    Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory consumption) by providing an invalid username in a connection attempt, related to apps/s_server.c and crypto/srp/srp_vfy.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-0798/">CVE-2016-0798</cve>
	<bugzilla href="https://bugzilla.suse.com/968044">SUSE bug 968044</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968265">SUSE bug 968265</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160800" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0800</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0800" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0800" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0800" ref_url="https://www.suse.com/security/cve/CVE-2016-0800" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0617-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0620-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0621-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0624-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0631-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0748-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1057-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7017297" ref_url="https://www.suse.com/support/kb/doc?id=7017297" source="SUSE-SU"/>
		<reference ref_id="TID7017315" ref_url="https://www.suse.com/support/kb/doc/?id=7017315" source="SUSE-SU"/>
		<reference ref_id="TID7017316" ref_url="https://www.suse.com/support/kb/doc/?id=7017316" source="SUSE-SU"/>
		<reference ref_id="TID7017317" ref_url="https://www.suse.com/support/kb/doc/?id=7017317" source="SUSE-SU"/>
		<reference ref_id="TID7017338" ref_url="https://www.suse.com/support/kb/doc/?id=7017338" source="SUSE-SU"/>
		<reference ref_id="TID7017374" ref_url="https://www.suse.com/support/kb/doc/?id=7017374" source="SUSE-SU"/>
		<reference ref_id="TID7021979" ref_url="https://www.suse.com/support/kb/doc/?id=7021979" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0627-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0628-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0637-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0720-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1239-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html" source="SUSE-SU"/>
    <description>
    The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-0800/">CVE-2016-0800</cve>
	<bugzilla href="https://bugzilla.suse.com/1106871">SUSE bug 1106871</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961377">SUSE bug 961377</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968044">SUSE bug 968044</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968046">SUSE bug 968046</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968888">SUSE bug 968888</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969591">SUSE bug 969591</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979060">SUSE bug 979060</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20160821" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-0821</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-0821" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0821" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-0821" ref_url="https://www.suse.com/security/cve/CVE-2016-0821" source="SUSE CVE"/>
    <description>
    The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison-pointer protection mechanism by triggering the use of an uninitialized list entry, aka Android internal bug 26186802, a different vulnerability than CVE-2015-3636.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-0821/">CVE-2016-0821</cve>
	<bugzilla href="https://bugzilla.suse.com/987709">SUSE bug 987709</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994624">SUSE bug 994624</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161000110" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1000110</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1000110" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1000110" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1000110" ref_url="https://www.suse.com/security/cve/CVE-2016-1000110" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002263.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002407.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2120-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00089.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2016-1000110/">CVE-2016-1000110</cve>
	<bugzilla href="https://bugzilla.suse.com/988484">SUSE bug 988484</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/989523">SUSE bug 989523</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610009" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10009</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10009" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10009" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10009" ref_url="https://www.suse.com/security/cve/CVE-2016-10009" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-January/002592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0607-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002685.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0607-3" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002972.html" source="SUSE-SU"/>
		<reference ref_id="TID7022102" ref_url="https://www.suse.com/support/kb/doc/?id=7022102" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0344-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-01/msg00178.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0674-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-03/msg00032.html" source="SUSE-SU"/>
    <description>
    Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2016-10009/">CVE-2016-10009</cve>
	<bugzilla href="https://bugzilla.suse.com/1016336">SUSE bug 1016336</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1016366">SUSE bug 1016366</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1016370">SUSE bug 1016370</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1026634">SUSE bug 1026634</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138392">SUSE bug 1138392</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1213504">SUSE bug 1213504</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610010" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10010</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10010" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10010" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10010" ref_url="https://www.suse.com/security/cve/CVE-2016-10010" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-January/002592.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0344-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-01/msg00178.html" source="SUSE-SU"/>
    <description>
    sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-07-20"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-10010/">CVE-2016-10010</cve>
	<bugzilla href="https://bugzilla.suse.com/1016336">SUSE bug 1016336</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1016368">SUSE bug 1016368</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1021751">SUSE bug 1021751</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196721">SUSE bug 1196721</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610011" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10011</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10011" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10011" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10011" ref_url="https://www.suse.com/security/cve/CVE-2016-10011" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-January/002592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0607-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002685.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0607-3" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002972.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0344-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-01/msg00178.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0674-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-03/msg00032.html" source="SUSE-SU"/>
    <description>
    authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-21"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-10011/">CVE-2016-10011</cve>
	<bugzilla href="https://bugzilla.suse.com/1016336">SUSE bug 1016336</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1016369">SUSE bug 1016369</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1016370">SUSE bug 1016370</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1017870">SUSE bug 1017870</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1026634">SUSE bug 1026634</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1029445">SUSE bug 1029445</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610012" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10012</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10012" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10012" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10012" ref_url="https://www.suse.com/security/cve/CVE-2016-10012" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-January/002592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004398.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004804.html" source="SUSE-SU"/>
		<reference ref_id="TID7022102" ref_url="https://www.suse.com/support/kb/doc/?id=7022102" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0344-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-01/msg00178.html" source="SUSE-SU"/>
    <description>
    The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-21"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-10012/">CVE-2016-10012</cve>
	<bugzilla href="https://bugzilla.suse.com/1006166">SUSE bug 1006166</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1016336">SUSE bug 1016336</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1016369">SUSE bug 1016369</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1016370">SUSE bug 1016370</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1017870">SUSE bug 1017870</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1026634">SUSE bug 1026634</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1035742">SUSE bug 1035742</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1073044">SUSE bug 1073044</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1092582">SUSE bug 1092582</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138392">SUSE bug 1138392</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610013" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10013</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10013" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10013" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10013" ref_url="https://www.suse.com/security/cve/CVE-2016-10013" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3207-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3208-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3221-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges by leveraging mishandling of SYSCALL singlestep during emulation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-10013/">CVE-2016-10013</cve>
	<bugzilla href="https://bugzilla.suse.com/1016340">SUSE bug 1016340</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610024" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10024</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10024" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10024" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10024" ref_url="https://www.suse.com/security/cve/CVE-2016-10024" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3207-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3208-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3221-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-10024/">CVE-2016-10024</cve>
	<bugzilla href="https://bugzilla.suse.com/1014298">SUSE bug 1014298</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610025" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10025</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10025" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10025" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10025" ref_url="https://www.suse.com/security/cve/CVE-2016-10025" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3208-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00001.html" source="SUSE-SU"/>
    <description>
    VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor crash) by leveraging a missing NULL pointer check.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-10025/">CVE-2016-10025</cve>
	<bugzilla href="https://bugzilla.suse.com/1014300">SUSE bug 1014300</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610028" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10028</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10028" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10028" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10028" ref_url="https://www.suse.com/security/cve/CVE-2016-10028" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    The virgl_cmd_get_capset function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a VIRTIO_GPU_CMD_GET_CAPSET command with a maximum capabilities size with a value of 0.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2016-10028/">CVE-2016-10028</cve>
	<bugzilla href="https://bugzilla.suse.com/1017084">SUSE bug 1017084</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1017085">SUSE bug 1017085</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1185981">SUSE bug 1185981</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610029" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10029</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10029" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10029" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10029" ref_url="https://www.suse.com/security/cve/CVE-2016-10029" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a scanout id in a VIRTIO_GPU_CMD_SET_SCANOUT command larger than num_scanouts.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-10029/">CVE-2016-10029</cve>
	<bugzilla href="https://bugzilla.suse.com/1017081">SUSE bug 1017081</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1017082">SUSE bug 1017082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610044" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10044</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10044" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10044" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10044" ref_url="https://www.suse.com/security/cve/CVE-2016-10044" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-10044/">CVE-2016-10044</cve>
	<bugzilla href="https://bugzilla.suse.com/1023992">SUSE bug 1023992</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610087" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10087</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10087" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10087" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10087" ref_url="https://www.suse.com/security/cve/CVE-2016-10087" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0860-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0901-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002787.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0937-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0942-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1037-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00063.html" source="SUSE-SU"/>
    <description>
    The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text chunk into a png structure, removing the text, and then adding another text chunk to the structure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-10087/">CVE-2016-10087</cve>
	<bugzilla href="https://bugzilla.suse.com/1017646">SUSE bug 1017646</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1149680">SUSE bug 1149680</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482352" comment="libpng16-16-1.6.34-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610147" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10147</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10147" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10147" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10147" ref_url="https://www.suse.com/security/cve/CVE-2016-10147" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2017:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00022.html" source="SUSE-SU"/>
    <description>
    crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an AF_ALG socket with an incompatible algorithm, as demonstrated by mcryptd(md5).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-10147/">CVE-2016-10147</cve>
	<bugzilla href="https://bugzilla.suse.com/1020381">SUSE bug 1020381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1020429">SUSE bug 1020429</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10155" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10155" ref_url="https://www.suse.com/security/cve/CVE-2016-10155" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0661-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1135-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-10155/">CVE-2016-10155</cve>
	<bugzilla href="https://bugzilla.suse.com/1021129">SUSE bug 1021129</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024183">SUSE bug 1024183</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610156" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10156</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10156" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10156" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10156" ref_url="https://www.suse.com/security/cve/CVE-2016-10156" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0279-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0287-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00058.html" source="SUSE-SU"/>
    <description>
    A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-10156/">CVE-2016-10156</cve>
	<bugzilla href="https://bugzilla.suse.com/1020601">SUSE bug 1020601</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1021969">SUSE bug 1021969</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1086936">SUSE bug 1086936</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610198" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10198</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10198" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10198" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10198" ref_url="https://www.suse.com/security/cve/CVE-2016-10198" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1004-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1010-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002801.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1066-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1076-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00081.html" source="SUSE-SU"/>
    <description>
    The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted audio file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-10198/">CVE-2016-10198</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024014">SUSE bug 1024014</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610199" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10199</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10199" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10199" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10199" ref_url="https://www.suse.com/security/cve/CVE-2016-10199" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1004-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1010-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002801.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1066-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1076-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00081.html" source="SUSE-SU"/>
    <description>
    The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-10199/">CVE-2016-10199</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024017">SUSE bug 1024017</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610208" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10208</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10208" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10208" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10208" ref_url="https://www.suse.com/security/cve/CVE-2016-10208" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0906-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00000.html" source="SUSE-SU"/>
    <description>
    The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-10208/">CVE-2016-10208</cve>
	<bugzilla href="https://bugzilla.suse.com/1023377">SUSE bug 1023377</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610214" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10214</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10214" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10214" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10214" ref_url="https://www.suse.com/security/cve/CVE-2016-10214" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002738.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0902-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-03/msg00119.html" source="SUSE-SU"/>
    <description>
    Memory leak in the virgl_resource_attach_backing function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-10214/">CVE-2016-10214</cve>
	<bugzilla href="https://bugzilla.suse.com/1024244">SUSE bug 1024244</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009488549" comment="libvirglrenderer0-0.6.0-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610228" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10228</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10228" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10228" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10228" ref_url="https://www.suse.com/security/cve/CVE-2016-10228" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:547-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2886-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011984.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1560-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4LDTHO3OJZ2XD7I3ONIRIUSKEMP42OY2/" source="SUSE-SU"/>
    <description>
    The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-10228/">CVE-2016-10228</cve>
	<bugzilla href="https://bugzilla.suse.com/1027496">SUSE bug 1027496</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704997" comment="glibc-2.26-13.62.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704998" comment="glibc-locale-2.26-13.62.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704999" comment="glibc-locale-base-2.26-13.62.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610739" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10739</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10739" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10739" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10739" ref_url="https://www.suse.com/security/cve/CVE-2016-10739" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0903-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190903-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013417.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1250-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00082.html" source="SUSE-SU"/>
    <description>
    In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.5/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2016-10739/">CVE-2016-10739</cve>
	<bugzilla href="https://bugzilla.suse.com/1122729">SUSE bug 1122729</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1155094">SUSE bug 1155094</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610741" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10741</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10741" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10741" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10741" ref_url="https://www.suse.com/security/cve/CVE-2016-10741" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13979-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005194.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of an I/O failure.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2016-10741/">CVE-2016-10741</cve>
	<bugzilla href="https://bugzilla.suse.com/1114920">SUSE bug 1114920</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1124010">SUSE bug 1124010</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610745" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10745</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10745" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10745" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10745" ref_url="https://www.suse.com/security/cve/CVE-2016-10745" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005488.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3896-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008099.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1614-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.7/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" href="https://www.suse.com/security/cve/CVE-2016-10745/">CVE-2016-10745</cve>
	<bugzilla href="https://bugzilla.suse.com/1132174">SUSE bug 1132174</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481633" comment="python3-Jinja2-2.10.1-3.5.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610746" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10746</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10746" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10746" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10746" ref_url="https://www.suse.com/security/cve/CVE-2016-10746" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005815.html" source="SUSE-SU"/>
    <description>
    libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-10746/">CVE-2016-10746</cve>
	<bugzilla href="https://bugzilla.suse.com/1133150">SUSE bug 1133150</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334933" comment="libvirt-daemon is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334936" comment="libvirt-daemon-driver-interface is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334939" comment="libvirt-daemon-driver-network is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334940" comment="libvirt-daemon-driver-nodedev is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334941" comment="libvirt-daemon-driver-nwfilter is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334942" comment="libvirt-daemon-driver-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334943" comment="libvirt-daemon-driver-secret is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334944" comment="libvirt-daemon-driver-storage is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336191" comment="libvirt-daemon-driver-storage-core is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336192" comment="libvirt-daemon-driver-storage-disk is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336193" comment="libvirt-daemon-driver-storage-iscsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336194" comment="libvirt-daemon-driver-storage-logical is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336195" comment="libvirt-daemon-driver-storage-mpath is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336196" comment="libvirt-daemon-driver-storage-rbd is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336197" comment="libvirt-daemon-driver-storage-scsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334946" comment="libvirt-daemon-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336198" comment="libvirt-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610905" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10905</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10905" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10905" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10905" ref_url="https://www.suse.com/security/cve/CVE-2016-10905" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010390.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-10905/">CVE-2016-10905</cve>
	<bugzilla href="https://bugzilla.suse.com/1146312">SUSE bug 1146312</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610906" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10906</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10906" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10906" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10906" ref_url="https://www.suse.com/security/cve/CVE-2016-10906" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caused by a race condition between the functions arc_emac_tx and arc_emac_tx_clean.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-10906/">CVE-2016-10906</cve>
	<bugzilla href="https://bugzilla.suse.com/1146584">SUSE bug 1146584</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201610907" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-10907</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-10907" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10907" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-10907" ref_url="https://www.suse.com/security/cve/CVE-2016-10907" source="SUSE CVE"/>
    <description>
    An issue was discovered in drivers/iio/dac/ad5755.c in the Linux kernel before 4.8.6. There is an out of bounds write in the function ad5755_parse_dt.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-10907/">CVE-2016-10907</cve>
	<bugzilla href="https://bugzilla.suse.com/1146302">SUSE bug 1146302</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161234" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1234</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1234" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1234" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1234" ref_url="https://www.suse.com/security/cve/CVE-2016-1234" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-July/002147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1527-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1779-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-1234/">CVE-2016-1234</cve>
	<bugzilla href="https://bugzilla.suse.com/1020940">SUSE bug 1020940</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969727">SUSE bug 969727</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/988770">SUSE bug 988770</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/988782">SUSE bug 988782</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/989127">SUSE bug 989127</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161237" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1237</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1237" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1237" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1237" ref_url="https://www.suse.com/security/cve/CVE-2016-1237" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2016:2290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00048.html" source="SUSE-SU"/>
    <description>
    nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-13"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-1237/">CVE-2016-1237</cve>
	<bugzilla href="https://bugzilla.suse.com/986570">SUSE bug 986570</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161238" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1238</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1238" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1238" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1238" ref_url="https://www.suse.com/security/cve/CVE-2016-1238" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002262.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005159.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1961-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2011-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192011-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2313-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0297-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1831-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/json_pp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1238/">CVE-2016-1238</cve>
	<bugzilla href="https://bugzilla.suse.com/1108749">SUSE bug 1108749</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123389">SUSE bug 1123389</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/987887">SUSE bug 987887</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/988311">SUSE bug 988311</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334114" comment="perl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336057" comment="perl-base is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161283" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1283</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1283" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1283" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1283" ref_url="https://www.suse.com/security/cve/CVE-2016-1283" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3161-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002488.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2805-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3099-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00076.html" source="SUSE-SU"/>
    <description>
    The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'&lt;((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgroups, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1283/">CVE-2016-1283</cve>
	<bugzilla href="https://bugzilla.suse.com/960837">SUSE bug 960837</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480657" comment="libpcre1-8.41-4.20 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161521" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1521</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1521" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1521" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1521" ref_url="https://www.suse.com/security/cve/CVE-2016-1521" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0779-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0791-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0875-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00088.html" source="SUSE-SU"/>
    <description>
    The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1521/">CVE-2016-1521</cve>
	<bugzilla href="https://bugzilla.suse.com/965803">SUSE bug 965803</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/965806">SUSE bug 965806</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/965807">SUSE bug 965807</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/965810">SUSE bug 965810</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480302" comment="libgraphite2-3-1.3.11-2.12 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161544" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1544</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1544" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1544" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1544" ref_url="https://www.suse.com/security/cve/CVE-2016-1544" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008541.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0675-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-03/msg00029.html" source="SUSE-SU"/>
    <description>
    nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-1544/">CVE-2016-1544</cve>
	<bugzilla href="https://bugzilla.suse.com/966514">SUSE bug 966514</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482322" comment="libnghttp2-14-1.40.0-1.15 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161567" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1567</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1567" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1567" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1567" ref_url="https://www.suse.com/security/cve/CVE-2016-1567" source="SUSE CVE"/>
    <description>
    chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-04"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1567/">CVE-2016-1567</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628349" comment="chrony-3.2-9.18.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628351" comment="chrony-pool-suse-3.2-9.18.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161568" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1568</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1568" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1568" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1568" ref_url="https://www.suse.com/security/cve/CVE-2016-1568" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1568/">CVE-2016-1568</cve>
	<bugzilla href="https://bugzilla.suse.com/961332">SUSE bug 961332</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961333">SUSE bug 961333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161570" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1570</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1570" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1570" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1570" ref_url="https://www.suse.com/security/cve/CVE-2016-1570" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other impact via a crafted page identifier (MFN) to the (1) MMUEXT_MARK_SUPER or (2) MMUEXT_UNMARK_SUPER sub-op in the HYPERVISOR_mmuext_op hypercall or (3) unknown vectors related to page table updates.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.5/CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1570/">CVE-2016-1570</cve>
	<bugzilla href="https://bugzilla.suse.com/960861">SUSE bug 960861</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161571" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1571</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1571" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1571" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1571" ref_url="https://www.suse.com/security/cve/CVE-2016-1571" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.3/CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-1571/">CVE-2016-1571</cve>
	<bugzilla href="https://bugzilla.suse.com/960861">SUSE bug 960861</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/960862">SUSE bug 960862</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161575" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1575</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1575" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1575" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1575" ref_url="https://www.suse.com/security/cve/CVE-2016-1575" source="SUSE CVE"/>
    <description>
    The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1575/">CVE-2016-1575</cve>
	<bugzilla href="https://bugzilla.suse.com/968092">SUSE bug 968092</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161583" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1583</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1583" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1583" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1583" ref_url="https://www.suse.com/security/cve/CVE-2016-1583" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1596-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1961-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1994-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2000-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2002-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2006-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2009-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2014-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2105-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="TID7017678" ref_url="https://www.suse.com/support/kb/doc/?id=7017678" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html" source="SUSE-SU"/>
    <description>
    The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1583/">CVE-2016-1583</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1052256">SUSE bug 1052256</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983143">SUSE bug 983143</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983144">SUSE bug 983144</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161714" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1714</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1714" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1714" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1714" ref_url="https://www.suse.com/security/cve/CVE-2016-1714" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
    <description>
    The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to cause a denial of service (out-of-bounds read or write access and process crash) or possibly execute arbitrary code via an invalid current entry value in a firmware configuration.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.1/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1714/">CVE-2016-1714</cve>
	<bugzilla href="https://bugzilla.suse.com/961691">SUSE bug 961691</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961692">SUSE bug 961692</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161762" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1762</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1762" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1762" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1762" ref_url="https://www.suse.com/security/cve/CVE-2016-1762" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1538-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1604-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1595-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00026.html" source="SUSE-SU"/>
    <description>
    The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-1762/">CVE-2016-1762</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981040">SUSE bug 981040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161833" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1833</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1833" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1833" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1833" ref_url="https://www.suse.com/security/cve/CVE-2016-1833" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1538-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1604-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1595-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00026.html" source="SUSE-SU"/>
    <description>
    The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1833/">CVE-2016-1833</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981108">SUSE bug 981108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161834" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1834</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1834" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1834" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1834" ref_url="https://www.suse.com/security/cve/CVE-2016-1834" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1538-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1604-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1595-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00026.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1834/">CVE-2016-1834</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981041">SUSE bug 981041</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161835" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1835</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1835" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1835" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1835" ref_url="https://www.suse.com/security/cve/CVE-2016-1835" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1538-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1604-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1595-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00026.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the xmlSAX2AttributeNs function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2 and OS X before 10.11.5, allows remote attackers to cause a denial of service via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1835/">CVE-2016-1835</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981109">SUSE bug 981109</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161836" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1836</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1836" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1836" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1836" ref_url="https://www.suse.com/security/cve/CVE-2016-1836" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1836/">CVE-2016-1836</cve>
	<bugzilla href="https://bugzilla.suse.com/1174862">SUSE bug 1174862</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981110">SUSE bug 981110</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161837" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1837</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1837" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1837" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1837" ref_url="https://www.suse.com/security/cve/CVE-2016-1837" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1538-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1604-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1595-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00026.html" source="SUSE-SU"/>
    <description>
    Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remote attackers to cause a denial of service via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1837/">CVE-2016-1837</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981111">SUSE bug 981111</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161838" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1838</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1838" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1838" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1838" ref_url="https://www.suse.com/security/cve/CVE-2016-1838" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1538-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1604-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1595-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00026.html" source="SUSE-SU"/>
    <description>
    The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1838/">CVE-2016-1838</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981112">SUSE bug 981112</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161839" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1839</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1839" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1839" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1839" ref_url="https://www.suse.com/security/cve/CVE-2016-1839" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1538-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1604-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1454-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1595-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1510-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-06/msg00022.html" source="SUSE-SU"/>
    <description>
    The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-1839/">CVE-2016-1839</cve>
	<bugzilla href="https://bugzilla.suse.com/1039069">SUSE bug 1039069</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039661">SUSE bug 1039661</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1069433">SUSE bug 1069433</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1069690">SUSE bug 1069690</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963963">SUSE bug 963963</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981114">SUSE bug 981114</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161840" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1840</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1840" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1840" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1840" ref_url="https://www.suse.com/security/cve/CVE-2016-1840" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1538-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1604-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1595-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00026.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1840/">CVE-2016-1840</cve>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981115">SUSE bug 981115</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161866" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1866</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1866" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1866" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1866" ref_url="https://www.suse.com/security/cve/CVE-2016-1866" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:14402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0694-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-03/msg00034.html" source="SUSE-SU"/>
    <description>
    Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1866/">CVE-2016-1866</cve>
	<bugzilla href="https://bugzilla.suse.com/965403">SUSE bug 965403</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161922" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1922</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1922" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1922" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1922" ref_url="https://www.suse.com/security/cve/CVE-2016-1922" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference flaw. It occurs while doing I/O port write operations via hmp interface. In that, 'current_cpu' remains null, which leads to the null pointer dereference. A user or process could use this flaw to crash the QEMU instance, resulting in DoS issue.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-1922/">CVE-2016-1922</cve>
	<bugzilla href="https://bugzilla.suse.com/962320">SUSE bug 962320</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/962321">SUSE bug 962321</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161950" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1950</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1950" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1950" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1950" ref_url="https://www.suse.com/security/cve/CVE-2016-1950" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0727-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0777-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1175-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1248-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0731-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0733-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1557-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00016.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1950/">CVE-2016-1950</cve>
	<bugzilla href="https://bugzilla.suse.com/969894">SUSE bug 969894</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/970257">SUSE bug 970257</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/970377">SUSE bug 970377</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/970378">SUSE bug 970378</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/970379">SUSE bug 970379</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/970380">SUSE bug 970380</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/970381">SUSE bug 970381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/970431">SUSE bug 970431</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/970433">SUSE bug 970433</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161979" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1979</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1979" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1979" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1979" ref_url="https://www.suse.com/security/cve/CVE-2016-1979" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0727-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0777-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0731-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0733-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-1979/">CVE-2016-1979</cve>
	<bugzilla href="https://bugzilla.suse.com/969894">SUSE bug 969894</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20161981" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-1981</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-1981" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1981" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-1981" ref_url="https://www.suse.com/security/cve/CVE-2016-1981" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is set outside the allocated descriptor buffer. A privileged user inside guest could use this flaw to crash the QEMU instance resulting in DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-1981/">CVE-2016-1981</cve>
	<bugzilla href="https://bugzilla.suse.com/963782">SUSE bug 963782</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963783">SUSE bug 963783</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162037" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2037</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2037" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2037" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2037" ref_url="https://www.suse.com/security/cve/CVE-2016-2037" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0366-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0389-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00026.html" source="SUSE-SU"/>
    <description>
    The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-2037/">CVE-2016-2037</cve>
	<bugzilla href="https://bugzilla.suse.com/1028410">SUSE bug 1028410</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/963448">SUSE bug 963448</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481843" comment="cpio-2.12-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162105" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2105</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2105" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2105" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2105" ref_url="https://www.suse.com/security/cve/CVE-2016-2105" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1228-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1231-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1267-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="TID7017583" ref_url="https://www.suse.com/support/kb/doc/?id=7017583" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1237-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1238-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1239-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1240-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1242-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1243-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2769-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2788-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00027.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2105/">CVE-2016-2105</cve>
	<bugzilla href="https://bugzilla.suse.com/977584">SUSE bug 977584</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/977614">SUSE bug 977614</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978492">SUSE bug 978492</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/989902">SUSE bug 989902</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990369">SUSE bug 990369</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990370">SUSE bug 990370</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162106" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2106</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2106" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2106" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2106" ref_url="https://www.suse.com/security/cve/CVE-2016-2106" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1228-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1231-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1267-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="TID7017583" ref_url="https://www.suse.com/support/kb/doc/?id=7017583" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1237-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1238-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1239-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1240-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1242-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1243-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00030.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2106/">CVE-2016-2106</cve>
	<bugzilla href="https://bugzilla.suse.com/977584">SUSE bug 977584</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/977615">SUSE bug 977615</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978492">SUSE bug 978492</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979279">SUSE bug 979279</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990369">SUSE bug 990369</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162107" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2107</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2107" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2107" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2107" ref_url="https://www.suse.com/security/cve/CVE-2016-2107" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1228-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="TID7017583" ref_url="https://www.suse.com/support/kb/doc/?id=7017583" source="SUSE-SU"/>
		<reference ref_id="TID7017793" ref_url="https://www.suse.com/support/kb/doc/?id=7017793" source="SUSE-SU"/>
		<reference ref_id="TID7017881" ref_url="https://www.suse.com/support/kb/doc/?id=7017881" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1237-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1238-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1240-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1243-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1566-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00019.html" source="SUSE-SU"/>
    <description>
    The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-2107/">CVE-2016-2107</cve>
	<bugzilla href="https://bugzilla.suse.com/976942">SUSE bug 976942</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/977584">SUSE bug 977584</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/977616">SUSE bug 977616</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978492">SUSE bug 978492</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990369">SUSE bug 990369</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990370">SUSE bug 990370</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162109" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2109</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2109" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2109" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2109" ref_url="https://www.suse.com/security/cve/CVE-2016-2109" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1228-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1231-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1267-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="TID7017583" ref_url="https://www.suse.com/support/kb/doc/?id=7017583" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1237-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1238-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1239-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1240-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1242-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1243-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00030.html" source="SUSE-SU"/>
    <description>
    The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2109/">CVE-2016-2109</cve>
	<bugzilla href="https://bugzilla.suse.com/1015243">SUSE bug 1015243</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/976942">SUSE bug 976942</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/977584">SUSE bug 977584</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978492">SUSE bug 978492</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990369">SUSE bug 990369</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162150" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2150</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2150" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2150" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2150" ref_url="https://www.suse.com/security/cve/CVE-2016-2150" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002108.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1561-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008966.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1725-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1726-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-07/msg00004.html" source="SUSE-SU"/>
    <description>
    SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-2150/">CVE-2016-2150</cve>
	<bugzilla href="https://bugzilla.suse.com/982385">SUSE bug 982385</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/982386">SUSE bug 982386</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162176" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2176</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2176" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2176" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2176" ref_url="https://www.suse.com/security/cve/CVE-2016-2176" source="SUSE CVE"/>
		<reference ref_id="TID7017583" ref_url="https://www.suse.com/support/kb/doc/?id=7017583" source="SUSE-SU"/>
    <description>
    The X509_NAME_oneline function in crypto/x509/x509_obj.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to obtain sensitive information from process stack memory or cause a denial of service (buffer over-read) via crafted EBCDIC ASN.1 data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2176/">CVE-2016-2176</cve>
	<bugzilla href="https://bugzilla.suse.com/978224">SUSE bug 978224</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990369">SUSE bug 990369</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162177" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2177</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2177" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2177" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2177" ref_url="https://www.suse.com/security/cve/CVE-2016-2177" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2469-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2177/">CVE-2016-2177</cve>
	<bugzilla href="https://bugzilla.suse.com/982575">SUSE bug 982575</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999075">SUSE bug 999075</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999665">SUSE bug 999665</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162178" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2178</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2178" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2178" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2178" ref_url="https://www.suse.com/security/cve/CVE-2016-2178" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2469-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2470-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2496-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-2178/">CVE-2016-2178</cve>
	<bugzilla href="https://bugzilla.suse.com/1004104">SUSE bug 1004104</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983249">SUSE bug 983249</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983519">SUSE bug 983519</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999665">SUSE bug 999665</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162179" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2179</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2179" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2179" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2179" ref_url="https://www.suse.com/security/cve/CVE-2016-2179" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2469-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial of service (memory consumption) by maintaining many crafted DTLS sessions simultaneously, related to d1_lib.c, statem_dtls.c, statem_lib.c, and statem_srvr.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2179/">CVE-2016-2179</cve>
	<bugzilla href="https://bugzilla.suse.com/1004104">SUSE bug 1004104</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994844">SUSE bug 994844</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999665">SUSE bug 999665</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162180" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2180</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2180" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2180" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2180" ref_url="https://www.suse.com/security/cve/CVE-2016-2180" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2469-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted time-stamp file that is mishandled by the "openssl ts" command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2180/">CVE-2016-2180</cve>
	<bugzilla href="https://bugzilla.suse.com/1003811">SUSE bug 1003811</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990419">SUSE bug 990419</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999665">SUSE bug 999665</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162181" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2181</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2181" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2181" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2181" ref_url="https://www.suse.com/security/cve/CVE-2016-2181" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2469-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cause a denial of service (false-positive packet drops) via spoofed DTLS records, related to rec_layer_d1.c and ssl3_record.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2181/">CVE-2016-2181</cve>
	<bugzilla href="https://bugzilla.suse.com/1004104">SUSE bug 1004104</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994749">SUSE bug 994749</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994844">SUSE bug 994844</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999665">SUSE bug 999665</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162182" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2182</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2182" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2182" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2182" ref_url="https://www.suse.com/security/cve/CVE-2016-2182" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2469-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-2182/">CVE-2016-2182</cve>
	<bugzilla href="https://bugzilla.suse.com/1004104">SUSE bug 1004104</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/993819">SUSE bug 993819</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994844">SUSE bug 994844</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/995959">SUSE bug 995959</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999665">SUSE bug 999665</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162183" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2183</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2183" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2183" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2183" ref_url="https://www.suse.com/security/cve/CVE-2016-2183" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2469-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2470-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0346-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0460-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0490-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002706.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0720-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002707.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0726-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002914.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1444-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7017985" ref_url="https://www.suse.com/support/kb/doc/?id=7017985" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="TID7020150" ref_url="https://www.suse.com/support/kb/doc/?id=7020150" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2496-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0374-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-2183/">CVE-2016-2183</cve>
	<bugzilla href="https://bugzilla.suse.com/1001912">SUSE bug 1001912</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024218">SUSE bug 1024218</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1027038">SUSE bug 1027038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1034689">SUSE bug 1034689</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1056614">SUSE bug 1056614</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1171693">SUSE bug 1171693</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994844">SUSE bug 994844</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/995359">SUSE bug 995359</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162187" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2187</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2187" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2187" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2187" ref_url="https://www.suse.com/security/cve/CVE-2016-2187" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
    <description>
    The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2187/">CVE-2016-2187</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/971919">SUSE bug 971919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/971944">SUSE bug 971944</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162198" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2198</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2198" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2198" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2198" ref_url="https://www.suse.com/security/cve/CVE-2016-2198" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this flaw to crash the QEMU process instance resulting in DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2198/">CVE-2016-2198</cve>
	<bugzilla href="https://bugzilla.suse.com/964413">SUSE bug 964413</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/964415">SUSE bug 964415</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162270" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2270</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2270" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2270" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2270" ref_url="https://www.suse.com/security/cve/CVE-2016-2270" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1445-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.8/CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2270/">CVE-2016-2270</cve>
	<bugzilla href="https://bugzilla.suse.com/965315">SUSE bug 965315</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162271" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2271</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2271" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2271" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2271" ref_url="https://www.suse.com/security/cve/CVE-2016-2271" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1445-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
    <description>
    VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2271/">CVE-2016-2271</cve>
	<bugzilla href="https://bugzilla.suse.com/965317">SUSE bug 965317</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162384" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2384</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2384" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2384" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2384" ref_url="https://www.suse.com/security/cve/CVE-2016-2384" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0911-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1019-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1031-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1032-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1033-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1034-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1035-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1037-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1038-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1039-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1041-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1045-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1046-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1764-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an invalid USB descriptor.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2384/">CVE-2016-2384</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/966693">SUSE bug 966693</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/967773">SUSE bug 967773</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162391" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2391</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2391" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2391" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2391" ref_url="https://www.suse.com/security/cve/CVE-2016-2391" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1445-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2391/">CVE-2016-2391</cve>
	<bugzilla href="https://bugzilla.suse.com/967012">SUSE bug 967012</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/967013">SUSE bug 967013</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/967101">SUSE bug 967101</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162392" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2392</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2392" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2392" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2392" ref_url="https://www.suse.com/security/cve/CVE-2016-2392" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving a remote NDIS control message packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2392/">CVE-2016-2392</cve>
	<bugzilla href="https://bugzilla.suse.com/967012">SUSE bug 967012</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/967090">SUSE bug 967090</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162538" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2538</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2538" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2538" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2538" ref_url="https://www.suse.com/security/cve/CVE-2016-2538" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain sensitive host memory information via a remote NDIS control message packet that is mishandled in the (1) rndis_query_response, (2) rndis_set_response, or (3) usb_net_handle_dataout function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2538/">CVE-2016-2538</cve>
	<bugzilla href="https://bugzilla.suse.com/967969">SUSE bug 967969</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968004">SUSE bug 968004</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162779" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2779</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2779" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2779" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2779" ref_url="https://www.suse.com/security/cve/CVE-2016-2779" source="SUSE CVE"/>
    <description>
    runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.6/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-2779/">CVE-2016-2779</cve>
	<bugzilla href="https://bugzilla.suse.com/1000998">SUSE bug 1000998</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1018892">SUSE bug 1018892</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/946429">SUSE bug 946429</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968375">SUSE bug 968375</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968674">SUSE bug 968674</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968675">SUSE bug 968675</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760806" comment="libblkid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760807" comment="libfdisk1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760808" comment="libmount1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760809" comment="libsmartcols1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760810" comment="libuuid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760811" comment="util-linux-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760812" comment="util-linux-systemd-2.33.1-4.13.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162782" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2782</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2782" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2782" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2782" ref_url="https://www.suse.com/security/cve/CVE-2016-2782" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1019-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1690-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1764-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2782/">CVE-2016-2782</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/961512">SUSE bug 961512</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968670">SUSE bug 968670</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162834" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2834</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2834" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2834" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2834" ref_url="https://www.suse.com/security/cve/CVE-2016-2834" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1691-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1799-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2061-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1175-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1248-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1552-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1557-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00016.html" source="SUSE-SU"/>
    <description>
    Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-2834/">CVE-2016-2834</cve>
	<bugzilla href="https://bugzilla.suse.com/983549">SUSE bug 983549</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983639">SUSE bug 983639</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20162841" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-2841</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-2841" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2841" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-2841" ref_url="https://www.suse.com/security/cve/CVE-2016-2841" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-03/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1445-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
    <description>
    The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP registers, involving ring buffer control.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-2841/">CVE-2016-2841</cve>
	<bugzilla href="https://bugzilla.suse.com/969350">SUSE bug 969350</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/969351">SUSE bug 969351</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163044" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3044</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3044" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3044" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3044" ref_url="https://www.suse.com/security/cve/CVE-2016-3044" source="SUSE CVE"/>
    <description>
    The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host OS infinite loop and hang) via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-3044/">CVE-2016-3044</cve>
	<bugzilla href="https://bugzilla.suse.com/1013013">SUSE bug 1013013</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163070" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3070</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3070" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3070" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3070" ref_url="https://www.suse.com/security/cve/CVE-2016-3070" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by triggering a certain page move.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-3070/">CVE-2016-3070</cve>
	<bugzilla href="https://bugzilla.suse.com/979215">SUSE bug 979215</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163075" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3075</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3075" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3075" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3075" ref_url="https://www.suse.com/security/cve/CVE-2016-3075" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-July/002147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1527-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1779-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-3075/">CVE-2016-3075</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/973164">SUSE bug 973164</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163115" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3115</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3115" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3115" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3115" ref_url="https://www.suse.com/security/cve/CVE-2016-3115" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-May/002080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002338.html" source="SUSE-SU"/>
		<reference ref_id="TID7022102" ref_url="https://www.suse.com/support/kb/doc/?id=7022102" source="SUSE-SU"/>
		<reference ref_id="TID7022313" ref_url="https://www.suse.com/support/kb/doc/?id=7022313" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1455-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-05/msg00132.html" source="SUSE-SU"/>
    <description>
    Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2016-3115/">CVE-2016-3115</cve>
	<bugzilla href="https://bugzilla.suse.com/1005738">SUSE bug 1005738</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1059233">SUSE bug 1059233</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138392">SUSE bug 1138392</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/970632">SUSE bug 970632</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/992296">SUSE bug 992296</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/992991">SUSE bug 992991</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/996040">SUSE bug 996040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333996" comment="openssh is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163119" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3119</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3119" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3119" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3119" ref_url="https://www.suse.com/security/cve/CVE-2016-3119" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:0994-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-April/001993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-April/002016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1072-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-04/msg00055.html" source="SUSE-SU"/>
    <description>
    The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request to modify a principal.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-3119/">CVE-2016-3119</cve>
	<bugzilla href="https://bugzilla.suse.com/971942">SUSE bug 971942</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163120" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3120</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3120" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3120" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3120" ref_url="https://www.suse.com/security/cve/CVE-2016-3120" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2136-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002222.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2268-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00035.html" source="SUSE-SU"/>
    <description>
    The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_tgt is enabled, uses an incorrect client data structure, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an S4U2Self request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-3120/">CVE-2016-3120</cve>
	<bugzilla href="https://bugzilla.suse.com/991088">SUSE bug 991088</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163134" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3134</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3134" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3134" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3134" ref_url="https://www.suse.com/security/cve/CVE-2016-3134" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1690-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1764-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1961-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1994-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2000-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2001-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2002-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2006-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2009-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2014-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-3134/">CVE-2016-3134</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1052256">SUSE bug 1052256</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/971126">SUSE bug 971126</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/971793">SUSE bug 971793</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986362">SUSE bug 986362</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986365">SUSE bug 986365</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986377">SUSE bug 986377</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163139" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3139</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3139" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3139" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3139" ref_url="https://www.suse.com/security/cve/CVE-2016-3139" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1019-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-04/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1690-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1764-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2649-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00063.html" source="SUSE-SU"/>
    <description>
    The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-11"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-3139/">CVE-2016-3139</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/970909">SUSE bug 970909</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163189" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3189</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3189" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3189" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3189" ref_url="https://www.suse.com/security/cve/CVE-2016-3189" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1206-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005739.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1435-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00056.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-3189/">CVE-2016-3189</cve>
	<bugzilla href="https://bugzilla.suse.com/985657">SUSE bug 985657</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481775" comment="libbz2-1-1.0.6-5.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163191" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3191</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3191" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3191" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3191" ref_url="https://www.suse.com/security/cve/CVE-2016-3191" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3161-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002488.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2035-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2805-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3099-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00076.html" source="SUSE-SU"/>
    <description>
    The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parentheses, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, aka ZDI-CAN-3542.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-3191/">CVE-2016-3191</cve>
	<bugzilla href="https://bugzilla.suse.com/971741">SUSE bug 971741</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009480657" comment="libpcre1-8.41-4.20 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480667" comment="libpcre2-8-0-10.31-1.14 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163627" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3627</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3627" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3627" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3627" ref_url="https://www.suse.com/security/cve/CVE-2016-3627" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-May/002036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-May/002037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1298-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-05/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1446-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-05/msg00127.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
    <description>
    The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-3627/">CVE-2016-3627</cve>
	<bugzilla href="https://bugzilla.suse.com/1026099">SUSE bug 1026099</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1026101">SUSE bug 1026101</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/972335">SUSE bug 972335</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/975947">SUSE bug 975947</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163697" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3697</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3697" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3697" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3697" ref_url="https://www.suse.com/security/cve/CVE-2016-3697" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-April/002030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1417-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-05/msg00111.html" source="SUSE-SU"/>
    <description>
    libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-3697/">CVE-2016-3697</cve>
	<bugzilla href="https://bugzilla.suse.com/976777">SUSE bug 976777</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163705" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3705</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3705" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3705" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3705" ref_url="https://www.suse.com/security/cve/CVE-2016-3705" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1538-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1604-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1446-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-05/msg00127.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1595-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00026.html" source="SUSE-SU"/>
    <description>
    The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-09-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-3705/">CVE-2016-3705</cve>
	<bugzilla href="https://bugzilla.suse.com/1017497">SUSE bug 1017497</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/975947">SUSE bug 975947</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163706" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3706</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3706" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3706" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3706" ref_url="https://www.suse.com/security/cve/CVE-2016-3706" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-July/002147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1527-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1779-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-3706/">CVE-2016-3706</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980483">SUSE bug 980483</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/997423">SUSE bug 997423</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163710" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3710</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3710" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3710" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3710" ref_url="https://www.suse.com/security/cve/CVE-2016-3710" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-3710/">CVE-2016-3710</cve>
	<bugzilla href="https://bugzilla.suse.com/978158">SUSE bug 978158</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978164">SUSE bug 978164</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978167">SUSE bug 978167</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163712" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3712</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3712" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3712" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3712" ref_url="https://www.suse.com/security/cve/CVE-2016-3712" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-3712/">CVE-2016-3712</cve>
	<bugzilla href="https://bugzilla.suse.com/978160">SUSE bug 978160</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978164">SUSE bug 978164</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978167">SUSE bug 978167</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163841" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3841</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3841" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3841" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3841" ref_url="https://www.suse.com/security/cve/CVE-2016-3841" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2976-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3069-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
    <description>
    The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-3841/">CVE-2016-3841</cve>
	<bugzilla href="https://bugzilla.suse.com/1052256">SUSE bug 1052256</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/992566">SUSE bug 992566</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/992569">SUSE bug 992569</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20163951" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-3951</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-3951" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3951" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-3951" ref_url="https://www.suse.com/security/cve/CVE-2016-3951" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1690-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1764-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-05/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
    <description>
    Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-3951/">CVE-2016-3951</cve>
	<bugzilla href="https://bugzilla.suse.com/974418">SUSE bug 974418</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164002" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4002</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4002" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4002" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4002" ref_url="https://www.suse.com/security/cve/CVE-2016-4002" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of service (memory corruption and QEMU crash) or possibly execute arbitrary code via a packet larger than 1514 bytes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-4002/">CVE-2016-4002</cve>
	<bugzilla href="https://bugzilla.suse.com/975136">SUSE bug 975136</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/975138">SUSE bug 975138</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164008" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4008</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4008" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4008" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4008" ref_url="https://www.suse.com/security/cve/CVE-2016-4008" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1567-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1674-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00097.html" source="SUSE-SU"/>
    <description>
    The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4008/">CVE-2016-4008</cve>
	<bugzilla href="https://bugzilla.suse.com/982779">SUSE bug 982779</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482427" comment="libtasn1-4.13-4.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482428" comment="libtasn1-6-4.13-4.5.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164020" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4020</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4020" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4020" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4020" ref_url="https://www.suse.com/security/cve/CVE-2016-4020" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-4020/">CVE-2016-4020</cve>
	<bugzilla href="https://bugzilla.suse.com/975700">SUSE bug 975700</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/975907">SUSE bug 975907</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164429" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4429</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4429" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4429" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4429" ref_url="https://www.suse.com/security/cve/CVE-2016-4429" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-July/002147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1527-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1779-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-07/msg00039.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4429/">CVE-2016-4429</cve>
	<bugzilla href="https://bugzilla.suse.com/1081556">SUSE bug 1081556</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980854">SUSE bug 980854</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164439" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4439</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4439" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4439" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4439" ref_url="https://www.suse.com/security/cve/CVE-2016-4439" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or potentially execute arbitrary code on the QEMU host via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="8.2/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-4439/">CVE-2016-4439</cve>
	<bugzilla href="https://bugzilla.suse.com/980711">SUSE bug 980711</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980716">SUSE bug 980716</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164440" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4440</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4440" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4440" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4440" ref_url="https://www.suse.com/security/cve/CVE-2016-4440" source="SUSE CVE"/>
    <description>
    arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off state, which allows guest OS users to obtain direct APIC MSR access on the host OS, and consequently cause a denial of service (host OS crash) or possibly execute arbitrary code on the host OS, via x2APIC mode.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-4440/">CVE-2016-4440</cve>
	<bugzilla href="https://bugzilla.suse.com/980829">SUSE bug 980829</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164441" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4441</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4441" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4441" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4441" ref_url="https://www.suse.com/security/cve/CVE-2016-4441" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via unspecified vectors, involving an SCSI command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4441/">CVE-2016-4441</cve>
	<bugzilla href="https://bugzilla.suse.com/980723">SUSE bug 980723</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980724">SUSE bug 980724</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164453" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4453</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4453" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4453" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4453" ref_url="https://www.suse.com/security/cve/CVE-2016-4453" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4453/">CVE-2016-4453</cve>
	<bugzilla href="https://bugzilla.suse.com/982223">SUSE bug 982223</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/982225">SUSE bug 982225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164454" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4454</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4454" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4454" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4454" ref_url="https://www.suse.com/security/cve/CVE-2016-4454" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4454/">CVE-2016-4454</cve>
	<bugzilla href="https://bugzilla.suse.com/982222">SUSE bug 982222</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/982224">SUSE bug 982224</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164472" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4472</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4472" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4472" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4472" ref_url="https://www.suse.com/security/cve/CVE-2016-4472" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006536.html" source="SUSE-SU"/>
    <description>
    The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-4472/">CVE-2016-4472</cve>
	<bugzilla href="https://bugzilla.suse.com/1034050">SUSE bug 1034050</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/939077">SUSE bug 939077</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980391">SUSE bug 980391</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983985">SUSE bug 983985</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481944" comment="libexpat1-2.2.5-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164476" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4476</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4476" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4476" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4476" ref_url="https://www.suse.com/security/cve/CVE-2016-4476" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
    <description>
    hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4476/">CVE-2016-4476</cve>
	<bugzilla href="https://bugzilla.suse.com/978172">SUSE bug 978172</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164477" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4477</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4477" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4477" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4477" ref_url="https://www.suse.com/security/cve/CVE-2016-4477" source="SUSE CVE"/>
    <description>
    wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-4477/">CVE-2016-4477</cve>
	<bugzilla href="https://bugzilla.suse.com/978175">SUSE bug 978175</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164480" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4480</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4480" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4480" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4480" ref_url="https://www.suse.com/security/cve/CVE-2016-4480" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-07-01"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-4480/">CVE-2016-4480</cve>
	<bugzilla href="https://bugzilla.suse.com/1072198">SUSE bug 1072198</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1072223">SUSE bug 1072223</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978288">SUSE bug 978288</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978295">SUSE bug 978295</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164482" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4482</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4482" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4482" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4482" ref_url="https://www.suse.com/security/cve/CVE-2016-4482" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1690-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2105-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html" source="SUSE-SU"/>
    <description>
    The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-4482/">CVE-2016-4482</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978401">SUSE bug 978401</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978445">SUSE bug 978445</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164483" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4483</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4483" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4483" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4483" ref_url="https://www.suse.com/security/cve/CVE-2016-4483" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1538-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1604-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1594-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1595-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00026.html" source="SUSE-SU"/>
    <description>
    The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization.  NOTE: this vulnerability may be a duplicate of CVE-2016-3627.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4483/">CVE-2016-4483</cve>
	<bugzilla href="https://bugzilla.suse.com/1026101">SUSE bug 1026101</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978395">SUSE bug 978395</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164485" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4485</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4485" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4485" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4485" ref_url="https://www.suse.com/security/cve/CVE-2016-4485" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00007.html" source="SUSE-SU"/>
    <description>
    The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-4485/">CVE-2016-4485</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/978821">SUSE bug 978821</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164565" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4565</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4565" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4565" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4565" ref_url="https://www.suse.com/security/cve/CVE-2016-4565" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1690-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1961-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1994-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2000-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2001-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2002-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2006-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2009-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2014-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2105-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html" source="SUSE-SU"/>
    <description>
    The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-4565/">CVE-2016-4565</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979548">SUSE bug 979548</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980363">SUSE bug 980363</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980883">SUSE bug 980883</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164568" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4568</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4568" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4568" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4568" ref_url="https://www.suse.com/security/cve/CVE-2016-4568" source="SUSE CVE"/>
    <description>
    drivers/media/v4l2-core/videobuf2-v4l2.c in the Linux kernel before 4.5.3 allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a crafted number of planes in a VIDIOC_DQBUF ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-4568/">CVE-2016-4568</cve>
	<bugzilla href="https://bugzilla.suse.com/979022">SUSE bug 979022</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981516">SUSE bug 981516</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164569" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4569</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4569" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4569" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4569" ref_url="https://www.suse.com/security/cve/CVE-2016-4569" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1690-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2105-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00007.html" source="SUSE-SU"/>
    <description>
    The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-4569/">CVE-2016-4569</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979213">SUSE bug 979213</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979879">SUSE bug 979879</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164574" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4574</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4574" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4574" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4574" ref_url="https://www.suse.com/security/cve/CVE-2016-4574" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1370-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-05/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1525-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00028.html" source="SUSE-SU"/>
    <description>
    Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-4356.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4574/">CVE-2016-4574</cve>
	<bugzilla href="https://bugzilla.suse.com/1135436">SUSE bug 1135436</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979261">SUSE bug 979261</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480597" comment="libksba8-1.3.5-2.14 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164579" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4579</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4579" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4579" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4579" ref_url="https://www.suse.com/security/cve/CVE-2016-4579" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-June/002099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1525-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00028.html" source="SUSE-SU"/>
    <description>
    Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4579/">CVE-2016-4579</cve>
	<bugzilla href="https://bugzilla.suse.com/1135436">SUSE bug 1135436</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/979906">SUSE bug 979906</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480597" comment="libksba8-1.3.5-2.14 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164658" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4658</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4658" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4658" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4658" ref_url="https://www.suse.com/security/cve/CVE-2016-4658" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2652-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2711-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2730-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0446-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00055.html" source="SUSE-SU"/>
    <description>
    xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-4658/">CVE-2016-4658</cve>
	<bugzilla href="https://bugzilla.suse.com/1005544">SUSE bug 1005544</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1014873">SUSE bug 1014873</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1069433">SUSE bug 1069433</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1078813">SUSE bug 1078813</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164738" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4738</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4738" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4738" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4738" ref_url="https://www.suse.com/security/cve/CVE-2016-4738" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1390-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00079.html" source="SUSE-SU"/>
    <description>
    libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-4738/">CVE-2016-4738</cve>
	<bugzilla href="https://bugzilla.suse.com/1005591">SUSE bug 1005591</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123130">SUSE bug 1123130</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482467" comment="libxslt1-1.1.32-3.8.24 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164794" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4794</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4794" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4794" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4794" ref_url="https://www.suse.com/security/cve/CVE-2016-4794" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2016:1798-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00014.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified other impact via crafted use of the mmap and bpf system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-4794/">CVE-2016-4794</cve>
	<bugzilla href="https://bugzilla.suse.com/980265">SUSE bug 980265</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981517">SUSE bug 981517</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164804" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4804</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4804" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4804" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4804" ref_url="https://www.suse.com/security/cve/CVE-2016-4804" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2145-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002225.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1461-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-06/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2233-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00014.html" source="SUSE-SU"/>
    <description>
    The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4804/">CVE-2016-4804</cve>
	<bugzilla href="https://bugzilla.suse.com/980364">SUSE bug 980364</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980377">SUSE bug 980377</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655181" comment="dosfstools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164912" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4912</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4912" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4912" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4912" ref_url="https://www.suse.com/security/cve/CVE-2016-4912" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0100-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003598.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2712-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00005.html" source="SUSE-SU"/>
    <description>
    The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which triggers a memory allocation failure.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4912/">CVE-2016-4912</cve>
	<bugzilla href="https://bugzilla.suse.com/1074356">SUSE bug 1074356</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980722">SUSE bug 980722</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482486" comment="openslp-2.0.0-6.12.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164952" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4952</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4952" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4952" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4952" ref_url="https://www.suse.com/security/cve/CVE-2016-4952" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1560-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (1) PVSCSI_CMD_SETUP_RINGS or (2) PVSCSI_CMD_SETUP_MSG_RING SCSI command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-01"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.3/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4952/">CVE-2016-4952</cve>
	<bugzilla href="https://bugzilla.suse.com/981266">SUSE bug 981266</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981276">SUSE bug 981276</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20164964" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-4964</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-4964" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4964" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-4964" ref_url="https://www.suse.com/security/cve/CVE-2016-4964" source="SUSE CVE"/>
    <description>
    The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop, and CPU consumption or QEMU process crash) via vectors involving s-&gt;state.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-4964/">CVE-2016-4964</cve>
	<bugzilla href="https://bugzilla.suse.com/981399">SUSE bug 981399</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/981401">SUSE bug 981401</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165011" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5011</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5011" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5011" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5011" ref_url="https://www.suse.com/security/cve/CVE-2016-5011" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002396.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0553-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2840-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3102-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00078.html" source="SUSE-SU"/>
    <description>
    The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-5011/">CVE-2016-5011</cve>
	<bugzilla href="https://bugzilla.suse.com/988361">SUSE bug 988361</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760806" comment="libblkid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760807" comment="libfdisk1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760808" comment="libmount1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760809" comment="libsmartcols1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760810" comment="libuuid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760811" comment="util-linux-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760812" comment="util-linux-systemd-2.33.1-4.13.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165105" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5105</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5105" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5105" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5105" ref_url="https://www.suse.com/security/cve/CVE-2016-5105" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.1/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-5105/">CVE-2016-5105</cve>
	<bugzilla href="https://bugzilla.suse.com/982017">SUSE bug 982017</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/982024">SUSE bug 982024</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165106" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5106</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5106" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5106" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5106" ref_url="https://www.suse.com/security/cve/CVE-2016-5106" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI) command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.3/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-5106/">CVE-2016-5106</cve>
	<bugzilla href="https://bugzilla.suse.com/982018">SUSE bug 982018</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/982025">SUSE bug 982025</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165107" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5107</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5107" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5107" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5107" ref_url="https://www.suse.com/security/cve/CVE-2016-5107" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.3/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-5107/">CVE-2016-5107</cve>
	<bugzilla href="https://bugzilla.suse.com/982019">SUSE bug 982019</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/982026">SUSE bug 982026</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165126" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5126</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5126" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5126" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5126" ref_url="https://www.suse.com/security/cve/CVE-2016-5126" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-5126/">CVE-2016-5126</cve>
	<bugzilla href="https://bugzilla.suse.com/982285">SUSE bug 982285</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/982286">SUSE bug 982286</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165238" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5238</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5238" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5238" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5238" ref_url="https://www.suse.com/security/cve/CVE-2016-5238" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-5238/">CVE-2016-5238</cve>
	<bugzilla href="https://bugzilla.suse.com/982959">SUSE bug 982959</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/982960">SUSE bug 982960</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165244" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5244</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5244" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5244" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5244" ref_url="https://www.suse.com/security/cve/CVE-2016-5244" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1690-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:1985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2105-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1641-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html" source="SUSE-SU"/>
    <description>
    The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-20"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-5244/">CVE-2016-5244</cve>
	<bugzilla href="https://bugzilla.suse.com/983213">SUSE bug 983213</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986225">SUSE bug 986225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165300" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5300</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5300" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5300" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5300" ref_url="https://www.suse.com/security/cve/CVE-2016-5300" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002631.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0483-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00071.html" source="SUSE-SU"/>
    <description>
    The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-5300/">CVE-2016-5300</cve>
	<bugzilla href="https://bugzilla.suse.com/983216">SUSE bug 983216</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481944" comment="libexpat1-2.2.5-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165337" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5337</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5337" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5337" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5337" ref_url="https://www.suse.com/security/cve/CVE-2016-5337" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-5337/">CVE-2016-5337</cve>
	<bugzilla href="https://bugzilla.suse.com/983961">SUSE bug 983961</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983973">SUSE bug 983973</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165338" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5338</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5338" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5338" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5338" ref_url="https://www.suse.com/security/cve/CVE-2016-5338" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-5338/">CVE-2016-5338</cve>
	<bugzilla href="https://bugzilla.suse.com/983982">SUSE bug 983982</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983984">SUSE bug 983984</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165389" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5389</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5389" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5389" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5389" ref_url="https://www.suse.com/security/cve/CVE-2016-5389" source="SUSE CVE"/>
    <description>
    ** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2016-5696.  Reason: This candidate is a reservation duplicate of CVE-2016-5696.  Notes: All CVE users should reference CVE-2016-5696 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2016-5389/">CVE-2016-5389</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165403" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5403</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5403" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5403" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5403" ref_url="https://www.suse.com/security/cve/CVE-2016-5403" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-5403/">CVE-2016-5403</cve>
	<bugzilla href="https://bugzilla.suse.com/990923">SUSE bug 990923</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/991080">SUSE bug 991080</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165407" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5407</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5407" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5407" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5407" ref_url="https://www.suse.com/security/cve/CVE-2016-5407" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002477.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2600-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-10/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3033-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00047.html" source="SUSE-SU"/>
    <description>
    The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-5407/">CVE-2016-5407</cve>
	<bugzilla href="https://bugzilla.suse.com/1003017">SUSE bug 1003017</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123148">SUSE bug 1123148</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480441" comment="libXv1-1.0.11-1.23 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165410" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5410</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5410" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5410" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5410" ref_url="https://www.suse.com/security/cve/CVE-2016-5410" source="SUSE CVE"/>
    <description>
    firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries D-Bus API method.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-5410/">CVE-2016-5410</cve>
	<bugzilla href="https://bugzilla.suse.com/992772">SUSE bug 992772</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481122" comment="firewalld-0.5.5-4.24.9 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481124" comment="python3-firewall-0.5.5-4.24.9 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165412" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5412</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5412" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5412" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5412" ref_url="https://www.suse.com/security/cve/CVE-2016-5412" source="SUSE CVE"/>
    <description>
    arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest OS users to cause a denial of service (host OS infinite loop) by making a H_CEDE hypercall during the existence of a suspended transaction.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-5412/">CVE-2016-5412</cve>
	<bugzilla href="https://bugzilla.suse.com/1013013">SUSE bug 1013013</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/991065">SUSE bug 991065</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165417" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5417</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5417" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5417" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5417" ref_url="https://www.suse.com/security/cve/CVE-2016-5417" source="SUSE CVE"/>
    <description>
    Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-5417/">CVE-2016-5417</cve>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/991670">SUSE bug 991670</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165636" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5636</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5636" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5636" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5636" ref_url="https://www.suse.com/security/cve/CVE-2016-5636" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002407.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1885-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-07/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2120-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00089.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-5636/">CVE-2016-5636</cve>
	<bugzilla href="https://bugzilla.suse.com/1065451">SUSE bug 1065451</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1106262">SUSE bug 1106262</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/985177">SUSE bug 985177</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165696" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5696</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5696" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5696" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5696" ref_url="https://www.suse.com/security/cve/CVE-2016-5696" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2976-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3069-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00013.html" source="SUSE-SU"/>
    <description>
    net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2016-5696/">CVE-2016-5696</cve>
	<bugzilla href="https://bugzilla.suse.com/1020452">SUSE bug 1020452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1175721">SUSE bug 1175721</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/989152">SUSE bug 989152</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165699" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5699</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5699" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5699" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5699" ref_url="https://www.suse.com/security/cve/CVE-2016-5699" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002263.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002407.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1885-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-07/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2120-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00089.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2016-5699/">CVE-2016-5699</cve>
	<bugzilla href="https://bugzilla.suse.com/1122729">SUSE bug 1122729</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1130840">SUSE bug 1130840</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/985348">SUSE bug 985348</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/985351">SUSE bug 985351</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/986630">SUSE bug 986630</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165735" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5735</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5735" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5735" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5735" ref_url="https://www.suse.com/security/cve/CVE-2016-5735" source="SUSE CVE"/>
    <description>
    Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers a buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-5735/">CVE-2016-5735</cve>
	<bugzilla href="https://bugzilla.suse.com/1173616">SUSE bug 1173616</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482352" comment="libpng16-16-1.6.34-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165759" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5759</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5759" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5759" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5759" ref_url="https://www.suse.com/security/cve/CVE-2016-5759" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2553-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002337.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2605-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-10/msg00083.html" source="SUSE-SU"/>
    <description>
    The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-5759/">CVE-2016-5759</cve>
	<bugzilla href="https://bugzilla.suse.com/990200">SUSE bug 990200</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760797" comment="kdump-0.9.0-11.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20165828" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-5828</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-5828" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5828" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-5828" ref_url="https://www.suse.com/security/cve/CVE-2016-5828" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:1937-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2105-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html" source="SUSE-SU"/>
    <description>
    The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-5828/">CVE-2016-5828</cve>
	<bugzilla href="https://bugzilla.suse.com/986569">SUSE bug 986569</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/991065">SUSE bug 991065</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166130" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6130</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6130" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6130" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6130" ref_url="https://www.suse.com/security/cve/CVE-2016-6130" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00013.html" source="SUSE-SU"/>
    <description>
    Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows local users to obtain sensitive information from kernel memory by changing a certain length value, aka a "double fetch" vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="2.2/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-6130/">CVE-2016-6130</cve>
	<bugzilla href="https://bugzilla.suse.com/987542">SUSE bug 987542</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166136" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6136</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6136" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6136" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6136" ref_url="https://www.suse.com/security/cve/CVE-2016-6136" source="SUSE CVE"/>
    <description>
    Race condition in the audit_log_single_execve_arg function in kernel/auditsc.c in the Linux kernel through 4.7 allows local users to bypass intended character-set restrictions or disrupt system-call auditing by changing a certain string, aka a "double fetch" vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6136/">CVE-2016-6136</cve>
	<bugzilla href="https://bugzilla.suse.com/988153">SUSE bug 988153</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166197" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6197</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6197" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6197" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6197" ref_url="https://www.suse.com/security/cve/CVE-2016-6197" source="SUSE CVE"/>
    <description>
    fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing, which allows local users to cause a denial of service (system crash) via a rename system call that specifies a self-hardlink.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6197/">CVE-2016-6197</cve>
	<bugzilla href="https://bugzilla.suse.com/988708">SUSE bug 988708</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166198" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6198</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6198" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6198" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6198" ref_url="https://www.suse.com/security/cve/CVE-2016-6198" source="SUSE CVE"/>
    <description>
    The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related to fs/namei.c and fs/open.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6198/">CVE-2016-6198</cve>
	<bugzilla href="https://bugzilla.suse.com/988708">SUSE bug 988708</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166210" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6210</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6210" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6210" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6210" ref_url="https://www.suse.com/security/cve/CVE-2016-6210" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002265.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002338.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2339-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00068.html" source="SUSE-SU"/>
    <description>
    sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-6210/">CVE-2016-6210</cve>
	<bugzilla href="https://bugzilla.suse.com/1001712">SUSE bug 1001712</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105010">SUSE bug 1105010</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138392">SUSE bug 1138392</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/989363">SUSE bug 989363</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166213" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6213</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6213" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6213" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6213" ref_url="https://www.suse.com/security/cve/CVE-2016-6213" source="SUSE CVE"/>
    <description>
    fs/namespace.c in the Linux kernel before 4.9 does not restrict how many mounts may exist in a mount namespace, which allows local users to cause a denial of service (memory consumption and deadlock) via MS_BIND mount system calls, as demonstrated by a loop that triggers exponential growth in the number of mounts.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6213/">CVE-2016-6213</cve>
	<bugzilla href="https://bugzilla.suse.com/988964">SUSE bug 988964</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166258" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6258</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6258" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6258" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6258" ref_url="https://www.suse.com/security/cve/CVE-2016-6258" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-6258/">CVE-2016-6258</cve>
	<bugzilla href="https://bugzilla.suse.com/1072198">SUSE bug 1072198</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1072223">SUSE bug 1072223</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/988675">SUSE bug 988675</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/988692">SUSE bug 988692</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166259" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6259</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6259" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6259" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6259" ref_url="https://www.suse.com/security/cve/CVE-2016-6259" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
    <description>
    Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6259/">CVE-2016-6259</cve>
	<bugzilla href="https://bugzilla.suse.com/988676">SUSE bug 988676</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/988694">SUSE bug 988694</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166261" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6261</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6261" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6261" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6261" ref_url="https://www.suse.com/security/cve/CVE-2016-6261" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2135-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00098.html" source="SUSE-SU"/>
    <description>
    The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6261/">CVE-2016-6261</cve>
	<bugzilla href="https://bugzilla.suse.com/1118435">SUSE bug 1118435</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173590">SUSE bug 1173590</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990190">SUSE bug 990190</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482248" comment="libidn11-1.34-3.2.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628747" comment="libidn2-0-2.2.0-3.6.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166262" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6262</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6262" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6262" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6262" ref_url="https://www.suse.com/security/cve/CVE-2016-6262" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1924-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2135-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00098.html" source="SUSE-SU"/>
    <description>
    idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-6262/">CVE-2016-6262</cve>
	<bugzilla href="https://bugzilla.suse.com/1014473">SUSE bug 1014473</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173590">SUSE bug 1173590</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190777">SUSE bug 1190777</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990189">SUSE bug 990189</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482248" comment="libidn11-1.34-3.2.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628747" comment="libidn2-0-2.2.0-3.6.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166263" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6263</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6263" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6263" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6263" ref_url="https://www.suse.com/security/cve/CVE-2016-6263" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:1924-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2135-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00098.html" source="SUSE-SU"/>
    <description>
    The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6263/">CVE-2016-6263</cve>
	<bugzilla href="https://bugzilla.suse.com/1118435">SUSE bug 1118435</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990191">SUSE bug 990191</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482248" comment="libidn11-1.34-3.2.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628747" comment="libidn2-0-2.2.0-3.6.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166302" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6302</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6302" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6302" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6302" ref_url="https://www.suse.com/security/cve/CVE-2016-6302" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2469-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that is too short.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6302/">CVE-2016-6302</cve>
	<bugzilla href="https://bugzilla.suse.com/1004104">SUSE bug 1004104</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994844">SUSE bug 994844</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/995324">SUSE bug 995324</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999665">SUSE bug 999665</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166303" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6303</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6303" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6303" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6303" ref_url="https://www.suse.com/security/cve/CVE-2016-6303" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2469-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-6303/">CVE-2016-6303</cve>
	<bugzilla href="https://bugzilla.suse.com/1004104">SUSE bug 1004104</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994844">SUSE bug 994844</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/995377">SUSE bug 995377</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999665">SUSE bug 999665</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166304" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6304</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6304" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6304" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6304" ref_url="https://www.suse.com/security/cve/CVE-2016-6304" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2469-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2470-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2496-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2769-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2788-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6304/">CVE-2016-6304</cve>
	<bugzilla href="https://bugzilla.suse.com/1001706">SUSE bug 1001706</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1003811">SUSE bug 1003811</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1004104">SUSE bug 1004104</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1005579">SUSE bug 1005579</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1021375">SUSE bug 1021375</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999665">SUSE bug 999665</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999666">SUSE bug 999666</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166306" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6306</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6306" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6306" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6306" ref_url="https://www.suse.com/security/cve/CVE-2016-6306" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2469-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2470-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="TID3426981" ref_url="https://www.suse.com/support/kb/doc/?id=3426981" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2391-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2496-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2537-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6306/">CVE-2016-6306</cve>
	<bugzilla href="https://bugzilla.suse.com/1004104">SUSE bug 1004104</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999665">SUSE bug 999665</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999668">SUSE bug 999668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166313" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6313</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6313" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6313" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6313" ref_url="https://www.suse.com/security/cve/CVE-2016-6313" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2208-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00126.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2423-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00108.html" source="SUSE-SU"/>
    <description>
    The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-6313/">CVE-2016-6313</cve>
	<bugzilla href="https://bugzilla.suse.com/1123792">SUSE bug 1123792</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994157">SUSE bug 994157</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482233" comment="libgcrypt20-1.8.2-8.36.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166318" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6318</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6318" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6318" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6318" ref_url="https://www.suse.com/security/cve/CVE-2016-6318" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-August/002220.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002248.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2204-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-08/msg00122.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-6318/">CVE-2016-6318</cve>
	<bugzilla href="https://bugzilla.suse.com/1123113">SUSE bug 1123113</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/992966">SUSE bug 992966</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628370" comment="cracklib-2.9.7-11.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628372" comment="cracklib-dict-small-2.9.7-11.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628373" comment="libcrack2-2.9.7-11.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166321" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6321</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6321" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6321" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6321" ref_url="https://www.suse.com/security/cve/CVE-2016-6321" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2895-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002416.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2896-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002417.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2874-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3003-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00028.html" source="SUSE-SU"/>
    <description>
    Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to improper sanitization of the file_name parameter, aka POINTYFEATHER.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-6321/">CVE-2016-6321</cve>
	<bugzilla href="https://bugzilla.suse.com/1007188">SUSE bug 1007188</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123796">SUSE bug 1123796</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481663" comment="tar-1.30-3.3.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166323" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6323</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6323" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6323" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6323" ref_url="https://www.suse.com/security/cve/CVE-2016-6323" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2016:2443-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-10/msg00009.html" source="SUSE-SU"/>
    <description>
    The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6323/">CVE-2016-6323</cve>
	<bugzilla href="https://bugzilla.suse.com/994359">SUSE bug 994359</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166351" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6351</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6351" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6351" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6351" ref_url="https://www.suse.com/security/cve/CVE-2016-6351" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arbitrary code on the QEMU host via vectors involving DMA read into ESP command buffer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-6351/">CVE-2016-6351</cve>
	<bugzilla href="https://bugzilla.suse.com/990835">SUSE bug 990835</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/990843">SUSE bug 990843</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166480" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6480</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6480" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6480" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6480" ref_url="https://www.suse.com/security/cve/CVE-2016-6480" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2175-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2177-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2178-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2179-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-08/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2230-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2674-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2976-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3069-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00013.html" source="SUSE-SU"/>
    <description>
    Race condition in the ioctl_send_fib function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (out-of-bounds access or system crash) by changing a certain size value, aka a "double fetch" vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6480/">CVE-2016-6480</cve>
	<bugzilla href="https://bugzilla.suse.com/1004418">SUSE bug 1004418</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/991608">SUSE bug 991608</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/991667">SUSE bug 991667</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/992568">SUSE bug 992568</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166489" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6489</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6489" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6489" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6489" ref_url="https://www.suse.com/security/cve/CVE-2016-6489" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1481-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002936.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1533-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-06/msg00032.html" source="SUSE-SU"/>
    <description>
    The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-6489/">CVE-2016-6489</cve>
	<bugzilla href="https://bugzilla.suse.com/991464">SUSE bug 991464</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482241" comment="libhogweed4-3.4.1-4.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482244" comment="libnettle6-3.4.1-4.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166490" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6490</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6490" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6490" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6490" ref_url="https://www.suse.com/security/cve/CVE-2016-6490" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the descriptor buffer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6490/">CVE-2016-6490</cve>
	<bugzilla href="https://bugzilla.suse.com/991466">SUSE bug 991466</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/993854">SUSE bug 993854</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166515" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6515</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6515" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6515" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6515" ref_url="https://www.suse.com/security/cve/CVE-2016-6515" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002265.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-September/002289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002338.html" source="SUSE-SU"/>
		<reference ref_id="TID7022102" ref_url="https://www.suse.com/support/kb/doc/?id=7022102" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2339-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-09/msg00068.html" source="SUSE-SU"/>
    <description>
    The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) via a long string.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6515/">CVE-2016-6515</cve>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/992533">SUSE bug 992533</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166786" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6786</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6786" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6786" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6786" ref_url="https://www.suse.com/security/cve/CVE-2016-6786" source="SUSE CVE"/>
    <description>
    kernel/events/core.c in the performance subsystem in the Linux kernel before 4.0 mismanages locks during certain migrations, which allows local users to gain privileges via a crafted application, aka Android internal bug 30955111.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-09"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-6786/">CVE-2016-6786</cve>
	<bugzilla href="https://bugzilla.suse.com/1015160">SUSE bug 1015160</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1025626">SUSE bug 1025626</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166787" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6787</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6787" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6787" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6787" ref_url="https://www.suse.com/security/cve/CVE-2016-6787" source="SUSE CVE"/>
    <description>
    kernel/events/core.c in the performance subsystem in the Linux kernel before 4.0 mismanages locks during certain migrations, which allows local users to gain privileges via a crafted application, aka Android internal bug 31095224.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-09"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-6787/">CVE-2016-6787</cve>
	<bugzilla href="https://bugzilla.suse.com/1015160">SUSE bug 1015160</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166828" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6828</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6828" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6828" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6828" ref_url="https://www.suse.com/security/cve/CVE-2016-6828" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2976-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3069-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00013.html" source="SUSE-SU"/>
    <description>
    The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certain SACK state after a failed data copy, which allows local users to cause a denial of service (tcp_xmit_retransmit_queue use-after-free and system crash) via a crafted SACK option.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6828/">CVE-2016-6828</cve>
	<bugzilla href="https://bugzilla.suse.com/1052256">SUSE bug 1052256</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994296">SUSE bug 994296</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166833" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6833</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6833" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6833" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6833" ref_url="https://www.suse.com/security/cve/CVE-2016-6833" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance crash) by leveraging failure to check if the device is active.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6833/">CVE-2016-6833</cve>
	<bugzilla href="https://bugzilla.suse.com/994774">SUSE bug 994774</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994775">SUSE bug 994775</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166836" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6836</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6836" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6836" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6836" ref_url="https://www.suse.com/security/cve/CVE-2016-6836" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcq_descr object.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-6836/">CVE-2016-6836</cve>
	<bugzilla href="https://bugzilla.suse.com/994760">SUSE bug 994760</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994761">SUSE bug 994761</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20166888" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-6888</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-6888" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6888" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-6888" ref_url="https://www.suse.com/security/cve/CVE-2016-6888" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-6888/">CVE-2016-6888</cve>
	<bugzilla href="https://bugzilla.suse.com/994771">SUSE bug 994771</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/994772">SUSE bug 994772</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167031" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7031</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7031" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7031" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7031" ref_url="https://www.suse.com/security/cve/CVE-2016-7031" source="SUSE CVE"/>
    <description>
    The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-07-01"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-7031/">CVE-2016-7031</cve>
	<bugzilla href="https://bugzilla.suse.com/997025">SUSE bug 997025</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009335684" comment="librados2 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335686" comment="librbd1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167032" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7032</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7032" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7032" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7032" ref_url="https://www.suse.com/security/cve/CVE-2016-7032" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002413.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002420.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2878-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00098.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2983-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3004-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00029.html" source="SUSE-SU"/>
    <description>
    sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7032/">CVE-2016-7032</cve>
	<bugzilla href="https://bugzilla.suse.com/1007501">SUSE bug 1007501</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1007766">SUSE bug 1007766</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1011975">SUSE bug 1011975</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1011976">SUSE bug 1011976</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760863" comment="sudo-1.8.22-4.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167052" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7052</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7052" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7052" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7052" ref_url="https://www.suse.com/security/cve/CVE-2016-7052" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2470-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="TID7018311" ref_url="https://www.suse.com/support/kb/doc/?id=7018311" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2496-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7052/">CVE-2016-7052</cve>
	<bugzilla href="https://bugzilla.suse.com/1001148">SUSE bug 1001148</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167055" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7055</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7055" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7055" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7055" ref_url="https://www.suse.com/security/cve/CVE-2016-7055" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0855-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7021518" ref_url="https://www.suse.com/support/kb/doc/?id=7021518" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0481-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0527-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00095.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0941-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker's direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7055/">CVE-2016-7055</cve>
	<bugzilla href="https://bugzilla.suse.com/1009528">SUSE bug 1009528</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1021641">SUSE bug 1021641</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167056" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7056</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7056" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7056" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7056" ref_url="https://www.suse.com/security/cve/CVE-2016-7056" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0112-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0409-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0487-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1211-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1212-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-7056/">CVE-2016-7056</cve>
	<bugzilla href="https://bugzilla.suse.com/1005878">SUSE bug 1005878</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1019334">SUSE bug 1019334</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1148697">SUSE bug 1148697</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167076" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7076</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7076" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7076" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7076" ref_url="https://www.suse.com/security/cve/CVE-2016-7076" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002413.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002420.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2878-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00098.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2983-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3004-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00029.html" source="SUSE-SU"/>
    <description>
    sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7076/">CVE-2016-7076</cve>
	<bugzilla href="https://bugzilla.suse.com/1007501">SUSE bug 1007501</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1011975">SUSE bug 1011975</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1011976">SUSE bug 1011976</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760863" comment="sudo-1.8.22-4.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167092" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7092</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7092" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7092" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7092" ref_url="https://www.suse.com/security/cve/CVE-2016-7092" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS privileges via vectors related to L3 recursive pagetables.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.5/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7092/">CVE-2016-7092</cve>
	<bugzilla href="https://bugzilla.suse.com/995785">SUSE bug 995785</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167093" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7093</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7093" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7093" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7093" ref_url="https://www.suse.com/security/cve/CVE-2016-7093" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7093/">CVE-2016-7093</cve>
	<bugzilla href="https://bugzilla.suse.com/995789">SUSE bug 995789</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167094" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7094</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7094" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7094" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7094" ref_url="https://www.suse.com/security/cve/CVE-2016-7094" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2473-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2533-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2725-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00022.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in Xen 4.7.x and earlier allows local x86 HVM guest OS administrators on guests running with shadow paging to cause a denial of service via a pagetable update.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.1/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7094/">CVE-2016-7094</cve>
	<bugzilla href="https://bugzilla.suse.com/995792">SUSE bug 995792</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167097" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7097</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7097" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7097" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7097" ref_url="https://www.suse.com/security/cve/CVE-2016-7097" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2976-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="TID7018489" ref_url="https://www.suse.com/support/kb/doc/?id=7018489" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00027.html" source="SUSE-SU"/>
    <description>
    The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2016-7097/">CVE-2016-7097</cve>
	<bugzilla href="https://bugzilla.suse.com/1021258">SUSE bug 1021258</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1052256">SUSE bug 1052256</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/870618">SUSE bug 870618</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/995968">SUSE bug 995968</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167116" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7116</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7116" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7116" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7116" ref_url="https://www.suse.com/security/cve/CVE-2016-7116" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot) in an unspecified string.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-7116/">CVE-2016-7116</cve>
	<bugzilla href="https://bugzilla.suse.com/996441">SUSE bug 996441</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167117" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7117</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7117" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7117" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7117" ref_url="https://www.suse.com/security/cve/CVE-2016-7117" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2976-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3094-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3098-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3104-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3112-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3249-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0575-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0456-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00022.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7117/">CVE-2016-7117</cve>
	<bugzilla href="https://bugzilla.suse.com/1003077">SUSE bug 1003077</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1003253">SUSE bug 1003253</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1057478">SUSE bug 1057478</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1071943">SUSE bug 1071943</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7155" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7155" ref_url="https://www.suse.com/security/cve/CVE-2016-7155" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor rings.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7155/">CVE-2016-7155</cve>
	<bugzilla href="https://bugzilla.suse.com/997858">SUSE bug 997858</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167156" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7156</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7156" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7156" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7156" ref_url="https://www.suse.com/security/cve/CVE-2016-7156" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2642-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00060.html" source="SUSE-SU"/>
    <description>
    The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging an incorrect cast.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7156/">CVE-2016-7156</cve>
	<bugzilla href="https://bugzilla.suse.com/997859">SUSE bug 997859</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167157" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7157</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7157" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7157" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7157" ref_url="https://www.suse.com/security/cve/CVE-2016-7157" source="SUSE CVE"/>
    <description>
    The (1) mptsas_config_manufacturing_1 and (2) mptsas_config_ioc_0 functions in hw/scsi/mptconfig.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via vectors involving MPTSAS_CONFIG_PACK.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7157/">CVE-2016-7157</cve>
	<bugzilla href="https://bugzilla.suse.com/997860">SUSE bug 997860</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167161" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7161</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7161" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7161" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7161" ref_url="https://www.suse.com/security/cve/CVE-2016-7161" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7161/">CVE-2016-7161</cve>
	<bugzilla href="https://bugzilla.suse.com/1001151">SUSE bug 1001151</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1001152">SUSE bug 1001152</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167167" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7167</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7167" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7167" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7167" ref_url="https://www.suse.com/security/cve/CVE-2016-7167" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2768-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00020.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7167/">CVE-2016-7167</cve>
	<bugzilla href="https://bugzilla.suse.com/998760">SUSE bug 998760</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167170" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7170</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7170" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7170" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7170" ref_url="https://www.suse.com/security/cve/CVE-2016-7170" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to cursor.mask[] and cursor.image[] array sizes when processing a DEFINE_CURSOR svga command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7170/">CVE-2016-7170</cve>
	<bugzilla href="https://bugzilla.suse.com/998516">SUSE bug 998516</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167421" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7421</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7421" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7421" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7421" ref_url="https://www.suse.com/security/cve/CVE-2016-7421" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
    <description>
    The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7421/">CVE-2016-7421</cve>
	<bugzilla href="https://bugzilla.suse.com/999661">SUSE bug 999661</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167422" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7422</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7422" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7422" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7422" ref_url="https://www.suse.com/security/cve/CVE-2016-7422" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7422/">CVE-2016-7422</cve>
	<bugzilla href="https://bugzilla.suse.com/1000346">SUSE bug 1000346</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167423" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7423</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7423" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7423" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7423" ref_url="https://www.suse.com/security/cve/CVE-2016-7423" source="SUSE CVE"/>
    <description>
    The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when built with LSI SAS1068 Host Bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors involving MPTSASRequest objects.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7423/">CVE-2016-7423</cve>
	<bugzilla href="https://bugzilla.suse.com/1000397">SUSE bug 1000397</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167425" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7425</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7425" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7425" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7425" ref_url="https://www.suse.com/security/cve/CVE-2016-7425" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2976-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3069-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2583-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00013.html" source="SUSE-SU"/>
    <description>
    The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) via an ARCMSR_MESSAGE_WRITE_WQBUFFER control code.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7425/">CVE-2016-7425</cve>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/999932">SUSE bug 999932</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167466" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7466</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7466" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7466" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7466" ref_url="https://www.suse.com/security/cve/CVE-2016-7466" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7466/">CVE-2016-7466</cve>
	<bugzilla href="https://bugzilla.suse.com/1000345">SUSE bug 1000345</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167545" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7545</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7545" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7545" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7545" ref_url="https://www.suse.com/security/cve/CVE-2016-7545" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-January/002610.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-January/002611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0340-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-January/002612.html" source="SUSE-SU"/>
    <description>
    SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7545/">CVE-2016-7545</cve>
	<bugzilla href="https://bugzilla.suse.com/1000998">SUSE bug 1000998</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968375">SUSE bug 968375</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/968674">SUSE bug 968674</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760844" comment="policycoreutils-3.1-1.25 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760845" comment="policycoreutils-python-utils-3.1-1.25 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760846" comment="python3-policycoreutils-3.1-1.25 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167567" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7567</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7567" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7567" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7567" ref_url="https://www.suse.com/security/cve/CVE-2016-7567" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-October/002371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0100-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003598.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2712-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-11/msg00005.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a crafted string.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7567/">CVE-2016-7567</cve>
	<bugzilla href="https://bugzilla.suse.com/1001600">SUSE bug 1001600</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074356">SUSE bug 1074356</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482486" comment="openslp-2.0.0-6.12.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167777" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7777</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7777" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7777" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7777" ref_url="https://www.suse.com/security/cve/CVE-2016-7777" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-7777/">CVE-2016-7777</cve>
	<bugzilla href="https://bugzilla.suse.com/1000106">SUSE bug 1000106</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167837" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7837</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7837" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7837" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7837" ref_url="https://www.suse.com/security/cve/CVE-2016-7837" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005161.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2810-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00069.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used in some userland utilities.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7837/">CVE-2016-7837</cve>
	<bugzilla href="https://bugzilla.suse.com/1026652">SUSE bug 1026652</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336474" comment="libbluetooth3 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167907" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7907</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7907" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7907" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7907" ref_url="https://www.suse.com/security/cve/CVE-2016-7907" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7907/">CVE-2016-7907</cve>
	<bugzilla href="https://bugzilla.suse.com/1002549">SUSE bug 1002549</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167908" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7908</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7908" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7908" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7908" ref_url="https://www.suse.com/security/cve/CVE-2016-7908" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7908/">CVE-2016-7908</cve>
	<bugzilla href="https://bugzilla.suse.com/1002550">SUSE bug 1002550</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1003030">SUSE bug 1003030</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167909" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7909</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7909" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7909" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7909" ref_url="https://www.suse.com/security/cve/CVE-2016-7909" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7909/">CVE-2016-7909</cve>
	<bugzilla href="https://bugzilla.suse.com/1002557">SUSE bug 1002557</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1003032">SUSE bug 1003032</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167910" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7910</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7910" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7910" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7910" ref_url="https://www.suse.com/security/cve/CVE-2016-7910" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0464-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3061-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00029.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the disk_seqf_stop function in block/genhd.c in the Linux kernel before 4.7.1 allows local users to gain privileges by leveraging the execution of a certain stop operation even if the corresponding start operation had failed.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7910/">CVE-2016-7910</cve>
	<bugzilla href="https://bugzilla.suse.com/1010716">SUSE bug 1010716</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196722">SUSE bug 1196722</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167913" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7913</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7913" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7913" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7913" ref_url="https://www.suse.com/security/cve/CVE-2016-7913" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0464-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3050-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3061-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00029.html" source="SUSE-SU"/>
    <description>
    The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of the firmware name from a certain data structure.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-7913/">CVE-2016-7913</cve>
	<bugzilla href="https://bugzilla.suse.com/1010478">SUSE bug 1010478</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167916" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7916</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7916" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7916" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7916" ref_url="https://www.suse.com/security/cve/CVE-2016-7916" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3061-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00029.html" source="SUSE-SU"/>
    <description>
    Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obtain sensitive information from kernel memory by reading a /proc/*/environ file during a process-setup time interval in which environment-variable copying is incomplete.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-7916/">CVE-2016-7916</cve>
	<bugzilla href="https://bugzilla.suse.com/1010467">SUSE bug 1010467</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167994" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7994</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7994" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7994" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7994" ref_url="https://www.suse.com/security/cve/CVE-2016-7994" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_CREATE_2D commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7994/">CVE-2016-7994</cve>
	<bugzilla href="https://bugzilla.suse.com/1003613">SUSE bug 1003613</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20167995" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-7995</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-7995" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7995" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-7995" ref_url="https://www.suse.com/security/cve/CVE-2016-7995" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
    <description>
    Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-7995/">CVE-2016-7995</cve>
	<bugzilla href="https://bugzilla.suse.com/1003612">SUSE bug 1003612</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1003870">SUSE bug 1003870</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168576" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8576</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8576" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8576" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8576" ref_url="https://www.suse.com/security/cve/CVE-2016-8576" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-8576/">CVE-2016-8576</cve>
	<bugzilla href="https://bugzilla.suse.com/1003878">SUSE bug 1003878</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1004016">SUSE bug 1004016</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168577" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8577</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8577" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8577" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8577" ref_url="https://www.suse.com/security/cve/CVE-2016-8577" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors related to an I/O read operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-8577/">CVE-2016-8577</cve>
	<bugzilla href="https://bugzilla.suse.com/1003893">SUSE bug 1003893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1004021">SUSE bug 1004021</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168578" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8578</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8578" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8578" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8578" ref_url="https://www.suse.com/security/cve/CVE-2016-8578" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) by sending an empty string parameter to a 9P operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-8578/">CVE-2016-8578</cve>
	<bugzilla href="https://bugzilla.suse.com/1003894">SUSE bug 1003894</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1004023">SUSE bug 1004023</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168610" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8610</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8610" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8610" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8610" ref_url="https://www.suse.com/security/cve/CVE-2016-8610" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0348-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002676.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0112-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3864-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004873.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3864-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3964-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183964-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3994-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1553-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005586.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0386-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0487-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4104-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00026.html" source="SUSE-SU"/>
    <description>
    A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-8610/">CVE-2016-8610</cve>
	<bugzilla href="https://bugzilla.suse.com/1005878">SUSE bug 1005878</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1005879">SUSE bug 1005879</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1110018">SUSE bug 1110018</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1120592">SUSE bug 1120592</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1148697">SUSE bug 1148697</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/982575">SUSE bug 982575</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168615" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8615</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8615" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8615" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8615" ref_url="https://www.suse.com/security/cve/CVE-2016-8615" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2768-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00020.html" source="SUSE-SU"/>
    <description>
    A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-8615/">CVE-2016-8615</cve>
	<bugzilla href="https://bugzilla.suse.com/1005633">SUSE bug 1005633</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168616" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8616</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8616" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8616" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8616" ref_url="https://www.suse.com/security/cve/CVE-2016-8616" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2768-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00020.html" source="SUSE-SU"/>
    <description>
    A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-8616/">CVE-2016-8616</cve>
	<bugzilla href="https://bugzilla.suse.com/1005634">SUSE bug 1005634</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168617" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8617</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8617" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8617" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8617" ref_url="https://www.suse.com/security/cve/CVE-2016-8617" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2768-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00020.html" source="SUSE-SU"/>
    <description>
    The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if it receives at least 1Gb as input via `CURLOPT_USERNAME`.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-8617/">CVE-2016-8617</cve>
	<bugzilla href="https://bugzilla.suse.com/1005635">SUSE bug 1005635</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168618" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8618</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8618" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8618" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8618" ref_url="https://www.suse.com/security/cve/CVE-2016-8618" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2768-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00020.html" source="SUSE-SU"/>
    <description>
    The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `size_t` variables.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2016-8618/">CVE-2016-8618</cve>
	<bugzilla href="https://bugzilla.suse.com/1005637">SUSE bug 1005637</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168619" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8619</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8619" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8619" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8619" ref_url="https://www.suse.com/security/cve/CVE-2016-8619" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2768-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00020.html" source="SUSE-SU"/>
    <description>
    The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-8619/">CVE-2016-8619</cve>
	<bugzilla href="https://bugzilla.suse.com/1005638">SUSE bug 1005638</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168620" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8620</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8620" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8620" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8620" ref_url="https://www.suse.com/security/cve/CVE-2016-8620" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2768-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00020.html" source="SUSE-SU"/>
    <description>
    The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-8620/">CVE-2016-8620</cve>
	<bugzilla href="https://bugzilla.suse.com/1005640">SUSE bug 1005640</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168621" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8621</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8621" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8621" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8621" ref_url="https://www.suse.com/security/cve/CVE-2016-8621" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2768-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00020.html" source="SUSE-SU"/>
    <description>
    The `curl_getdate` function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input with one digit short.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-8621/">CVE-2016-8621</cve>
	<bugzilla href="https://bugzilla.suse.com/1005642">SUSE bug 1005642</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168622" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8622</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8622" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8622" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8622" ref_url="https://www.suse.com/security/cve/CVE-2016-8622" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2768-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00020.html" source="SUSE-SU"/>
    <description>
    The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just truncated or both truncated and turned negative. That could then lead to libcurl writing outside of its heap based buffer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-8622/">CVE-2016-8622</cve>
	<bugzilla href="https://bugzilla.suse.com/1005643">SUSE bug 1005643</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168623" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8623</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8623" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8623" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8623" ref_url="https://www.suse.com/security/cve/CVE-2016-8623" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2768-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00020.html" source="SUSE-SU"/>
    <description>
    A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-after-free leading to information disclosure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-8623/">CVE-2016-8623</cve>
	<bugzilla href="https://bugzilla.suse.com/1005645">SUSE bug 1005645</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168624" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8624</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8624" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8624" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8624" ref_url="https://www.suse.com/security/cve/CVE-2016-8624" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2714-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2768-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00020.html" source="SUSE-SU"/>
    <description>
    curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use an URL parser that follows the RFC to check for allowed domains before using curl to request them.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-8624/">CVE-2016-8624</cve>
	<bugzilla href="https://bugzilla.suse.com/1005646">SUSE bug 1005646</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168625" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8625</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8625" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8625" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8625" ref_url="https://www.suse.com/security/cve/CVE-2016-8625" source="SUSE CVE"/>
    <description>
    curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-8625/">CVE-2016-8625</cve>
	<bugzilla href="https://bugzilla.suse.com/1005649">SUSE bug 1005649</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168630" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8630</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8630" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8630" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8630" ref_url="https://www.suse.com/security/cve/CVE-2016-8630" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2016:3058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00027.html" source="SUSE-SU"/>
    <description>
    The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of service (host OS crash) via a certain use of a ModR/M byte in an undefined instruction.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-8630/">CVE-2016-8630</cve>
	<bugzilla href="https://bugzilla.suse.com/1009222">SUSE bug 1009222</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168632" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8632</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8632" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8632" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8632" ref_url="https://www.suse.com/security/cve/CVE-2016-8632" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3039-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3049-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3063-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0227-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0228-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0229-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0230-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0231-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0234-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0235-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0244-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0246-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0248-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0249-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0268-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0278-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3050-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3077-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00034.html" source="SUSE-SU"/>
    <description>
    The tipc_msg_build function in net/tipc/msg.c in the Linux kernel through 4.8.11 does not validate the relationship between the minimum fragment length and the maximum packet size, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) by leveraging the CAP_NET_ADMIN capability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-8632/">CVE-2016-8632</cve>
	<bugzilla href="https://bugzilla.suse.com/1008831">SUSE bug 1008831</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1012852">SUSE bug 1012852</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168633" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8633</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8633" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8633" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8633" ref_url="https://www.suse.com/security/cve/CVE-2016-8633" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0464-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3061-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00029.html" source="SUSE-SU"/>
    <description>
    drivers/firewire/net.c in the Linux kernel before 4.8.7, in certain unusual hardware configurations, allows remote attackers to execute arbitrary code via crafted fragmented packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-8633/">CVE-2016-8633</cve>
	<bugzilla href="https://bugzilla.suse.com/1008833">SUSE bug 1008833</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168637" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8637</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8637" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8637" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8637" ref_url="https://www.suse.com/security/cve/CVE-2016-8637" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0951-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2696-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003286.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0708-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-03/msg00047.html" source="SUSE-SU"/>
    <description>
    A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-8637/">CVE-2016-8637</cve>
	<bugzilla href="https://bugzilla.suse.com/1008340">SUSE bug 1008340</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760776" comment="dracut-049.1+suse.186.g320cc3d1-1.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168645" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8645</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8645" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8645" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8645" ref_url="https://www.suse.com/security/cve/CVE-2016-8645" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0464-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0456-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00022.html" source="SUSE-SU"/>
    <description>
    The TCP stack in the Linux kernel before 4.8.10 mishandles skb truncation, which allows local users to cause a denial of service (system crash) via a crafted application that makes sendto system calls, related to net/ipv4/tcp_ipv4.c and net/ipv6/tcp_ipv6.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-8645/">CVE-2016-8645</cve>
	<bugzilla href="https://bugzilla.suse.com/1009969">SUSE bug 1009969</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168646" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8646</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8646" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8646" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8646" ref_url="https://www.suse.com/security/cve/CVE-2016-8646" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3061-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00029.html" source="SUSE-SU"/>
    <description>
    The hash_accept function in crypto/algif_hash.c in the Linux kernel before 4.3.6 allows local users to cause a denial of service (OOPS) by attempting to trigger use of in-kernel hash algorithms for a socket that has received zero bytes of data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-8646/">CVE-2016-8646</cve>
	<bugzilla href="https://bugzilla.suse.com/1010150">SUSE bug 1010150</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168650" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8650</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8650" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8650" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8650" ref_url="https://www.suse.com/security/cve/CVE-2016-8650" source="SUSE CVE"/>
    <description>
    The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-8650/">CVE-2016-8650</cve>
	<bugzilla href="https://bugzilla.suse.com/1011820">SUSE bug 1011820</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168655" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8655</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8655" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8655" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8655" ref_url="https://www.suse.com/security/cve/CVE-2016-8655" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3039-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3049-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3063-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3094-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3096-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3098-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3104-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3112-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3113-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3116-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3117-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3183-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3197-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3205-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3249-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="TID7018348" ref_url="https://www.suse.com/support/kb/doc/?id=7018348" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3050-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3061-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3077-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00034.html" source="SUSE-SU"/>
    <description>
    Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-19"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-8655/">CVE-2016-8655</cve>
	<bugzilla href="https://bugzilla.suse.com/1012754">SUSE bug 1012754</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1012759">SUSE bug 1012759</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1013822">SUSE bug 1013822</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1052365">SUSE bug 1052365</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168658" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8658</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8658" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8658" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8658" ref_url="https://www.suse.com/security/cve/CVE-2016-8658" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2583-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-10/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00013.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a long SSID Information Element in a command to a Netlink socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2016-8658/">CVE-2016-8658</cve>
	<bugzilla href="https://bugzilla.suse.com/1004462">SUSE bug 1004462</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168667" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8667</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8667" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8667" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8667" ref_url="https://www.suse.com/security/cve/CVE-2016-8667" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via a large interval timer reload value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-8667/">CVE-2016-8667</cve>
	<bugzilla href="https://bugzilla.suse.com/1004702">SUSE bug 1004702</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1005004">SUSE bug 1005004</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168668" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8668</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8668" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8668" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8668" ref_url="https://www.suse.com/security/cve/CVE-2016-8668" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    The rocker_io_writel function in hw/net/rocker/rocker.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging failure to limit DMA buffer size.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-8668/">CVE-2016-8668</cve>
	<bugzilla href="https://bugzilla.suse.com/1004706">SUSE bug 1004706</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168669" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8669</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8669" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8669" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8669" ref_url="https://www.suse.com/security/cve/CVE-2016-8669" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater than baud base.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-8669/">CVE-2016-8669</cve>
	<bugzilla href="https://bugzilla.suse.com/1004707">SUSE bug 1004707</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1005005">SUSE bug 1005005</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168858" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8858</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8858" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8858" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8858" ref_url="https://www.suse.com/security/cve/CVE-2016-8858" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-January/002592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0607-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002685.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0607-3" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002972.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0344-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-01/msg00178.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0674-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-03/msg00032.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests.  NOTE: a third party reports that "OpenSSH upstream does not consider this as a security issue."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-8858/">CVE-2016-8858</cve>
	<bugzilla href="https://bugzilla.suse.com/1005480">SUSE bug 1005480</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168867" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8867</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8867" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8867" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8867" ref_url="https://www.suse.com/security/cve/CVE-2016-8867" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002467.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3009-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00033.html" source="SUSE-SU"/>
    <description>
    Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-8867/">CVE-2016-8867</cve>
	<bugzilla href="https://bugzilla.suse.com/1007249">SUSE bug 1007249</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168909" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8909</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8909" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8909" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8909" ref_url="https://www.suse.com/security/cve/CVE-2016-8909" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-8909/">CVE-2016-8909</cve>
	<bugzilla href="https://bugzilla.suse.com/1006536">SUSE bug 1006536</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1007160">SUSE bug 1007160</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20168910" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-8910</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-8910" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8910" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-8910" ref_url="https://www.suse.com/security/cve/CVE-2016-8910" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3/CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-8910/">CVE-2016-8910</cve>
	<bugzilla href="https://bugzilla.suse.com/1006538">SUSE bug 1006538</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1007157">SUSE bug 1007157</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024178">SUSE bug 1024178</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169015" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9015</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9015" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9015" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9015" ref_url="https://www.suse.com/security/cve/CVE-2016-9015" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005056.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0159-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability affects users using versions 1.17 and 1.18 of the urllib3 library, who are using the optional PyOpenSSL support for TLS instead of the regular standard library TLS backend, and who are using OpenSSL 1.1.0 via PyOpenSSL. This is an extremely uncommon configuration, so the security impact of this vulnerability is low.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-9015/">CVE-2016-9015</cve>
	<bugzilla href="https://bugzilla.suse.com/1023502">SUSE bug 1023502</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024540">SUSE bug 1024540</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760851" comment="python3-urllib3-1.24-9.10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169063" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9063</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9063" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9063" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9063" ref_url="https://www.suse.com/security/cve/CVE-2016-9063" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2299-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-September/003189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2872-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192872-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006536.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:2861-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2336-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-09/msg00004.html" source="SUSE-SU"/>
    <description>
    An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox &lt; 50.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9063/">CVE-2016-9063</cve>
	<bugzilla href="https://bugzilla.suse.com/1009026">SUSE bug 1009026</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1010424">SUSE bug 1010424</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1047240">SUSE bug 1047240</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123115">SUSE bug 1123115</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481944" comment="libexpat1-2.2.5-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169082" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9082</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9082" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9082" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9082" ref_url="https://www.suse.com/security/cve/CVE-2016-9082" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1453-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004095.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference) via a large svg file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9082/">CVE-2016-9082</cve>
	<bugzilla href="https://bugzilla.suse.com/1007255">SUSE bug 1007255</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481783" comment="libcairo2-1.16.0-1.55 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169101" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9101</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9101" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9101" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9101" ref_url="https://www.suse.com/security/cve/CVE-2016-9101" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
    <description>
    Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9101/">CVE-2016-9101</cve>
	<bugzilla href="https://bugzilla.suse.com/1007391">SUSE bug 1007391</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1013668">SUSE bug 1013668</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024181">SUSE bug 1024181</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169102" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9102</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9102" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9102" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9102" ref_url="https://www.suse.com/security/cve/CVE-2016-9102" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
    <description>
    Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate messages with the same fid number.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9102/">CVE-2016-9102</cve>
	<bugzilla href="https://bugzilla.suse.com/1007450">SUSE bug 1007450</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1014256">SUSE bug 1014256</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169103" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9103</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9103" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9103" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9103" ref_url="https://www.suse.com/security/cve/CVE-2016-9103" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
    <description>
    The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to them.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-9103/">CVE-2016-9103</cve>
	<bugzilla href="https://bugzilla.suse.com/1007454">SUSE bug 1007454</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1014259">SUSE bug 1014259</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169104" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9104</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9104" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9104" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9104" ref_url="https://www.suse.com/security/cve/CVE-2016-9104" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via a crafted offset, which triggers an out-of-bounds access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9104/">CVE-2016-9104</cve>
	<bugzilla href="https://bugzilla.suse.com/1007493">SUSE bug 1007493</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1014297">SUSE bug 1014297</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1034990">SUSE bug 1034990</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169105" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9105</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9105" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9105" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9105" ref_url="https://www.suse.com/security/cve/CVE-2016-9105" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fid object.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9105/">CVE-2016-9105</cve>
	<bugzilla href="https://bugzilla.suse.com/1007494">SUSE bug 1007494</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1014279">SUSE bug 1014279</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169106" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9106</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9106" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9106" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9106" ref_url="https://www.suse.com/security/cve/CVE-2016-9106" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-November/002411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:2988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3237-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00140.html" source="SUSE-SU"/>
    <description>
    Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) by leveraging failure to free an IO vector.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9106/">CVE-2016-9106</cve>
	<bugzilla href="https://bugzilla.suse.com/1007495">SUSE bug 1007495</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1014299">SUSE bug 1014299</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169178" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9178</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9178" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9178" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9178" ref_url="https://www.suse.com/security/cve/CVE-2016-9178" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2016:3058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00027.html" source="SUSE-SU"/>
    <description>
    The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel before 4.7.5 does not initialize a certain integer variable, which allows local users to obtain sensitive information from kernel stack memory by triggering failure of a get_user_ex call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-9178/">CVE-2016-9178</cve>
	<bugzilla href="https://bugzilla.suse.com/1008650">SUSE bug 1008650</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1012353">SUSE bug 1012353</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169313" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9313</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9313" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9313" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9313" ref_url="https://www.suse.com/security/cve/CVE-2016-9313" source="SUSE CVE"/>
    <description>
    security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9313/">CVE-2016-9313</cve>
	<bugzilla href="https://bugzilla.suse.com/1012356">SUSE bug 1012356</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169377" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9377</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9377" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9377" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9377" ref_url="https://www.suse.com/security/cve/CVE-2016-9377" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
    <description>
    Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9377/">CVE-2016-9377</cve>
	<bugzilla href="https://bugzilla.suse.com/1009108">SUSE bug 1009108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169378" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9378</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9378" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9378" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9378" ref_url="https://www.suse.com/security/cve/CVE-2016-9378" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
    <description>
    Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9378/">CVE-2016-9378</cve>
	<bugzilla href="https://bugzilla.suse.com/1009108">SUSE bug 1009108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169379" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9379</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9379" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9379" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9379" ref_url="https://www.suse.com/security/cve/CVE-2016-9379" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via string quotes and S-expressions in the bootloader configuration file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.9/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-9379/">CVE-2016-9379</cve>
	<bugzilla href="https://bugzilla.suse.com/1009111">SUSE bug 1009111</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169380" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9380</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9380" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9380" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9380" ref_url="https://www.suse.com/security/cve/CVE-2016-9380" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-9380/">CVE-2016-9380</cve>
	<bugzilla href="https://bugzilla.suse.com/1009111">SUSE bug 1009111</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169381" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9381</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9381" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9381" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9381" ref_url="https://www.suse.com/security/cve/CVE-2016-9381" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
    <description>
    Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9381/">CVE-2016-9381</cve>
	<bugzilla href="https://bugzilla.suse.com/1009109">SUSE bug 1009109</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169382" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9382</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9382" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9382" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9382" ref_url="https://www.suse.com/security/cve/CVE-2016-9382" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9382/">CVE-2016-9382</cve>
	<bugzilla href="https://bugzilla.suse.com/1009103">SUSE bug 1009103</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169383" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9383</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9383" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9383" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9383" ref_url="https://www.suse.com/security/cve/CVE-2016-9383" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host crash), or execute arbitrary code on the host by leveraging broken emulation of bit test instructions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9383/">CVE-2016-9383</cve>
	<bugzilla href="https://bugzilla.suse.com/1009107">SUSE bug 1009107</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169384" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9384</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9384" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9384" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9384" ref_url="https://www.suse.com/security/cve/CVE-2016-9384" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
    <description>
    Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-9384/">CVE-2016-9384</cve>
	<bugzilla href="https://bugzilla.suse.com/1009105">SUSE bug 1009105</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169385" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9385</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9385" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9385" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9385" ref_url="https://www.suse.com/security/cve/CVE-2016-9385" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9385/">CVE-2016-9385</cve>
	<bugzilla href="https://bugzilla.suse.com/1009104">SUSE bug 1009104</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169386" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9386</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9386" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9386" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9386" ref_url="https://www.suse.com/security/cve/CVE-2016-9386" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9386/">CVE-2016-9386</cve>
	<bugzilla href="https://bugzilla.suse.com/1009100">SUSE bug 1009100</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169401" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9401</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9401" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9401" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9401" ref_url="https://www.suse.com/security/cve/CVE-2016-9401" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002891.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1337-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002896.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1402-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00082.html" source="SUSE-SU"/>
    <description>
    popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-10-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9401/">CVE-2016-9401</cve>
	<bugzilla href="https://bugzilla.suse.com/1010845">SUSE bug 1010845</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1044328">SUSE bug 1044328</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123788">SUSE bug 1123788</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1159416">SUSE bug 1159416</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481750" comment="bash-4.4-9.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481754" comment="libreadline7-7.0-9.10.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169555" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9555</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9555" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9555" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9555" ref_url="https://www.suse.com/security/cve/CVE-2016-9555" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3039-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3049-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3063-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3094-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3096-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3098-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3100-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3104-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3112-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3113-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3116-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3117-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3183-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3197-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3205-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3206-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3249-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3050-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3061-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3077-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00034.html" source="SUSE-SU"/>
    <description>
    The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-20"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9555/">CVE-2016-9555</cve>
	<bugzilla href="https://bugzilla.suse.com/1011685">SUSE bug 1011685</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1012183">SUSE bug 1012183</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169577" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9577</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9577" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9577" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9577" ref_url="https://www.suse.com/security/cve/CVE-2016-9577" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0392-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0393-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0396-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0400-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0419-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0421-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00015.html" source="SUSE-SU"/>
    <description>
    A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9577/">CVE-2016-9577</cve>
	<bugzilla href="https://bugzilla.suse.com/1023078">SUSE bug 1023078</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169578" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9578</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9578" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9578" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9578" ref_url="https://www.suse.com/security/cve/CVE-2016-9578" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0392-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0393-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0396-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0400-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0419-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0421-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00015.html" source="SUSE-SU"/>
    <description>
    A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9578/">CVE-2016-9578</cve>
	<bugzilla href="https://bugzilla.suse.com/1023078">SUSE bug 1023078</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1023079">SUSE bug 1023079</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169586" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9586</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9586" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9586" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9586" ref_url="https://www.suse.com/security/cve/CVE-2016-9586" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1042-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1043-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1105-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00094.html" source="SUSE-SU"/>
    <description>
    curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary input filtering, it could allow remote attacks.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9586/">CVE-2016-9586</cve>
	<bugzilla href="https://bugzilla.suse.com/1015332">SUSE bug 1015332</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169588" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9588</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9588" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9588" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9588" ref_url="https://www.suse.com/security/cve/CVE-2016-9588" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    arch/x86/kvm/vmx.c in the Linux kernel through 4.9 mismanages the #BP and #OF exceptions, which allows guest OS users to cause a denial of service (guest OS crash) by declining to handle an exception thrown by an L2 guest.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.5/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-9588/">CVE-2016-9588</cve>
	<bugzilla href="https://bugzilla.suse.com/1015703">SUSE bug 1015703</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1017512">SUSE bug 1017512</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169594" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9594</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9594" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9594" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9594" ref_url="https://www.suse.com/security/cve/CVE-2016-9594" source="SUSE CVE"/>
    <description>
    curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 32bit random value.  Having a weak or virtually non-existent random value makes the operations that use it vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9594/">CVE-2016-9594</cve>
	<bugzilla href="https://bugzilla.suse.com/1016738">SUSE bug 1016738</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1017161">SUSE bug 1017161</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1042181">SUSE bug 1042181</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169602" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9602</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9602" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9602" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9602" ref_url="https://www.suse.com/security/cve/CVE-2016-9602" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9602/">CVE-2016-9602</cve>
	<bugzilla href="https://bugzilla.suse.com/1020427">SUSE bug 1020427</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169604" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9604</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9604" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9604" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9604" ref_url="https://www.suse.com/security/cve/CVE-2016-9604" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
    <description>
    It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstream, by joining it as its session keyring. This allows root to bypass module signature verification by adding a new public key of its own devising to the keyring.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-9604/">CVE-2016-9604</cve>
	<bugzilla href="https://bugzilla.suse.com/1035576">SUSE bug 1035576</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169637" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9637</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9637" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9637" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9637" ref_url="https://www.suse.com/security/cve/CVE-2016-9637" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3083-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9637/">CVE-2016-9637</cve>
	<bugzilla href="https://bugzilla.suse.com/1011652">SUSE bug 1011652</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169639" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9639</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9639" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9639" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9639" ref_url="https://www.suse.com/security/cve/CVE-2016-9639" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1053-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-04/msg00061.html" source="SUSE-SU"/>
    <description>
    Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="9.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2016-9639/">CVE-2016-9639</cve>
	<bugzilla href="https://bugzilla.suse.com/1012398">SUSE bug 1012398</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169756" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9756</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9756" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9756" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9756" ref_url="https://www.suse.com/security/cve/CVE-2016-9756" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0464-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0002-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00000.html" source="SUSE-SU"/>
    <description>
    arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.1/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-9756/">CVE-2016-9756</cve>
	<bugzilla href="https://bugzilla.suse.com/1013038">SUSE bug 1013038</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169776" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9776</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9776" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9776" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9776" ref_url="https://www.suse.com/security/cve/CVE-2016-9776" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0661-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1135-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could use this issue to crash the QEMU process on the host leading to DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3/CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-9776/">CVE-2016-9776</cve>
	<bugzilla href="https://bugzilla.suse.com/1013285">SUSE bug 1013285</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1013657">SUSE bug 1013657</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024182">SUSE bug 1024182</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169794" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9794</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9794" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9794" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9794" ref_url="https://www.suse.com/security/cve/CVE-2016-9794" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3146-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3188-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3217-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00081.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3248-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3252-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0227-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0228-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0229-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0230-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0231-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0234-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0235-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0244-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0246-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0248-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0249-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0267-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0268-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0278-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0293-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0294-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3050-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3118-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00057.html" source="SUSE-SU"/>
    <description>
    Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted SNDRV_PCM_TRIGGER_START command.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9794/">CVE-2016-9794</cve>
	<bugzilla href="https://bugzilla.suse.com/1013533">SUSE bug 1013533</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1013543">SUSE bug 1013543</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1013604">SUSE bug 1013604</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169797" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9797</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9797" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9797" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9797" ref_url="https://www.suse.com/security/cve/CVE-2016-9797" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1353-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1476-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html" source="SUSE-SU"/>
    <description>
    In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-9797/">CVE-2016-9797</cve>
	<bugzilla href="https://bugzilla.suse.com/1013708">SUSE bug 1013708</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1013712">SUSE bug 1013712</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760813" comment="libbluetooth3-5.48-13.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169798" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9798</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9798" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9798" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9798" ref_url="https://www.suse.com/security/cve/CVE-2016-9798" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1353-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3046-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006164.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1476-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2585-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2588-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00072.html" source="SUSE-SU"/>
    <description>
    In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-9798/">CVE-2016-9798</cve>
	<bugzilla href="https://bugzilla.suse.com/1013708">SUSE bug 1013708</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1013712">SUSE bug 1013712</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1013732">SUSE bug 1013732</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760813" comment="libbluetooth3-5.48-13.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169800" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9800</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9800" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9800" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9800" ref_url="https://www.suse.com/security/cve/CVE-2016-9800" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005161.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4259-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00064.html" source="SUSE-SU"/>
    <description>
    In BlueZ 5.42, a buffer overflow was observed in "pin_code_reply_dump" function in "tools/parser/hci.c" source file. The issue exists because "pin" array is overflowed by supplied parameter due to lack of boundary checks on size of the buffer from frame "pin_code_reply_cp *cp" parameter.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-9800/">CVE-2016-9800</cve>
	<bugzilla href="https://bugzilla.suse.com/1013721">SUSE bug 1013721</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760813" comment="libbluetooth3-5.48-13.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169801" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9801</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9801" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9801" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9801" ref_url="https://www.suse.com/security/cve/CVE-2016-9801" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:4188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005161.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4259-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00064.html" source="SUSE-SU"/>
    <description>
    In BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" function in "tools/parser/l2cap.c" source file when processing corrupted dump file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-9801/">CVE-2016-9801</cve>
	<bugzilla href="https://bugzilla.suse.com/1013732">SUSE bug 1013732</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760813" comment="libbluetooth3-5.48-13.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169802" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9802</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9802" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9802" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9802" ref_url="https://www.suse.com/security/cve/CVE-2016-9802" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1353-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1476-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html" source="SUSE-SU"/>
    <description>
    In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-9802/">CVE-2016-9802</cve>
	<bugzilla href="https://bugzilla.suse.com/1013893">SUSE bug 1013893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1015173">SUSE bug 1015173</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760813" comment="libbluetooth3-5.48-13.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169803" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9803</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9803" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9803" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9803" ref_url="https://www.suse.com/security/cve/CVE-2016-9803" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:3718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012661.html" source="SUSE-SU"/>
    <description>
    In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file. This issue exists because 'subevent' (which is used to read correct element from 'ev_le_meta_str' array) is overflowed.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-9803/">CVE-2016-9803</cve>
	<bugzilla href="https://bugzilla.suse.com/1013885">SUSE bug 1013885</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336474" comment="libbluetooth3 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169804" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9804</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9804" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9804" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9804" ref_url="https://www.suse.com/security/cve/CVE-2016-9804" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005161.html" source="SUSE-SU"/>
    <description>
    In BlueZ 5.42, a buffer overflow was observed in "commands_dump" function in "tools/parser/csr.c" source file. The issue exists because "commands" array is overflowed by supplied parameter due to lack of boundary checks on size of the buffer from frame "frm-&gt;ptr" parameter. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2016-9804/">CVE-2016-9804</cve>
	<bugzilla href="https://bugzilla.suse.com/1013877">SUSE bug 1013877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760813" comment="libbluetooth3-5.48-13.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169843" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9843</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9843" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9843" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9843" ref_url="https://www.suse.com/security/cve/CVE-2016-9843" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2016-December/002506.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-January/002540.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0004-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-January/002541.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1384-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002911.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1386-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1387-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002914.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1444-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2989-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1815-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004805.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3972-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183972-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0555-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190555-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0628-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190628-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005775.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2016:3202-1" ref_url="https://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0077-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0080-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2998-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0042-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3478-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0327-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00021.html" source="SUSE-SU"/>
    <description>
    The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9843/">CVE-2016-9843</cve>
	<bugzilla href="https://bugzilla.suse.com/1003580">SUSE bug 1003580</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1013882">SUSE bug 1013882</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1038505">SUSE bug 1038505</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1062104">SUSE bug 1062104</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1116686">SUSE bug 1116686</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1120866">SUSE bug 1120866</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123150">SUSE bug 1123150</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1127473">SUSE bug 1127473</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1184301">SUSE bug 1184301</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760838" comment="libz1-1.2.11-3.18.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169845" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9845</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9845" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9845" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9845" ref_url="https://www.suse.com/security/cve/CVE-2016-9845" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents of the host memory bytes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-9845/">CVE-2016-9845</cve>
	<bugzilla href="https://bugzilla.suse.com/1013767">SUSE bug 1013767</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169846" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9846</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9846" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9846" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9846" ref_url="https://www.suse.com/security/cve/CVE-2016-9846" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while updating the cursor data in update_cursor_data_virgl. A guest user/process could use this flaw to leak host memory bytes, resulting in DoS for a host.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9846/">CVE-2016-9846</cve>
	<bugzilla href="https://bugzilla.suse.com/1013764">SUSE bug 1013764</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169907" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9907</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9907" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9907" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9907" ref_url="https://www.suse.com/security/cve/CVE-2016-9907" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0661-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1135-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9907/">CVE-2016-9907</cve>
	<bugzilla href="https://bugzilla.suse.com/1014109">SUSE bug 1014109</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1014490">SUSE bug 1014490</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169908" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9908</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9908" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9908" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9908" ref_url="https://www.suse.com/security/cve/CVE-2016-9908" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
    <description>
    Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest user/process could use this flaw to leak contents of the host memory bytes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-9908/">CVE-2016-9908</cve>
	<bugzilla href="https://bugzilla.suse.com/1014514">SUSE bug 1014514</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169911" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9911</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9911" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9911" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9911" ref_url="https://www.suse.com/security/cve/CVE-2016-9911" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0661-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1135-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9911/">CVE-2016-9911</cve>
	<bugzilla href="https://bugzilla.suse.com/1014111">SUSE bug 1014111</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1014507">SUSE bug 1014507</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169912" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9912</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9912" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9912" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9912" ref_url="https://www.suse.com/security/cve/CVE-2016-9912" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
    <description>
    Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while destroying gpu resource object in 'virtio_gpu_resource_destroy'. A guest user/process could use this flaw to leak host memory bytes, resulting in DoS for a host.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9912/">CVE-2016-9912</cve>
	<bugzilla href="https://bugzilla.suse.com/1014112">SUSE bug 1014112</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169913" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9913</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9913" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9913" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9913" ref_url="https://www.suse.com/security/cve/CVE-2016-9913" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
    <description>
    Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) via vectors involving the order of resource cleanup.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9913/">CVE-2016-9913</cve>
	<bugzilla href="https://bugzilla.suse.com/1014110">SUSE bug 1014110</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1014311">SUSE bug 1014311</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169917" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9917</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9917" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9917" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9917" ref_url="https://www.suse.com/security/cve/CVE-2016-9917" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1353-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1476-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00069.html" source="SUSE-SU"/>
    <description>
    In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9917/">CVE-2016-9917</cve>
	<bugzilla href="https://bugzilla.suse.com/1015171">SUSE bug 1015171</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760813" comment="libbluetooth3-5.48-13.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169918" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9918</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9918" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9918" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9918" ref_url="https://www.suse.com/security/cve/CVE-2016-9918" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005494.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1198-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00054.html" source="SUSE-SU"/>
    <description>
    In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2016-9918/">CVE-2016-9918</cve>
	<bugzilla href="https://bugzilla.suse.com/1013893">SUSE bug 1013893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1015173">SUSE bug 1015173</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760813" comment="libbluetooth3-5.48-13.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169921" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9921</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9921" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9921" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9921" ref_url="https://www.suse.com/security/cve/CVE-2016-9921" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0571-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0661-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1135-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0665-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw to crash the Qemu process instance on the host, resulting in DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9921/">CVE-2016-9921</cve>
	<bugzilla href="https://bugzilla.suse.com/1014702">SUSE bug 1014702</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1015169">SUSE bug 1015169</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169922" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9922</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9922" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9922" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9922" ref_url="https://www.suse.com/security/cve/CVE-2016-9922" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0571-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0661-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1135-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0665-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest OS privileged users to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving blit pitch values.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9922/">CVE-2016-9922</cve>
	<bugzilla href="https://bugzilla.suse.com/1014702">SUSE bug 1014702</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1015169">SUSE bug 1015169</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169923" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9923</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9923" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9923" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9923" ref_url="https://www.suse.com/security/cve/CVE-2016-9923" source="SUSE CVE"/>
    <description>
    Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue. It could occur while hotplug and unplugging the device in the guest. A guest user/process could use this flaw to crash a Qemu process on the host resulting in DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2016-9923/">CVE-2016-9923</cve>
	<bugzilla href="https://bugzilla.suse.com/1014703">SUSE bug 1014703</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1015145">SUSE bug 1015145</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1015148">SUSE bug 1015148</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1015154">SUSE bug 1015154</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169932" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9932</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9932" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9932" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9932" ref_url="https://www.suse.com/security/cve/CVE-2016-9932" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2016:3207-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3208-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3221-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2016:3241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2016-12/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00003.html" source="SUSE-SU"/>
    <description>
    CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2016-9932/">CVE-2016-9932</cve>
	<bugzilla href="https://bugzilla.suse.com/1012651">SUSE bug 1012651</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1016340">SUSE bug 1016340</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20169962" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2016-9962</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2016-9962" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9962" source="CVE"/>
    <reference ref_id="SUSE CVE-2016-9962" ref_url="https://www.suse.com/security/cve/CVE-2016-9962" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1964-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-July/003069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005178.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1966-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-07/msg00093.html" source="SUSE-SU"/>
    <description>
    RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container.  This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2016-9962/">CVE-2016-9962</cve>
	<bugzilla href="https://bugzilla.suse.com/1012568">SUSE bug 1012568</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173425">SUSE bug 1173425</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629067" comment="containerd-1.3.9-5.29.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629072" comment="docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-6.45.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482602" comment="runc-1.0.0~rc10-1.9.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20170379" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-0379</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-0379" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0379" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-0379" ref_url="https://www.suse.com/security/cve/CVE-2017-0379" source="SUSE CVE"/>
    <description>
    Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-0379/">CVE-2017-0379</cve>
	<bugzilla href="https://bugzilla.suse.com/1055837">SUSE bug 1055837</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482233" comment="libgcrypt20-1.8.2-8.36.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20170381" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-0381</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-0381" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0381" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-0381" ref_url="https://www.suse.com/security/cve/CVE-2017-0381" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0436-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00031.html" source="SUSE-SU"/>
    <description>
    An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31607432.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-0381/">CVE-2017-0381</cve>
	<bugzilla href="https://bugzilla.suse.com/1020102">SUSE bug 1020102</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628819" comment="libopus0-1.3.1-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20170386" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-0386</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-0386" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0386" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-0386" ref_url="https://www.suse.com/security/cve/CVE-2017-0386" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012179.html" source="SUSE-SU"/>
    <description>
    An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-0386/">CVE-2017-0386</cve>
	<bugzilla href="https://bugzilla.suse.com/1020123">SUSE bug 1020123</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009654583" comment="libnl-config is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009654584" comment="libnl3-200 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20170663" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-0663</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-0663" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0663" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-0663" ref_url="https://www.suse.com/security/cve/CVE-2017-0663" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1670-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-July/003017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1746-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-07/msg00000.html" source="SUSE-SU"/>
    <description>
    A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37104170.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-0663/">CVE-2017-0663</cve>
	<bugzilla href="https://bugzilla.suse.com/1044337">SUSE bug 1044337</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000099" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000099</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000099" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000099" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000099" ref_url="https://www.suse.com/security/cve/CVE-2017-1000099" source="SUSE CVE"/>
    <description>
    When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers. The code doing this would send the wrong buffer to the user (stdout or the application's provide callback), which could lead to other private data from the heap to get inadvertently displayed. The wrong buffer was an uninitialized memory area allocated on the heap and if it turned out to not contain any zero byte, it would continue and display the data following that buffer in memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-1000099/">CVE-2017-1000099</cve>
	<bugzilla href="https://bugzilla.suse.com/1051645">SUSE bug 1051645</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1053919">SUSE bug 1053919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000100" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000100</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000100" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000100" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000100" ref_url="https://www.suse.com/security/cve/CVE-2017-1000100" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2174-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-September/003186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2205-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-08/msg00080.html" source="SUSE-SU"/>
    <description>
    When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 bytes), the file name is truncated to fit within the buffer boundaries, but the buffer size is still wrongly updated to use the untruncated length. This too large value is then used in the sendto() call, making curl attempt to send more data than what is actually put into the buffer. The endto() function will then read beyond the end of the heap based buffer. A malicious HTTP(S) server could redirect a vulnerable libcurl-using client to a crafted TFTP URL (if the client hasn't restricted which protocols it allows redirects to) and trick it to send private memory contents to a remote server over UDP. Limit curl's redirect protocols with --proto-redir and libcurl's with CURLOPT_REDIR_PROTOCOLS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-1000100/">CVE-2017-1000100</cve>
	<bugzilla href="https://bugzilla.suse.com/1051644">SUSE bug 1051644</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000101" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000101</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000101" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000101" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000101" ref_url="https://www.suse.com/security/cve/CVE-2017-1000101" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2174-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2205-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-08/msg00080.html" source="SUSE-SU"/>
    <description>
    curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfers. In the globbing function that parses the numerical range, there was an omission that made curl read a byte beyond the end of the URL if given a carefully crafted, or just wrongly written, URL. The URL is stored in a heap based buffer, so it could then be made to wrongly read something else instead of crashing. An example of a URL that triggers the flaw would be `http://ur%20[0-60000000000000000000`.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-1000101/">CVE-2017-1000101</cve>
	<bugzilla href="https://bugzilla.suse.com/1051643">SUSE bug 1051643</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000249" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000249</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000249" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000249" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000249" ref_url="https://www.suse.com/security/cve/CVE-2017-1000249" source="SUSE CVE"/>
    <description>
    An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an ELF binary. This was fixed in commit 35c94dc6acc418f1ad7f6241a6680e5327495793 (Aug 2017).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-1000249/">CVE-2017-1000249</cve>
	<bugzilla href="https://bugzilla.suse.com/1056838">SUSE bug 1056838</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628435" comment="file-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628437" comment="file-magic-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628438" comment="libmagic1-5.32-7.11.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000250" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000250</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000250" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000250" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000250" ref_url="https://www.suse.com/security/cve/CVE-2017-1000250" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005161.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2810-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00069.html" source="SUSE-SU"/>
    <description>
    All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-1000250/">CVE-2017-1000250</cve>
	<bugzilla href="https://bugzilla.suse.com/1057342">SUSE bug 1057342</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336474" comment="libbluetooth3 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000251" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000251</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000251" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000251" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000251" ref_url="https://www.suse.com/security/cve/CVE-2017-1000251" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2521-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2523-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2534-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2548-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2694-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2769-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2770-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2772-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2773-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2776-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2777-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2779-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2780-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2781-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2782-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2783-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2784-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2787-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2788-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2790-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2792-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2793-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2794-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2796-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2797-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2798-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2799-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2800-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2803-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2804-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2805-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2806-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2807-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2809-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2811-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2816-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2956-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="TID000019028" ref_url="https://www.suse.com/support/kb/doc/?id=000019028" source="SUSE-SU"/>
		<reference ref_id="TID7021383" ref_url="https://www.suse.com/support/kb/doc/?id=7021383" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2495-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00057.html" source="SUSE-SU"/>
    <description>
    The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-1000251/">CVE-2017-1000251</cve>
	<bugzilla href="https://bugzilla.suse.com/1057389">SUSE bug 1057389</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1057950">SUSE bug 1057950</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1070535">SUSE bug 1070535</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1072162">SUSE bug 1072162</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1120758">SUSE bug 1120758</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000254" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000254</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000254" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000254" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000254" ref_url="https://www.suse.com/security/cve/CVE-2017-1000254" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003350.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2861-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003359.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-December/003464.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003630.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2880-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00098.html" source="SUSE-SU"/>
    <description>
    libcurl may read outside of a heap allocated buffer when doing FTP. When libcurl connects to an FTP server and successfully logs in (anonymous or not), it asks the server for the current directory with the `PWD` command. The server then responds with a 257 response containing the path, inside double quotes. The returned path name is then kept by libcurl for subsequent uses. Due to a flaw in the string parser for this directory name, a directory name passed like this but without a closing double quote would lead to libcurl not adding a trailing NUL byte to the buffer holding the name. When libcurl would then later access the string, it could read beyond the allocated heap buffer and crash or wrongly access data beyond the buffer, thinking it was part of the path. A malicious server could abuse this fact and effectively prevent libcurl-based clients to work with it - the PWD command is always issued on new FTP connections and the mistake has a high chance of causing a segfault. The simple fact that this has issue remained undiscovered for this long could suggest that malformed PWD responses are rare in benign servers. We are not aware of any exploit of this flaw. This bug was introduced in commit [415d2e7cb7](https://github.com/curl/curl/commit/415d2e7cb7), March 2005. In libcurl version 7.56.0, the parser always zero terminates the string but also rejects it if not terminated properly with a final double quote.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-1000254/">CVE-2017-1000254</cve>
	<bugzilla href="https://bugzilla.suse.com/1061876">SUSE bug 1061876</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000256" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000256</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000256" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000256" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000256" ref_url="https://www.suse.com/security/cve/CVE-2017-1000256" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003354.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2878-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00096.html" source="SUSE-SU"/>
    <description>
    libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-1000256/">CVE-2017-1000256</cve>
	<bugzilla href="https://bugzilla.suse.com/1062563">SUSE bug 1062563</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000257" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000257</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000257" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000257" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000257" ref_url="https://www.suse.com/security/cve/CVE-2017-1000257" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003350.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2861-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003359.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2880-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00098.html" source="SUSE-SU"/>
    <description>
    An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data function treats zero as a magic number and invokes strlen() on the data to figure out the length. The strlen() is called on a heap based buffer that might not be zero terminated so libcurl might read beyond the end of it into whatever memory lies after (or just crash) and then deliver that to the application as if it was actually downloaded.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.8/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-1000257/">CVE-2017-1000257</cve>
	<bugzilla href="https://bugzilla.suse.com/1063824">SUSE bug 1063824</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000366" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000366</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000366" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000366" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000366" ref_url="https://www.suse.com/security/cve/CVE-2017-1000366" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1614-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1619-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1621-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="TID7020973" ref_url="https://www.suse.com/support/kb/doc/?id=7020973" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1629-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00024.html" source="SUSE-SU"/>
    <description>
    glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-1000366/">CVE-2017-1000366</cve>
	<bugzilla href="https://bugzilla.suse.com/1037551">SUSE bug 1037551</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039357">SUSE bug 1039357</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1071319">SUSE bug 1071319</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000367" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000367</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000367" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000367" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000367" ref_url="https://www.suse.com/security/cve/CVE-2017-1000367" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1446-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1450-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1455-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00079.html" source="SUSE-SU"/>
    <description>
    Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-1000367/">CVE-2017-1000367</cve>
	<bugzilla href="https://bugzilla.suse.com/1007501">SUSE bug 1007501</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039361">SUSE bug 1039361</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1042146">SUSE bug 1042146</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1077345">SUSE bug 1077345</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760863" comment="sudo-1.8.22-4.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000368" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000368</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000368" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000368" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000368" ref_url="https://www.suse.com/security/cve/CVE-2017-1000368" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1626-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1627-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-July/003004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="TID7021027" ref_url="https://www.suse.com/support/kb/doc/?id=7021027" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1697-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00034.html" source="SUSE-SU"/>
    <description>
    Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-1000368/">CVE-2017-1000368</cve>
	<bugzilla href="https://bugzilla.suse.com/1039361">SUSE bug 1039361</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1042146">SUSE bug 1042146</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1045986">SUSE bug 1045986</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760863" comment="sudo-1.8.22-4.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000370" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000370</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000370" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000370" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000370" ref_url="https://www.suse.com/security/cve/CVE-2017-1000370" source="SUSE CVE"/>
    <description>
    The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nullifying the protection of the offset2lib patch. This affects Linux Kernel version 4.11.5 and earlier. This is a different issue than CVE-2017-1000371. This issue appears to be limited to i386 based systems.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-12"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2017-1000370/">CVE-2017-1000370</cve>
	<bugzilla href="https://bugzilla.suse.com/1037551">SUSE bug 1037551</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039346">SUSE bug 1039346</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039349">SUSE bug 1039349</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039354">SUSE bug 1039354</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000371" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000371</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000371" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000371" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000371" ref_url="https://www.suse.com/security/cve/CVE-2017-1000371" source="SUSE CVE"/>
    <description>
    The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-write segment and the start of the stack becomes small enough that the stack guard page can be jumped over by an attacker. This affects Linux Kernel version 4.11.5. This is a different issue than CVE-2017-1000370 and CVE-2017-1000365. This issue appears to be limited to i386 based systems.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-12"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2017-1000371/">CVE-2017-1000371</cve>
	<bugzilla href="https://bugzilla.suse.com/1037551">SUSE bug 1037551</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039346">SUSE bug 1039346</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039349">SUSE bug 1039349</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039354">SUSE bug 1039354</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000380" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000380</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000380" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000380" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000380" ref_url="https://www.suse.com/security/cve/CVE-2017-1000380" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1633-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00026.html" source="SUSE-SU"/>
    <description>
    sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-12"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-1000380/">CVE-2017-1000380</cve>
	<bugzilla href="https://bugzilla.suse.com/1044125">SUSE bug 1044125</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000382" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000382</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000382" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000382" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000382" ref_url="https://www.suse.com/security/cve/CVE-2017-1000382" source="SUSE CVE"/>
    <description>
    VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-1000382/">CVE-2017-1000382</cve>
	<bugzilla href="https://bugzilla.suse.com/1065958">SUSE bug 1065958</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1070955">SUSE bug 1070955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760864" comment="vim-data-common-8.0.1568-5.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760865" comment="vim-small-8.0.1568-5.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000408" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000408</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000408" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000408" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000408" ref_url="https://www.suse.com/security/cve/CVE-2017-1000408" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0089-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00040.html" source="SUSE-SU"/>
    <description>
    A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-1000408/">CVE-2017-1000408</cve>
	<bugzilla href="https://bugzilla.suse.com/1039357">SUSE bug 1039357</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1071319">SUSE bug 1071319</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20171000409" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-1000409</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-1000409" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000409" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-1000409" ref_url="https://www.suse.com/security/cve/CVE-2017-1000409" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0089-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00040.html" source="SUSE-SU"/>
    <description>
    A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-1000409/">CVE-2017-1000409</cve>
	<bugzilla href="https://bugzilla.suse.com/1071319">SUSE bug 1071319</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201710661" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-10661</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-10661" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10661" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-10661" ref_url="https://www.suse.com/security/cve/CVE-2017-10661" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2694-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3286-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3287-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3288-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3289-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3291-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3292-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3293-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3296-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3299-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3302-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3303-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3305-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3306-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3308-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3309-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3310-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3312-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3313-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3316-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3318-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3320-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3321-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3322-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3323-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3332-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3337-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3340-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00073.html" source="SUSE-SU"/>
    <description>
    Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-10661/">CVE-2017-10661</cve>
	<bugzilla href="https://bugzilla.suse.com/1053152">SUSE bug 1053152</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1053153">SUSE bug 1053153</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201710664" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-10664</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-10664" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10664" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-10664" ref_url="https://www.suse.com/security/cve/CVE-2017-10664" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2326-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2327-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2327-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2416-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2450-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2941-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00008.html" source="SUSE-SU"/>
    <description>
    qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-10664/">CVE-2017-10664</cve>
	<bugzilla href="https://bugzilla.suse.com/1046636">SUSE bug 1046636</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1046637">SUSE bug 1046637</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201710806" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-10806</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-10806" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10806" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-10806" ref_url="https://www.suse.com/security/cve/CVE-2017-10806" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2416-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2450-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2941-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00008.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-10806/">CVE-2017-10806</cve>
	<bugzilla href="https://bugzilla.suse.com/1047674">SUSE bug 1047674</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1047675">SUSE bug 1047675</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201710911" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-10911</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-10911" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10911" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-10911" ref_url="https://www.suse.com/security/cve/CVE-2017-10911" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1795-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2924-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2938-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2941-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00008.html" source="SUSE-SU"/>
    <description>
    The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-10911/">CVE-2017-10911</cve>
	<bugzilla href="https://bugzilla.suse.com/1042863">SUSE bug 1042863</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1043330">SUSE bug 1043330</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1057378">SUSE bug 1057378</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201711176" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-11176</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-11176" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11176" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-11176" ref_url="https://www.suse.com/security/cve/CVE-2017-11176" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
    <description>
    The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2017-11176/">CVE-2017-11176</cve>
	<bugzilla href="https://bugzilla.suse.com/1048275">SUSE bug 1048275</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201711334" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-11334</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-11334" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11334" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-11334" ref_url="https://www.suse.com/security/cve/CVE-2017-11334" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2416-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2450-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2941-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00008.html" source="SUSE-SU"/>
    <description>
    The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-11334/">CVE-2017-11334</cve>
	<bugzilla href="https://bugzilla.suse.com/1048902">SUSE bug 1048902</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1048920">SUSE bug 1048920</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201711368" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-11368</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-11368" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11368" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-11368" ref_url="https://www.suse.com/security/cve/CVE-2017-11368" source="SUSE CVE"/>
    <description>
    In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-11368/">CVE-2017-11368</cve>
	<bugzilla href="https://bugzilla.suse.com/1049819">SUSE bug 1049819</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201711423" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-11423</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-11423" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11423" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-11423" ref_url="https://www.suse.com/security/cve/CVE-2017-11423" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0254-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0255-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0809-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0863-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0258-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0825-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00062.html" source="SUSE-SU"/>
    <description>
    The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-11423/">CVE-2017-11423</cve>
	<bugzilla href="https://bugzilla.suse.com/1049423">SUSE bug 1049423</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1083915">SUSE bug 1083915</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482310" comment="libmspack0-0.6-3.8.19 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201711434" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-11434</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-11434" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11434" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-11434" ref_url="https://www.suse.com/security/cve/CVE-2017-11434" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2326-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2327-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2327-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2416-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2450-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2941-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00008.html" source="SUSE-SU"/>
    <description>
    The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options string.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.6/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-11434/">CVE-2017-11434</cve>
	<bugzilla href="https://bugzilla.suse.com/1049381">SUSE bug 1049381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1049578">SUSE bug 1049578</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201711462" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-11462</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-11462" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11462" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-11462" ref_url="https://www.suse.com/security/cve/CVE-2017-11462" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003277.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2861-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003359.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003861.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2712-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00041.html" source="SUSE-SU"/>
    <description>
    Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-11462/">CVE-2017-11462</cve>
	<bugzilla href="https://bugzilla.suse.com/1056995">SUSE bug 1056995</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122468">SUSE bug 1122468</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201711472" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-11472</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-11472" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11472" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-11472" ref_url="https://www.suse.com/security/cve/CVE-2017-11472" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2869-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2956-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2495-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00057.html" source="SUSE-SU"/>
    <description>
    The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-11472/">CVE-2017-11472</cve>
	<bugzilla href="https://bugzilla.suse.com/1049580">SUSE bug 1049580</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201711600" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-11600</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-11600" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11600" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-11600" ref_url="https://www.suse.com/security/cve/CVE-2017-11600" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:3398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3410-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0031-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004430.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004433.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004435.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004468.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3358-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3359-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00079.html" source="SUSE-SU"/>
    <description>
    net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of xfrm_userpolicy_id is XFRM_POLICY_MAX or less, which allows local users to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via an XFRM_MSG_MIGRATE xfrm Netlink message.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2017-11600/">CVE-2017-11600</cve>
	<bugzilla href="https://bugzilla.suse.com/1050231">SUSE bug 1050231</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1096564">SUSE bug 1096564</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201711695" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-11695</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-11695" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11695" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-11695" ref_url="https://www.suse.com/security/cve/CVE-2017-11695" source="SUSE CVE"/>
    <description>
    Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-11695/">CVE-2017-11695</cve>
	<bugzilla href="https://bugzilla.suse.com/1053418">SUSE bug 1053418</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1053419">SUSE bug 1053419</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1053420">SUSE bug 1053420</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1053422">SUSE bug 1053422</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009338955" comment="libfreebl3 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338959" comment="libsoftokn3 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338881" comment="mozilla-nss is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338964" comment="mozilla-nss-certs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201711696" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-11696</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-11696" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11696" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-11696" ref_url="https://www.suse.com/security/cve/CVE-2017-11696" source="SUSE CVE"/>
    <description>
    Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-11696/">CVE-2017-11696</cve>
	<bugzilla href="https://bugzilla.suse.com/1053418">SUSE bug 1053418</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1053419">SUSE bug 1053419</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1053420">SUSE bug 1053420</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1053422">SUSE bug 1053422</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009338955" comment="libfreebl3 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338959" comment="libsoftokn3 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338881" comment="mozilla-nss is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338964" comment="mozilla-nss-certs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201711698" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-11698</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-11698" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11698" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-11698" ref_url="https://www.suse.com/security/cve/CVE-2017-11698" source="SUSE CVE"/>
    <description>
    Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-11698/">CVE-2017-11698</cve>
	<bugzilla href="https://bugzilla.suse.com/1053418">SUSE bug 1053418</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1053419">SUSE bug 1053419</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1053420">SUSE bug 1053420</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1053422">SUSE bug 1053422</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009338955" comment="libfreebl3 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338959" comment="libsoftokn3 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338881" comment="mozilla-nss is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338964" comment="mozilla-nss-certs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201712132" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-12132</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-12132" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12132" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-12132" ref_url="https://www.suse.com/security/cve/CVE-2017-12132" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0451-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0565-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004372.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00039.html" source="SUSE-SU"/>
    <description>
    The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-12132/">CVE-2017-12132</cve>
	<bugzilla href="https://bugzilla.suse.com/1051791">SUSE bug 1051791</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201712133" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-12133</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-12133" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12133" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-12133" ref_url="https://www.suse.com/security/cve/CVE-2017-12133" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003802.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0874-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003870.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0668-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-03/msg00037.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-12133/">CVE-2017-12133</cve>
	<bugzilla href="https://bugzilla.suse.com/1081556">SUSE bug 1081556</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/980854">SUSE bug 980854</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201712135" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-12135</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-12135" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12135" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-12135" ref_url="https://www.suse.com/security/cve/CVE-2017-12135" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2326-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2327-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2327-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2450-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00022.html" source="SUSE-SU"/>
    <description>
    Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2017-12135/">CVE-2017-12135</cve>
	<bugzilla href="https://bugzilla.suse.com/1051787">SUSE bug 1051787</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1169392">SUSE bug 1169392</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201712136" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-12136</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-12136" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12136" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-12136" ref_url="https://www.suse.com/security/cve/CVE-2017-12136" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2326-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2327-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2327-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00022.html" source="SUSE-SU"/>
    <description>
    Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-12136/">CVE-2017-12136</cve>
	<bugzilla href="https://bugzilla.suse.com/1051789">SUSE bug 1051789</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201712137" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-12137</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-12137" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12137" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-12137" ref_url="https://www.suse.com/security/cve/CVE-2017-12137" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2319-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2326-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2327-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2327-2" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2339-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2450-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2394-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00022.html" source="SUSE-SU"/>
    <description>
    arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-12137/">CVE-2017-12137</cve>
	<bugzilla href="https://bugzilla.suse.com/1051788">SUSE bug 1051788</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201712153" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-12153</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-12153" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12153" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-12153" ref_url="https://www.suse.com/security/cve/CVE-2017-12153" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2869-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3267-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2739-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2741-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00019.html" source="SUSE-SU"/>
    <description>
    A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are present in a Netlink request. This request can be issued by a user with the CAP_NET_ADMIN capability and may result in a NULL pointer dereference and system crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-12153/">CVE-2017-12153</cve>
	<bugzilla href="https://bugzilla.suse.com/1058410">SUSE bug 1058410</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1058624">SUSE bug 1058624</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201712652" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-12652</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-12652" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12652" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-12652" ref_url="https://www.suse.com/security/cve/CVE-2017-12652" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3060-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3060-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0911-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006673.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016340.html" source="SUSE-SU"/>
    <description>
    libpng before 1.6.32 does not properly check the length of chunks against the user limit.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-09-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-12652/">CVE-2017-12652</cve>
	<bugzilla href="https://bugzilla.suse.com/1141493">SUSE bug 1141493</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482352" comment="libpng16-16-1.6.34-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201712791" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-12791</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-12791" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12791" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-12791" ref_url="https://www.suse.com/security/cve/CVE-2017-12791" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2666-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003279.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2674-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-October/003281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2383-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-09/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2822-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1053-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-04/msg00061.html" source="SUSE-SU"/>
    <description>
    Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-12791/">CVE-2017-12791</cve>
	<bugzilla href="https://bugzilla.suse.com/1053955">SUSE bug 1053955</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1062462">SUSE bug 1062462</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201712814" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-12814</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-12814" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12814" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-12814" ref_url="https://www.suse.com/security/cve/CVE-2017-12814" source="SUSE CVE"/>
    <description>
    Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrary code via a long environment variable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-23"/>
	<updated date="2023-09-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-12814/">CVE-2017-12814</cve>
	<bugzilla href="https://bugzilla.suse.com/1057727">SUSE bug 1057727</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334114" comment="perl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336057" comment="perl-base is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201712837" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-12837</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-12837" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12837" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-12837" ref_url="https://www.suse.com/security/cve/CVE-2017-12837" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-November/003416.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003580.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3101-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-11/msg00083.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-12837/">CVE-2017-12837</cve>
	<bugzilla href="https://bugzilla.suse.com/1057724">SUSE bug 1057724</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760842" comment="perl-5.26.1-7.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760843" comment="perl-base-5.26.1-7.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201712883" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-12883</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-12883" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12883" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-12883" ref_url="https://www.suse.com/security/cve/CVE-2017-12883" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-November/003416.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003580.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3101-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-11/msg00083.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-12883/">CVE-2017-12883</cve>
	<bugzilla href="https://bugzilla.suse.com/1057721">SUSE bug 1057721</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760842" comment="perl-5.26.1-7.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760843" comment="perl-base-5.26.1-7.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713077" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13077</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13077" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13077" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13077" ref_url="https://www.suse.com/security/cve/CVE-2017-13077" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="TID7022107" ref_url="https://www.suse.com/support/kb/doc/?id=7022107" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-13077/">CVE-2017-13077</cve>
	<bugzilla href="https://bugzilla.suse.com/1056061">SUSE bug 1056061</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063479">SUSE bug 1063479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063963">SUSE bug 1063963</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179588">SUSE bug 1179588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713078" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13078</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13078" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13078" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13078" ref_url="https://www.suse.com/security/cve/CVE-2017-13078" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2752-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="TID7022107" ref_url="https://www.suse.com/support/kb/doc/?id=7022107" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2755-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-13078/">CVE-2017-13078</cve>
	<bugzilla href="https://bugzilla.suse.com/1056061">SUSE bug 1056061</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063479">SUSE bug 1063479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063667">SUSE bug 1063667</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179588">SUSE bug 1179588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713079" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13079</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13079" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13079" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13079" ref_url="https://www.suse.com/security/cve/CVE-2017-13079" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2752-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="TID7022107" ref_url="https://www.suse.com/support/kb/doc/?id=7022107" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2755-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-13079/">CVE-2017-13079</cve>
	<bugzilla href="https://bugzilla.suse.com/1056061">SUSE bug 1056061</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063479">SUSE bug 1063479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179588">SUSE bug 1179588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713080" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13080</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13080" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13080" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13080" ref_url="https://www.suse.com/security/cve/CVE-2017-13080" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2752-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2869-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3072-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3076-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3106-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3116-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3117-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3118-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3120-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3121-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3122-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3125-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3128-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3129-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3130-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3131-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3132-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3136-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3139-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3145-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3146-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3148-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3149-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3150-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3151-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3152-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3157-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3158-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3159-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3160-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00081.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3165-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3267-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="TID7022107" ref_url="https://www.suse.com/support/kb/doc/?id=7022107" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2755-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2846-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2905-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00085.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-13080/">CVE-2017-13080</cve>
	<bugzilla href="https://bugzilla.suse.com/1056061">SUSE bug 1056061</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063479">SUSE bug 1063479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063667">SUSE bug 1063667</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063671">SUSE bug 1063671</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1066295">SUSE bug 1066295</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105108">SUSE bug 1105108</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178872">SUSE bug 1178872</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179588">SUSE bug 1179588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760799" comment="kernel-firmware-20200107-3.15.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713081" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13081</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13081" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13081" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13081" ref_url="https://www.suse.com/security/cve/CVE-2017-13081" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2752-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3106-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="TID7022107" ref_url="https://www.suse.com/support/kb/doc/?id=7022107" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2755-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3144-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-13081/">CVE-2017-13081</cve>
	<bugzilla href="https://bugzilla.suse.com/1056061">SUSE bug 1056061</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063479">SUSE bug 1063479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1066295">SUSE bug 1066295</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105108">SUSE bug 1105108</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179588">SUSE bug 1179588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760799" comment="kernel-firmware-20200107-3.15.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713082" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13082</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13082" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13082" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13082" ref_url="https://www.suse.com/security/cve/CVE-2017-13082" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="TID7022107" ref_url="https://www.suse.com/support/kb/doc/?id=7022107" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0222-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-13082/">CVE-2017-13082</cve>
	<bugzilla href="https://bugzilla.suse.com/1056061">SUSE bug 1056061</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063479">SUSE bug 1063479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179588">SUSE bug 1179588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713086" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13086</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13086" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13086" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13086" ref_url="https://www.suse.com/security/cve/CVE-2017-13086" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-13086/">CVE-2017-13086</cve>
	<bugzilla href="https://bugzilla.suse.com/1056061">SUSE bug 1056061</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063479">SUSE bug 1063479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179588">SUSE bug 1179588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713087" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13087</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13087" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13087" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13087" ref_url="https://www.suse.com/security/cve/CVE-2017-13087" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2752-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2755-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-13087/">CVE-2017-13087</cve>
	<bugzilla href="https://bugzilla.suse.com/1056061">SUSE bug 1056061</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063479">SUSE bug 1063479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179588">SUSE bug 1179588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713088" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13088</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13088" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13088" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13088" ref_url="https://www.suse.com/security/cve/CVE-2017-13088" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2752-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2755-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2896-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-13088/">CVE-2017-13088</cve>
	<bugzilla href="https://bugzilla.suse.com/1056061">SUSE bug 1056061</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063479">SUSE bug 1063479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179588">SUSE bug 1179588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713168" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13168</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13168" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13168" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13168" ref_url="https://www.suse.com/security/cve/CVE-2017-13168" source="SUSE CVE"/>
    <description>
    An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2017-13168/">CVE-2017-13168</cve>
	<bugzilla href="https://bugzilla.suse.com/1072831">SUSE bug 1072831</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713215" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13215</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13215" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13215" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13215" ref_url="https://www.suse.com/security/cve/CVE-2017-13215" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0555-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0660-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0841-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00070.html" source="SUSE-SU"/>
    <description>
    A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-13215/">CVE-2017-13215</cve>
	<bugzilla href="https://bugzilla.suse.com/1075908">SUSE bug 1075908</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1091815">SUSE bug 1091815</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713220" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13220</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13220" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13220" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13220" ref_url="https://www.suse.com/security/cve/CVE-2017-13220" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1220-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1221-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00021.html" source="SUSE-SU"/>
    <description>
    An elevation of privilege vulnerability in the Upstream kernel bluez. Product: Android. Versions: Android kernel. Android ID: A-63527053.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2017-13220/">CVE-2017-13220</cve>
	<bugzilla href="https://bugzilla.suse.com/1076537">SUSE bug 1076537</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713672" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13672</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13672" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13672" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13672" ref_url="https://www.suse.com/security/cve/CVE-2017-13672" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2924-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3239-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3242-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2938-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2941-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00042.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3/CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-13672/">CVE-2017-13672</cve>
	<bugzilla href="https://bugzilla.suse.com/1056334">SUSE bug 1056334</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1056336">SUSE bug 1056336</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1084604">SUSE bug 1084604</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713673" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13673</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13673" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13673" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13673" ref_url="https://www.suse.com/security/cve/CVE-2017-13673" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005184.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00042.html" source="SUSE-SU"/>
    <description>
    The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of service (assertion failure) in the cpu_physical_memory_snapshot_get_dirty function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3/CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-13673/">CVE-2017-13673</cve>
	<bugzilla href="https://bugzilla.suse.com/1056386">SUSE bug 1056386</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1056387">SUSE bug 1056387</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1084604">SUSE bug 1084604</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713693" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13693</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13693" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13693" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13693" ref_url="https://www.suse.com/security/cve/CVE-2017-13693" source="SUSE CVE"/>
    <description>
    The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-13693/">CVE-2017-13693</cve>
	<bugzilla href="https://bugzilla.suse.com/1055713">SUSE bug 1055713</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713694" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13694</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13694" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13694" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13694" ref_url="https://www.suse.com/security/cve/CVE-2017-13694" source="SUSE CVE"/>
    <description>
    The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-13694/">CVE-2017-13694</cve>
	<bugzilla href="https://bugzilla.suse.com/1055705">SUSE bug 1055705</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201713711" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-13711</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-13711" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13711" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-13711" ref_url="https://www.suse.com/security/cve/CVE-2017-13711" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2924-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2938-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00007.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-13711/">CVE-2017-13711</cve>
	<bugzilla href="https://bugzilla.suse.com/1056291">SUSE bug 1056291</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714051" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14051</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14051" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14051" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14051" ref_url="https://www.suse.com/security/cve/CVE-2017-14051" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2694-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2869-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2956-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2384-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2495-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00057.html" source="SUSE-SU"/>
    <description>
    An integer overflow in the qla2x00_sysfs_write_optrom_ctl function in drivers/scsi/qla2xxx/qla_attr.c in the Linux kernel through 4.12.10 allows local users to cause a denial of service (memory corruption and system crash) by leveraging root access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-14051/">CVE-2017-14051</cve>
	<bugzilla href="https://bugzilla.suse.com/1056588">SUSE bug 1056588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714062" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14062</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14062" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14062" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14062" ref_url="https://www.suse.com/security/cve/CVE-2017-14062" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003874.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0903-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003879.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0891-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-04/msg00010.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-14062/">CVE-2017-14062</cve>
	<bugzilla href="https://bugzilla.suse.com/1056450">SUSE bug 1056450</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087709">SUSE bug 1087709</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118435">SUSE bug 1118435</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123123">SUSE bug 1123123</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173590">SUSE bug 1173590</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482248" comment="libidn11-1.34-3.2.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714106" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14106</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14106" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14106" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14106" ref_url="https://www.suse.com/security/cve/CVE-2017-14106" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2869-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2956-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2495-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00057.html" source="SUSE-SU"/>
    <description>
    The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-14106/">CVE-2017-14106</cve>
	<bugzilla href="https://bugzilla.suse.com/1056982">SUSE bug 1056982</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714140" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14140</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14140" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14140" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14140" ref_url="https://www.suse.com/security/cve/CVE-2017-14140" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2694-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
    <description>
    The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local attacker to learn the memory layout of a setuid executable despite ASLR.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-14140/">CVE-2017-14140</cve>
	<bugzilla href="https://bugzilla.suse.com/1057179">SUSE bug 1057179</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714160" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14160</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14160" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14160" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14160" ref_url="https://www.suse.com/security/cve/CVE-2017-14160" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1345-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00084.html" source="SUSE-SU"/>
    <description>
    The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-14160/">CVE-2017-14160</cve>
	<bugzilla href="https://bugzilla.suse.com/1059812">SUSE bug 1059812</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1091072">SUSE bug 1091072</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481533" comment="libvorbis0-1.3.6-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481534" comment="libvorbisenc2-1.3.6-4.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714167" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14167</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14167" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14167" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14167" ref_url="https://www.suse.com/security/cve/CVE-2017-14167" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2924-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2938-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2941-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00008.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the load_multiboot function in hw/i386/multiboot.c in QEMU (aka Quick Emulator) allows local guest OS users to execute arbitrary code on the host via crafted multiboot header address values, which trigger an out-of-bounds write.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-14167/">CVE-2017-14167</cve>
	<bugzilla href="https://bugzilla.suse.com/1057585">SUSE bug 1057585</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714316" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14316</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14316" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14316" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14316" ref_url="https://www.suse.com/security/cve/CVE-2017-14316" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2420-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2450-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2466-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-September/003223.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2519-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2514-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2540-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00078.html" source="SUSE-SU"/>
    <description>
    A parameter verification issue was discovered in Xen through 4.9.x. The function `alloc_heap_pages` allows callers to specify the first NUMA node that should be used for allocations through the `memflags` parameter; the node is extracted using the `MEMF_get_node` macro. While the function checks to see if the special constant `NUMA_NO_NODE` is specified, it otherwise does not handle the case where `node &gt;= MAX_NUMNODES`. This allows an out-of-bounds access to an internal array.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-14316/">CVE-2017-14316</cve>
	<bugzilla href="https://bugzilla.suse.com/1056278">SUSE bug 1056278</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1072198">SUSE bug 1072198</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1072223">SUSE bug 1072223</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714489" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14489</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14489" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14489" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14489" ref_url="https://www.suse.com/security/cve/CVE-2017-14489" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2869-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3165-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3267-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2739-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2741-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00019.html" source="SUSE-SU"/>
    <description>
    The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (panic) by leveraging incorrect length validation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-14489/">CVE-2017-14489</cve>
	<bugzilla href="https://bugzilla.suse.com/1059051">SUSE bug 1059051</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714497" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14497</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14497" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14497" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14497" ref_url="https://www.suse.com/security/cve/CVE-2017-14497" source="SUSE CVE"/>
    <description>
    The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact via crafted system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-14497/">CVE-2017-14497</cve>
	<bugzilla href="https://bugzilla.suse.com/1059058">SUSE bug 1059058</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714632" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14632</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14632" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14632" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14632" ref_url="https://www.suse.com/security/cve/CVE-2017-14632" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0016-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003568.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0047-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00015.html" source="SUSE-SU"/>
    <description>
    Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi-&gt;channels&lt;=0, a similar issue to Mozilla bug 550184.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-14632/">CVE-2017-14632</cve>
	<bugzilla href="https://bugzilla.suse.com/1059809">SUSE bug 1059809</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481533" comment="libvorbis0-1.3.6-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481534" comment="libvorbisenc2-1.3.6-4.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714633" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14633</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14633" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14633" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14633" ref_url="https://www.suse.com/security/cve/CVE-2017-14633" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0016-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003568.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0047-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00015.html" source="SUSE-SU"/>
    <description>
    In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-14633/">CVE-2017-14633</cve>
	<bugzilla href="https://bugzilla.suse.com/1059811">SUSE bug 1059811</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1081833">SUSE bug 1081833</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481533" comment="libvorbis0-1.3.6-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481534" comment="libvorbisenc2-1.3.6-4.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714695" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14695</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14695" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14695" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14695" ref_url="https://www.suse.com/security/cve/CVE-2017-14695" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-December/003542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-December/003543.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2822-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2824-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1053-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-04/msg00061.html" source="SUSE-SU"/>
    <description>
    Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-14695/">CVE-2017-14695</cve>
	<bugzilla href="https://bugzilla.suse.com/1053955">SUSE bug 1053955</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1062462">SUSE bug 1062462</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714696" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14696</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14696" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14696" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14696" ref_url="https://www.suse.com/security/cve/CVE-2017-14696" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-December/003542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-December/003543.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2822-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2824-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1053-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-04/msg00061.html" source="SUSE-SU"/>
    <description>
    SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-14696/">CVE-2017-14696</cve>
	<bugzilla href="https://bugzilla.suse.com/1053955">SUSE bug 1053955</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1062464">SUSE bug 1062464</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201714992" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-14992</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-14992" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14992" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-14992" ref_url="https://www.suse.com/security/cve/CVE-2017-14992" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0386-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0406-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00012.html" source="SUSE-SU"/>
    <description>
    Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-14992/">CVE-2017-14992</cve>
	<bugzilla href="https://bugzilla.suse.com/1066210">SUSE bug 1066210</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715038" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15038</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15038" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15038" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15038" ref_url="https://www.suse.com/security/cve/CVE-2017-15038" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2924-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2938-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2941-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00008.html" source="SUSE-SU"/>
    <description>
    Race condition in the v9fs_xattrwalk function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS users to obtain sensitive information from host heap memory via vectors related to reading extended attributes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3/CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-15038/">CVE-2017-15038</cve>
	<bugzilla href="https://bugzilla.suse.com/1062069">SUSE bug 1062069</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715102" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15102</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15102" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15102" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15102" ref_url="https://www.suse.com/security/cve/CVE-2017-15102" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:3210-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3249-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
    <description>
    The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-15102/">CVE-2017-15102</cve>
	<bugzilla href="https://bugzilla.suse.com/1066705">SUSE bug 1066705</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715115" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15115</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15115" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15115" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15115" ref_url="https://www.suse.com/security/cve/CVE-2017-15115" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:3398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3410-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0031-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3358-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3359-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00079.html" source="SUSE-SU"/>
    <description>
    The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-15115/">CVE-2017-15115</cve>
	<bugzilla href="https://bugzilla.suse.com/1068671">SUSE bug 1068671</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715116" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15116</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15116" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15116" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15116" ref_url="https://www.suse.com/security/cve/CVE-2017-15116" source="SUSE CVE"/>
    <description>
    The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-15116/">CVE-2017-15116</cve>
	<bugzilla href="https://bugzilla.suse.com/1070613">SUSE bug 1070613</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715118" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15118</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15118" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15118" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15118" ref_url="https://www.suse.com/security/cve/CVE-2017-15118" source="SUSE CVE"/>
    <description>
    A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If NBD server requires TLS, the attacker cannot trigger the buffer overflow without first successfully negotiating TLS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-15118/">CVE-2017-15118</cve>
	<bugzilla href="https://bugzilla.suse.com/1070147">SUSE bug 1070147</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715119" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15119</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15119" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15119" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15119" ref_url="https://www.suse.com/security/cve/CVE-2017-15119" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0762-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0831-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0780-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00053.html" source="SUSE-SU"/>
    <description>
    The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client could use this flaw to keep the NBD server from serving other requests, resulting in DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-15119/">CVE-2017-15119</cve>
	<bugzilla href="https://bugzilla.suse.com/1070144">SUSE bug 1070144</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715232" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15232</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15232" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15232" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15232" ref_url="https://www.suse.com/security/cve/CVE-2017-15232" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-February/003709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004223.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2899-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-10/msg00115.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0393-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-02/msg00023.html" source="SUSE-SU"/>
    <description>
    libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-15232/">CVE-2017-15232</cve>
	<bugzilla href="https://bugzilla.suse.com/1062937">SUSE bug 1062937</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628779" comment="libjpeg8-8.1.2-5.15.7 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715265" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15265</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15265" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15265" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15265" ref_url="https://www.suse.com/security/cve/CVE-2017-15265" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3165-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3267-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3410-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2846-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2905-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00085.html" source="SUSE-SU"/>
    <description>
    Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/seq ioctl calls, related to sound/core/seq/seq_clientmgr.c and sound/core/seq/seq_ports.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-15265/">CVE-2017-15265</cve>
	<bugzilla href="https://bugzilla.suse.com/1062520">SUSE bug 1062520</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715268" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15268</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15268" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15268" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15268" ref_url="https://www.suse.com/security/cve/CVE-2017-15268" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2924-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2938-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2941-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00008.html" source="SUSE-SU"/>
    <description>
    Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-websock.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-15268/">CVE-2017-15268</cve>
	<bugzilla href="https://bugzilla.suse.com/1062942">SUSE bug 1062942</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715274" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15274</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15274" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15274" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15274" ref_url="https://www.suse.com/security/cve/CVE-2017-15274" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2769-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2770-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2772-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2773-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2775-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2776-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2777-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2779-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2780-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2781-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2782-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2783-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2784-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2785-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2786-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2787-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2788-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2790-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2791-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2792-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2793-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2796-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2797-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3165-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
    <description>
    security/keys/keyctl.c in the Linux kernel before 4.11.5 does not consider the case of a NULL payload in conjunction with a nonzero length value, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted add_key or keyctl system call, a different vulnerability than CVE-2017-12192.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-15274/">CVE-2017-15274</cve>
	<bugzilla href="https://bugzilla.suse.com/1045327">SUSE bug 1045327</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1062471">SUSE bug 1062471</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715289" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15289</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15289" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15289" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15289" ref_url="https://www.suse.com/security/cve/CVE-2017-15289" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2924-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3178-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3212-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3239-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3242-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2938-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2941-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3193-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3194-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00004.html" source="SUSE-SU"/>
    <description>
    The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors related to dst calculation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-15289/">CVE-2017-15289</cve>
	<bugzilla href="https://bugzilla.suse.com/1063122">SUSE bug 1063122</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063123">SUSE bug 1063123</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715649" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15649</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15649" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15649" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15649" ref_url="https://www.suse.com/security/cve/CVE-2017-15649" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2847-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2869-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3072-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3076-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3116-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3117-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3118-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3120-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3121-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3122-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3123-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3124-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3125-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3127-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3128-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3129-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3130-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3131-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3132-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3134-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3136-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3139-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3145-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3146-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3148-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3149-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3150-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3151-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3152-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3154-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3156-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3157-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3158-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3159-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3160-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00081.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3267-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3307-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3315-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0562-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0664-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2846-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2905-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00085.html" source="SUSE-SU"/>
    <description>
    net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that leads to a use-after-free, a different vulnerability than CVE-2017-6346.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-20"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-15649/">CVE-2017-15649</cve>
	<bugzilla href="https://bugzilla.suse.com/1064388">SUSE bug 1064388</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1064392">SUSE bug 1064392</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715670" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15670</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15670" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15670" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15670" ref_url="https://www.suse.com/security/cve/CVE-2017-15670" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2883-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004606.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0089-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00040.html" source="SUSE-SU"/>
    <description>
    The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.c, related to the processing of home directories using the ~ operator followed by a long string.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-15670/">CVE-2017-15670</cve>
	<bugzilla href="https://bugzilla.suse.com/1064583">SUSE bug 1064583</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1110160">SUSE bug 1110160</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715671" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15671</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15671" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15671" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15671" ref_url="https://www.suse.com/security/cve/CVE-2017-15671" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004949.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0089-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00040.html" source="SUSE-SU"/>
    <description>
    The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-15671/">CVE-2017-15671</cve>
	<bugzilla href="https://bugzilla.suse.com/1064569">SUSE bug 1064569</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715804" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15804</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15804" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15804" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15804" ref_url="https://www.suse.com/security/cve/CVE-2017-15804" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2883-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004606.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0089-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00040.html" source="SUSE-SU"/>
    <description>
    The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-15804/">CVE-2017-15804</cve>
	<bugzilla href="https://bugzilla.suse.com/1064580">SUSE bug 1064580</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1110160">SUSE bug 1110160</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715868" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15868</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15868" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15868" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15868" ref_url="https://www.suse.com/security/cve/CVE-2017-15868" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0031-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0237-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0238-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0239-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0240-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0242-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0243-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0244-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0249-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0250-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0251-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0252-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0253-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0266-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00081.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0267-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0268-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0270-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00085.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0271-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0275-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0276-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00091.html" source="SUSE-SU"/>
    <description>
    The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-15868/">CVE-2017-15868</cve>
	<bugzilla href="https://bugzilla.suse.com/1071470">SUSE bug 1071470</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1071471">SUSE bug 1071471</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201715908" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-15908</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-15908" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15908" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-15908" ref_url="https://www.suse.com/security/cve/CVE-2017-15908" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0299-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003686.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0320-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00118.html" source="SUSE-SU"/>
    <description>
    In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-15908/">CVE-2017-15908</cve>
	<bugzilla href="https://bugzilla.suse.com/1065276">SUSE bug 1065276</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201716528" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-16528</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-16528" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16528" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-16528" ref_url="https://www.suse.com/security/cve/CVE-2017-16528" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:3398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3410-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3358-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3359-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00079.html" source="SUSE-SU"/>
    <description>
    sound/core/seq_device.c in the Linux kernel before 4.13.4 allows local users to cause a denial of service (snd_rawmidi_dev_seq_free use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-16528/">CVE-2017-16528</cve>
	<bugzilla href="https://bugzilla.suse.com/1066629">SUSE bug 1066629</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146519">SUSE bug 1146519</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201716530" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-16530</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-16530" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16530" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-16530" ref_url="https://www.suse.com/security/cve/CVE-2017-16530" source="SUSE CVE"/>
    <description>
    The uas driver in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to drivers/usb/storage/uas-detect.h and drivers/usb/storage/uas.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-16530/">CVE-2017-16530</cve>
	<bugzilla href="https://bugzilla.suse.com/1066668">SUSE bug 1066668</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146519">SUSE bug 1146519</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201716532" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-16532</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-16532" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16532" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-16532" ref_url="https://www.suse.com/security/cve/CVE-2017-16532" source="SUSE CVE"/>
    <description>
    The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-16532/">CVE-2017-16532</cve>
	<bugzilla href="https://bugzilla.suse.com/1066673">SUSE bug 1066673</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146519">SUSE bug 1146519</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201716536" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-16536</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-16536" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16536" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-16536" ref_url="https://www.suse.com/security/cve/CVE-2017-16536" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:3210-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3249-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3410-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3358-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3359-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00079.html" source="SUSE-SU"/>
    <description>
    The cx231xx_usb_probe function in drivers/media/usb/cx231xx/cx231xx-cards.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-16536/">CVE-2017-16536</cve>
	<bugzilla href="https://bugzilla.suse.com/1066606">SUSE bug 1066606</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146519">SUSE bug 1146519</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201716537" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-16537</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-16537" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16537" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-16537" ref_url="https://www.suse.com/security/cve/CVE-2017-16537" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:3210-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3249-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3410-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3358-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3359-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00079.html" source="SUSE-SU"/>
    <description>
    The imon_probe function in drivers/media/rc/imon.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-16537/">CVE-2017-16537</cve>
	<bugzilla href="https://bugzilla.suse.com/1066573">SUSE bug 1066573</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146519">SUSE bug 1146519</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201716539" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-16539</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-16539" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16539" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-16539" ref_url="https://www.suse.com/security/cve/CVE-2017-16539" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0386-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0406-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00012.html" source="SUSE-SU"/>
    <description>
    The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-16539/">CVE-2017-16539</cve>
	<bugzilla href="https://bugzilla.suse.com/1066801">SUSE bug 1066801</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201716548" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-16548</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-16548" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16548" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-16548" ref_url="https://www.suse.com/security/cve/CVE-2017-16548" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003604.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0101-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00044.html" source="SUSE-SU"/>
    <description>
    The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact by sending crafted data to the daemon.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-16548/">CVE-2017-16548</cve>
	<bugzilla href="https://bugzilla.suse.com/1066644">SUSE bug 1066644</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482539" comment="rsync-3.1.3-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201716646" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-16646</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-16646" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16646" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-16646" ref_url="https://www.suse.com/security/cve/CVE-2017-16646" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:3398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3410-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3358-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3359-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00079.html" source="SUSE-SU"/>
    <description>
    drivers/media/usb/dvb-usb/dib0700_devices.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (BUG and system crash) or possibly have unspecified other impact via a crafted USB device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-16646/">CVE-2017-16646</cve>
	<bugzilla href="https://bugzilla.suse.com/1067105">SUSE bug 1067105</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146519">SUSE bug 1146519</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201716648" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-16648</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-16648" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16648" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-16648" ref_url="https://www.suse.com/security/cve/CVE-2017-16648" source="SUSE CVE"/>
    <description>
    The dvb_frontend_free function in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device. NOTE: the function was later renamed __dvb_frontend_free.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-16648/">CVE-2017-16648</cve>
	<bugzilla href="https://bugzilla.suse.com/1067087">SUSE bug 1067087</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146519">SUSE bug 1146519</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201716845" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-16845</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-16845" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16845" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-16845" ref_url="https://www.suse.com/security/cve/CVE-2017-16845" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0762-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0831-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0780-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00053.html" source="SUSE-SU"/>
    <description>
    hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-16845/">CVE-2017-16845</cve>
	<bugzilla href="https://bugzilla.suse.com/1068613">SUSE bug 1068613</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201716997" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-16997</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-16997" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16997" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-16997" ref_url="https://www.suse.com/security/cve/CVE-2017-16997" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0089-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00040.html" source="SUSE-SU"/>
    <description>
    elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a Trojan horse library in the current working directory, related to the fillin_rpath and decompose_rpath functions. This is associated with misinterpretion of an empty RPATH/RUNPATH token as the "./" directory. NOTE: this configuration of RPATH/RUNPATH for a privileged program is apparently very uncommon; most likely, no such program is shipped with any common Linux distribution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-16997/">CVE-2017-16997</cve>
	<bugzilla href="https://bugzilla.suse.com/1073231">SUSE bug 1073231</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201717053" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-17053</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-17053" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17053" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-17053" ref_url="https://www.suse.com/security/cve/CVE-2017-17053" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004468.html" source="SUSE-SU"/>
    <description>
    The init_new_context function in arch/x86/include/asm/mmu_context.h in the Linux kernel before 4.12.10 does not correctly handle errors from LDT table allocation when forking a new process, allowing a local attacker to achieve a use-after-free or possibly have unspecified other impact by running a specially crafted program. This vulnerability only affected kernels built with CONFIG_MODIFY_LDT_SYSCALL=y.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-20"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-17053/">CVE-2017-17053</cve>
	<bugzilla href="https://bugzilla.suse.com/1070264">SUSE bug 1070264</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1096679">SUSE bug 1096679</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201717087" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-17087</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-17087" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17087" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-17087" ref_url="https://www.suse.com/security/cve/CVE-2017-17087" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-17087/">CVE-2017-17087</cve>
	<bugzilla href="https://bugzilla.suse.com/1065958">SUSE bug 1065958</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1070955">SUSE bug 1070955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201717426" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-17426</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-17426" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17426" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-17426" ref_url="https://www.suse.com/security/cve/CVE-2017-17426" source="SUSE CVE"/>
    <description>
    The malloc function in the GNU C Library (aka glibc or libc6) 2.26 could return a memory block that is too small if an attempt is made to allocate an object whose size is close to SIZE_MAX, potentially leading to a subsequent heap overflow. This occurs because the per-thread cache (aka tcache) feature enables a code path that lacks an integer overflow check.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-17426/">CVE-2017-17426</cve>
	<bugzilla href="https://bugzilla.suse.com/1071479">SUSE bug 1071479</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201717450" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-17450</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-17450" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17450" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-17450" ref_url="https://www.suse.com/security/cve/CVE-2017-17450" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:3398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3410-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0031-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3358-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3359-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00079.html" source="SUSE-SU"/>
    <description>
    net/netfilter/xt_osf.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for add_callback and remove_callback operations, which allows local users to bypass intended access restrictions because the xt_osf_fingers data structure is shared across all net namespaces.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2017-17450/">CVE-2017-17450</cve>
	<bugzilla href="https://bugzilla.suse.com/1071695">SUSE bug 1071695</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074033">SUSE bug 1074033</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201717558" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-17558</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-17558" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17558" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-17558" ref_url="https://www.suse.com/security/cve/CVE-2017-17558" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0031-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
    <description>
    The usb_destroy_configuration function in drivers/usb/core/config.c in the USB core subsystem in the Linux kernel through 4.14.5 does not consider the maximum number of configurations and interfaces before attempting to release resources, which allows local users to cause a denial of service (out-of-bounds write access) or possibly have unspecified other impact via a crafted USB device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-17558/">CVE-2017-17558</cve>
	<bugzilla href="https://bugzilla.suse.com/1072561">SUSE bug 1072561</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146519">SUSE bug 1146519</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201717740" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-17740</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-17740" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17740" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-17740" ref_url="https://www.suse.com/security/cve/CVE-2017-17740" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2395-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005929.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2157-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2176-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html" source="SUSE-SU"/>
    <description>
    contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-17740/">CVE-2017-17740</cve>
	<bugzilla href="https://bugzilla.suse.com/1073313">SUSE bug 1073313</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201717742" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-17742</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-17742" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17742" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-17742" ref_url="https://www.suse.com/security/cve/CVE-2017-17742" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HTTP server of WEBrick.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2017-17742/">CVE-2017-17742</cve>
	<bugzilla href="https://bugzilla.suse.com/1087434">SUSE bug 1087434</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136906">SUSE bug 1136906</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1152992">SUSE bug 1152992</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201717806" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-17806</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-17806" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17806" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-17806" ref_url="https://www.suse.com/security/cve/CVE-2017-17806" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0012-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0023-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html" source="SUSE-SU"/>
    <description>
    The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executing a crafted sequence of system calls that encounter a missing SHA-3 initialization.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.6/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-17806/">CVE-2017-17806</cve>
	<bugzilla href="https://bugzilla.suse.com/1073874">SUSE bug 1073874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201717833" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-17833</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-17833" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17833" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-17833" ref_url="https://www.suse.com/security/cve/CVE-2017-17833" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:616-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1917-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2779-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2991-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2991-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2991-3" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005372.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1958-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2813-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00063.html" source="SUSE-SU"/>
    <description>
    OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2017-17833/">CVE-2017-17833</cve>
	<bugzilla href="https://bugzilla.suse.com/1090638">SUSE bug 1090638</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1099519">SUSE bug 1099519</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482486" comment="openslp-2.0.0-6.12.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201717840" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-17840</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-17840" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17840" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-17840" ref_url="https://www.suse.com/security/cve/CVE-2017-17840" source="SUSE CVE"/>
    <description>
    An issue was discovered in Open-iSCSI through 2.0.875. A local attacker can cause the iscsiuio server to abort or potentially execute code by sending messages with incorrect lengths, which (due to lack of checking) can lead to buffer overflows, and result in aborts (with overflow checking enabled) or code execution. The process_iscsid_broadcast function in iscsiuio/src/unix/iscsid_ipc.c does not validate the payload length before a write operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2017-17840/">CVE-2017-17840</cve>
	<bugzilla href="https://bugzilla.suse.com/1072312">SUSE bug 1072312</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009659871" comment="iscsiuio is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009659872" comment="libopeniscsiusr0_2_0 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009659873" comment="open-iscsi is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201718078" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-18078</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-18078" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18078" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-18078" ref_url="https://www.suse.com/security/cve/CVE-2017-18078" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-February/003753.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0560-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-02/msg00109.html" source="SUSE-SU"/>
    <description>
    systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-18078/">CVE-2017-18078</cve>
	<bugzilla href="https://bugzilla.suse.com/1077925">SUSE bug 1077925</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201718207" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-18207</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-18207" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18207" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-18207" ref_url="https://www.suse.com/security/cve/CVE-2017-18207" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0934-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003890.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004216.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2040-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004297.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006445.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0966-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-04/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2126-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be prepared to handle a wide variety of exceptions."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-18207/">CVE-2017-18207</cve>
	<bugzilla href="https://bugzilla.suse.com/1083507">SUSE bug 1083507</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201718222" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-18222</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-18222" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18222" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-18222" ref_url="https://www.suse.com/security/cve/CVE-2017-18222" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 4.12, Hisilicon Network Subsystem (HNS) does not consider the ETH_SS_PRIV_FLAGS case when retrieving sset_count data, which allows local users to cause a denial of service (buffer overflow and memory corruption) or possibly have unspecified other impact, as demonstrated by incompatibility between hns_get_sset_count and ethtool_get_strings.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-18222/">CVE-2017-18222</cve>
	<bugzilla href="https://bugzilla.suse.com/1084529">SUSE bug 1084529</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201718249" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-18249</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-18249" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18249" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-18249" ref_url="https://www.suse.com/security/cve/CVE-2017-18249" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1855-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1855-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0470-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0901-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005309.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1773-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00040.html" source="SUSE-SU"/>
    <description>
    The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-18249/">CVE-2017-18249</cve>
	<bugzilla href="https://bugzilla.suse.com/1087036">SUSE bug 1087036</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201718255" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-18255</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-18255" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18255" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-18255" ref_url="https://www.suse.com/security/cve/CVE-2017-18255" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
    <description>
    The perf_cpu_time_max_percent_handler function in kernel/events/core.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow) or possibly have unspecified other impact via a large value, as demonstrated by an incorrect sample-rate calculation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-18255/">CVE-2017-18255</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087813">SUSE bug 1087813</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201718258" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-18258</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-18258" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18258" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-18258" ref_url="https://www.suse.com/security/cve/CVE-2017-18258" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004657.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3107-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00026.html" source="SUSE-SU"/>
    <description>
    The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-18258/">CVE-2017-18258</cve>
	<bugzilla href="https://bugzilla.suse.com/1088279">SUSE bug 1088279</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1088601">SUSE bug 1088601</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105166">SUSE bug 1105166</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201718261" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-18261</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-18261" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18261" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-18261" ref_url="https://www.suse.com/security/cve/CVE-2017-18261" source="SUSE CVE"/>
    <description>
    The arch_timer_reg_read_stable macro in arch/arm64/include/asm/arch_timer.h in the Linux kernel before 4.13 allows local users to cause a denial of service (infinite recursion) by writing to a file under /sys/kernel/debug in certain circumstances, as demonstrated by a scenario involving debugfs, ftrace, PREEMPT_TRACER, and FUNCTION_GRAPH_TRACER.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-18261/">CVE-2017-18261</cve>
	<bugzilla href="https://bugzilla.suse.com/1090225">SUSE bug 1090225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201718269" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-18269</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-18269" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18269" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-18269" ref_url="https://www.suse.com/security/cve/CVE-2017-18269" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1562-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004156.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1562-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1991-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004285.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1600-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2159-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00000.html" source="SUSE-SU"/>
    <description>
    An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the middle of the address space, resulting in corrupt data being produced by the copy operation. This may disclose information to context-dependent attackers, or result in a denial of service, or, possibly, code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-18269/">CVE-2017-18269</cve>
	<bugzilla href="https://bugzilla.suse.com/1094150">SUSE bug 1094150</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118435">SUSE bug 1118435</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201718270" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-18270</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-18270" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18270" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-18270" ref_url="https://www.suse.com/security/cve/CVE-2017-18270" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-09"/>
	<updated date="2023-08-09"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-18270/">CVE-2017-18270</cve>
	<bugzilla href="https://bugzilla.suse.com/1065999">SUSE bug 1065999</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1094186">SUSE bug 1094186</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1174993">SUSE bug 1174993</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201718342" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-18342</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-18342" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18342" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-18342" ref_url="https://www.suse.com/security/cve/CVE-2017-18342" source="SUSE CVE"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-18342/">CVE-2017-18342</cve>
	<bugzilla href="https://bugzilla.suse.com/1099308">SUSE bug 1099308</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1164453">SUSE bug 1164453</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482516" comment="python3-PyYAML-5.1.2-6.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201718552" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-18552</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-18552" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18552" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-18552" ref_url="https://www.suse.com/security/cve/CVE-2017-18552" source="SUSE CVE"/>
    <description>
    An issue was discovered in net/rds/af_rds.c in the Linux kernel before 4.11. There is an out of bounds write and read in the function rds_recv_track_latency.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-18552/">CVE-2017-18552</cve>
	<bugzilla href="https://bugzilla.suse.com/1146295">SUSE bug 1146295</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20172584" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-2584</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-2584" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2584" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-2584" ref_url="https://www.suse.com/security/cve/CVE-2017-2584" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0464-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0575-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0456-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0906-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00000.html" source="SUSE-SU"/>
    <description>
    arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free) via a crafted application that leverages instruction emulation for fxrstor, fxsave, sgdt, and sidt.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.1/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-2584/">CVE-2017-2584</cve>
	<bugzilla href="https://bugzilla.suse.com/1019851">SUSE bug 1019851</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20172615" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-2615</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-2615" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2615" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-2615" ref_url="https://www.suse.com/security/cve/CVE-2017-2615" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0571-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0661-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1135-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0665-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-2615/">CVE-2017-2615</cve>
	<bugzilla href="https://bugzilla.suse.com/1023004">SUSE bug 1023004</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20172616" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-2616</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-2616" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2616" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-2616" ref_url="https://www.suse.com/security/cve/CVE-2017-2616" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0553-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0554-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0555-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0866-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0589-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00002.html" source="SUSE-SU"/>
    <description>
    A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-2616/">CVE-2017-2616</cve>
	<bugzilla href="https://bugzilla.suse.com/1023041">SUSE bug 1023041</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123789">SUSE bug 1123789</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760806" comment="libblkid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760807" comment="libfdisk1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760808" comment="libmount1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760809" comment="libsmartcols1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760810" comment="libuuid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760811" comment="util-linux-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760812" comment="util-linux-systemd-2.33.1-4.13.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20172620" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-2620</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-2620" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2620" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-2620" ref_url="https://www.suse.com/security/cve/CVE-2017-2620" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0571-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0661-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1135-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0665-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.9/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-2620/">CVE-2017-2620</cve>
	<bugzilla href="https://bugzilla.suse.com/1024834">SUSE bug 1024834</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024972">SUSE bug 1024972</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20172629" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-2629</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-2629" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2629" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-2629" ref_url="https://www.suse.com/security/cve/CVE-2017-2629" source="SUSE CVE"/>
    <description>
    curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or failure. It ends up always thinking there's valid proof, even when there is none or if the server doesn't support the TLS extension in question. This could lead to users not detecting when a server's certificate goes invalid or otherwise be mislead that the server is in a better shape than it is in reality. This flaw also exists in the command line tool (--cert-status).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-2629/">CVE-2017-2629</cve>
	<bugzilla href="https://bugzilla.suse.com/1025379">SUSE bug 1025379</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1042181">SUSE bug 1042181</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20172630" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-2630</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-2630" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2630" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-2630" ref_url="https://www.suse.com/security/cve/CVE-2017-2630" source="SUSE CVE"/>
    <description>
    A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with privileges of the QEMU process.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-2630/">CVE-2017-2630</cve>
	<bugzilla href="https://bugzilla.suse.com/1025396">SUSE bug 1025396</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20172633" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-2633</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-2633" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2633" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-2633" ref_url="https://www.suse.com/security/cve/CVE-2017-2633" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1080-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1081-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0019-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0039-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00022.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-2633/">CVE-2017-2633</cve>
	<bugzilla href="https://bugzilla.suse.com/1026612">SUSE bug 1026612</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1026636">SUSE bug 1026636</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074701">SUSE bug 1074701</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20172635" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-2635</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-2635" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2635" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-2635" ref_url="https://www.suse.com/security/cve/CVE-2017-2635" source="SUSE CVE"/>
    <description>
    A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-2635/">CVE-2017-2635</cve>
	<bugzilla href="https://bugzilla.suse.com/1027075">SUSE bug 1027075</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20172647" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-2647</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-2647" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2647" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-2647" ref_url="https://www.suse.com/security/cve/CVE-2017-2647" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
    <description>
    The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-2647/">CVE-2017-2647</cve>
	<bugzilla href="https://bugzilla.suse.com/1030593">SUSE bug 1030593</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20172671" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-2671</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-2671" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2671" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-2671" ref_url="https://www.suse.com/security/cve/CVE-2017-2671" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1183-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1140-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1215-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00016.html" source="SUSE-SU"/>
    <description>
    The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-2671/">CVE-2017-2671</cve>
	<bugzilla href="https://bugzilla.suse.com/1027179">SUSE bug 1027179</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1031003">SUSE bug 1031003</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20173731" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-3731</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-3731" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3731" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-3731" ref_url="https://www.suse.com/security/cve/CVE-2017-3731" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0855-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0112-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7021518" ref_url="https://www.suse.com/support/kb/doc/?id=7021518" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0481-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0487-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0527-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00095.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0941-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2868-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-3731/">CVE-2017-3731</cve>
	<bugzilla href="https://bugzilla.suse.com/1021641">SUSE bug 1021641</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1022085">SUSE bug 1022085</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1064118">SUSE bug 1064118</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1064119">SUSE bug 1064119</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20173732" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-3732</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-3732" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3732" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-3732" ref_url="https://www.suse.com/security/cve/CVE-2017-3732" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-February/002638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0855-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2839-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004658.html" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7021518" ref_url="https://www.suse.com/support/kb/doc/?id=7021518" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0481-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0527-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00095.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0941-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2011-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-07/msg00117.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html" source="SUSE-SU"/>
    <description>
    There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. For example this can occur by default in OpenSSL DHE based SSL/TLS ciphersuites. Note: This issue is very similar to CVE-2015-3193 but must be treated as a separate problem.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-3732/">CVE-2017-3732</cve>
	<bugzilla href="https://bugzilla.suse.com/1021641">SUSE bug 1021641</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1022086">SUSE bug 1022086</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1049418">SUSE bug 1049418</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1049421">SUSE bug 1049421</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1049422">SUSE bug 1049422</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1066242">SUSE bug 1066242</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1071906">SUSE bug 1071906</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957814">SUSE bug 957814</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482336" comment="openssl-1.1.1d-1.46 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20173735" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-3735</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-3735" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3735" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-3735" ref_url="https://www.suse.com/security/cve/CVE-2017-3735" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2968-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2981-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-November/003461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0002-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003558.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0112-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="TID7022367" ref_url="https://www.suse.com/support/kb/doc/?id=7022367" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3192-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0029-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0315-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00113.html" source="SUSE-SU"/>
    <description>
    While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2017-3735/">CVE-2017-3735</cve>
	<bugzilla href="https://bugzilla.suse.com/1056058">SUSE bug 1056058</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20173736" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-3736</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-3736" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3736" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-3736" ref_url="https://www.suse.com/security/cve/CVE-2017-3736" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-November/003461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0002-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003558.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2839-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004658.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="TID7016794" ref_url="https://www.suse.com/support/kb/doc/?id=7016794" source="SUSE-SU"/>
		<reference ref_id="TID7022367" ref_url="https://www.suse.com/support/kb/doc/?id=7022367" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3192-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-12/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0029-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0315-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00113.html" source="SUSE-SU"/>
    <description>
    There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-3736/">CVE-2017-3736</cve>
	<bugzilla href="https://bugzilla.suse.com/1066242">SUSE bug 1066242</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1071906">SUSE bug 1071906</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1076369">SUSE bug 1076369</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/957814">SUSE bug 957814</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20173738" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-3738</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-3738" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3738" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-3738" ref_url="https://www.suse.com/security/cve/CVE-2017-3738" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3343-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0002-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003558.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="TID7022464" ref_url="https://www.suse.com/support/kb/doc/?id=7022464" source="SUSE-SU"/>
		<reference ref_id="TID7022627" ref_url="https://www.suse.com/support/kb/doc/?id=7022627" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3345-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0029-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0315-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00113.html" source="SUSE-SU"/>
    <description>
    There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH1024 private key among multiple clients, which is no longer an option since CVE-2016-0701. This only affects processors that support the AVX2 but not ADX extensions like Intel Haswell (4th generation). Note: The impact from this issue is similar to CVE-2017-3736, CVE-2017-3732 and CVE-2015-3193. OpenSSL version 1.0.2-1.0.2m and 1.1.0-1.1.0g are affected. Fixed in OpenSSL 1.0.2n. Due to the low severity of this issue we are not issuing a new release of OpenSSL 1.1.0 at this time. The fix will be included in OpenSSL 1.1.0h when it becomes available. The fix is also available in commit e502cc86d in the OpenSSL git repository.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-3738/">CVE-2017-3738</cve>
	<bugzilla href="https://bugzilla.suse.com/1071906">SUSE bug 1071906</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1097757">SUSE bug 1097757</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175029" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5029</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5029" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5029" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5029" ref_url="https://www.suse.com/security/cve/CVE-2017-5029" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0738-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0740-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1390-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00079.html" source="SUSE-SU"/>
    <description>
    The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-5029/">CVE-2017-5029</cve>
	<bugzilla href="https://bugzilla.suse.com/1028848">SUSE bug 1028848</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1028875">SUSE bug 1028875</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1035905">SUSE bug 1035905</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123130">SUSE bug 1123130</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482467" comment="libxslt1-1.1.32-3.8.24 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175200" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5200</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5200" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5200" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5200" ref_url="https://www.suse.com/security/cve/CVE-2017-5200" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1581-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002948.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1053-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-04/msg00061.html" source="SUSE-SU"/>
    <description>
    Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-5200/">CVE-2017-5200</cve>
	<bugzilla href="https://bugzilla.suse.com/1011800">SUSE bug 1011800</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009347405" comment="python3-salt is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009347406" comment="salt is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009347413" comment="salt-minion is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009656852" comment="salt-transactional-update is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175436" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5436</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5436" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5436" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5436" ref_url="https://www.suse.com/security/cve/CVE-2017-5436" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1149-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1175-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1248-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1669-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2235-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1196-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1268-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00026.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affects Thunderbird &lt; 52.1, Firefox ESR &lt; 45.9, Firefox ESR &lt; 52.1, and Firefox &lt; 53.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-5436/">CVE-2017-5436</cve>
	<bugzilla href="https://bugzilla.suse.com/1035082">SUSE bug 1035082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1035204">SUSE bug 1035204</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480302" comment="libgraphite2-3-1.3.11-2.12 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175525" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5525</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5525" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5525" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5525" ref_url="https://www.suse.com/security/cve/CVE-2017-5525" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5525/">CVE-2017-5525</cve>
	<bugzilla href="https://bugzilla.suse.com/1020491">SUSE bug 1020491</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175526" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5526</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5526" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5526" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5526" ref_url="https://www.suse.com/security/cve/CVE-2017-5526" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2751-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2815-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2856-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2864-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2873-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00080.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2821-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2916-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00000.html" source="SUSE-SU"/>
    <description>
    Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5526/">CVE-2017-5526</cve>
	<bugzilla href="https://bugzilla.suse.com/1020589">SUSE bug 1020589</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1059777">SUSE bug 1059777</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175549" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5549</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5549" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5549" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5549" ref_url="https://www.suse.com/security/cve/CVE-2017-5549" source="SUSE CVE"/>
    <description>
    The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents into a log entry upon a failure to read the line status, which allows local users to obtain sensitive information by reading the log.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-12"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-5549/">CVE-2017-5549</cve>
	<bugzilla href="https://bugzilla.suse.com/1021256">SUSE bug 1021256</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175551" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5551</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5551" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5551" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5551" ref_url="https://www.suse.com/security/cve/CVE-2017-5551" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-01/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0464-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0471-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0575-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0456-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00022.html" source="SUSE-SU"/>
    <description>
    The simple_set_acl function in fs/posix_acl.c in the Linux kernel before 4.9.6 preserves the setgid bit during a setxattr call involving a tmpfs filesystem, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7097.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2017-5551/">CVE-2017-5551</cve>
	<bugzilla href="https://bugzilla.suse.com/1021258">SUSE bug 1021258</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/995968">SUSE bug 995968</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175552" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5552</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5552" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5552" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5552" ref_url="https://www.suse.com/security/cve/CVE-2017-5552" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
    <description>
    Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5552/">CVE-2017-5552</cve>
	<bugzilla href="https://bugzilla.suse.com/1021195">SUSE bug 1021195</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175578" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5578</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5578" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5578" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5578" ref_url="https://www.suse.com/security/cve/CVE-2017-5578" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
    <description>
    Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5578/">CVE-2017-5578</cve>
	<bugzilla href="https://bugzilla.suse.com/1021481">SUSE bug 1021481</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175579" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5579</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5579" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5579" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5579" ref_url="https://www.suse.com/security/cve/CVE-2017-5579" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5579/">CVE-2017-5579</cve>
	<bugzilla href="https://bugzilla.suse.com/1021741">SUSE bug 1021741</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1022627">SUSE bug 1022627</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175667" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5667</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5667" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5667" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5667" ref_url="https://www.suse.com/security/cve/CVE-2017-5667" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0661-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary code on the QEMU host via vectors involving the data transfer length.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5667/">CVE-2017-5667</cve>
	<bugzilla href="https://bugzilla.suse.com/1022541">SUSE bug 1022541</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175669" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5669</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5669" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5669" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5669" ref_url="https://www.suse.com/security/cve/CVE-2017-5669" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0906-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00000.html" source="SUSE-SU"/>
    <description>
    The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and consequently bypass a protection mechanism that exists for the mmap system call, by making crafted shmget and shmat system calls in a privileged context.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-5669/">CVE-2017-5669</cve>
	<bugzilla href="https://bugzilla.suse.com/1026914">SUSE bug 1026914</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1102390">SUSE bug 1102390</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175715" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5715</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5715" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5715" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5715" ref_url="https://www.suse.com/security/cve/CVE-2017-5715" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0006-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0009-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0012-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0019-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0020-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0031-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0036-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0039-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0041-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0051-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0056-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0068-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0069-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0113-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0114-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0131-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0171-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0219-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0383-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0416-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0438-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0472-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0482-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0552-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-February/003755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0552-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0555-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0601-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0609-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0638-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0660-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0705-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0708-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0762-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0831-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0838-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0841-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0861-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0986-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1077-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1080-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1308-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1363-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1368-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1465-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1567-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004160.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1571-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1571-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1699-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004222.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004334.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004357.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2631-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005270.html" source="SUSE-SU"/>
		<reference ref_id="TID000019122" ref_url="https://www.suse.com/support/kb/doc/?id=000019122" source="SUSE-SU"/>
		<reference ref_id="TID7022512" ref_url="https://www.suse.com/support/kb/doc/?id=7022512" source="SUSE-SU"/>
		<reference ref_id="TID7022514" ref_url="https://www.suse.com/support/kb/doc/?id=7022514" source="SUSE-SU"/>
		<reference ref_id="TID7022531" ref_url="https://www.suse.com/support/kb/doc/?id=7022531" source="SUSE-SU"/>
		<reference ref_id="TID7022541" ref_url="https://www.suse.com/support/kb/doc/?id=7022541" source="SUSE-SU"/>
		<reference ref_id="TID7022548" ref_url="https://www.suse.com/support/kb/doc/?id=7022548" source="SUSE-SU"/>
		<reference ref_id="TID7022568" ref_url="https://www.suse.com/support/kb/doc/?id=7022568" source="SUSE-SU"/>
		<reference ref_id="TID7022569" ref_url="https://www.suse.com/support/kb/doc/?id=7022569" source="SUSE-SU"/>
		<reference ref_id="TID7022571" ref_url="https://www.suse.com/support/kb/doc/?id=7022571" source="SUSE-SU"/>
		<reference ref_id="TID7022572" ref_url="https://www.suse.com/support/kb/doc/?id=7022572" source="SUSE-SU"/>
		<reference ref_id="TID7022578" ref_url="https://www.suse.com/support/kb/doc/?id=7022578" source="SUSE-SU"/>
		<reference ref_id="TID7022579" ref_url="https://www.suse.com/support/kb/doc/?id=7022579" source="SUSE-SU"/>
		<reference ref_id="TID7022982" ref_url="https://www.suse.com/support/kb/doc/?id=7022982" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU--1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0013-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0023-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0026-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0030-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0059-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0066-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0187-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0326-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00106.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0408-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0710-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0745-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0780-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0939-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1502-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1623-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1631-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2237-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2524-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00080.html" source="SUSE-SU"/>
    <description>
    Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-5715/">CVE-2017-5715</cve>
	<bugzilla href="https://bugzilla.suse.com/1068032">SUSE bug 1068032</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074562">SUSE bug 1074562</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074578">SUSE bug 1074578</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074701">SUSE bug 1074701</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074741">SUSE bug 1074741</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074919">SUSE bug 1074919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1075006">SUSE bug 1075006</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1075007">SUSE bug 1075007</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1075262">SUSE bug 1075262</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1075419">SUSE bug 1075419</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1076115">SUSE bug 1076115</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1076372">SUSE bug 1076372</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1076606">SUSE bug 1076606</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1078353">SUSE bug 1078353</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1080039">SUSE bug 1080039</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087887">SUSE bug 1087887</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087939">SUSE bug 1087939</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1088147">SUSE bug 1088147</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1089055">SUSE bug 1089055</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1091815">SUSE bug 1091815</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1095735">SUSE bug 1095735</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1102517">SUSE bug 1102517</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105108">SUSE bug 1105108</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126516">SUSE bug 1126516</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173489">SUSE bug 1173489</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201457">SUSE bug 1201457</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1203236">SUSE bug 1203236</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760799" comment="kernel-firmware-20200107-3.15.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175753" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5753</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5753" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5753" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5753" ref_url="https://www.suse.com/security/cve/CVE-2017-5753" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0012-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0031-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0069-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0113-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0114-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0131-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0171-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0219-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0438-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0472-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0552-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-February/003755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0552-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0601-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0609-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0638-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1368-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1699-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004334.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005240.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2861-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2862-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1800-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1801-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1802-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1803-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1811-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1848-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1892-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1894-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1897-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1992-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2232-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2506-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029875.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015468.html" source="SUSE-SU"/>
		<reference ref_id="TID000019122" ref_url="https://www.suse.com/support/kb/doc/?id=000019122" source="SUSE-SU"/>
		<reference ref_id="TID000019229" ref_url="https://www.suse.com/support/kb/doc/?id=000019229" source="SUSE-SU"/>
		<reference ref_id="TID7022512" ref_url="https://www.suse.com/support/kb/doc/?id=7022512" source="SUSE-SU"/>
		<reference ref_id="TID7022514" ref_url="https://www.suse.com/support/kb/doc/?id=7022514" source="SUSE-SU"/>
		<reference ref_id="TID7022531" ref_url="https://www.suse.com/support/kb/doc/?id=7022531" source="SUSE-SU"/>
		<reference ref_id="TID7022541" ref_url="https://www.suse.com/support/kb/doc/?id=7022541" source="SUSE-SU"/>
		<reference ref_id="TID7022548" ref_url="https://www.suse.com/support/kb/doc/?id=7022548" source="SUSE-SU"/>
		<reference ref_id="TID7022568" ref_url="https://www.suse.com/support/kb/doc/?id=7022568" source="SUSE-SU"/>
		<reference ref_id="TID7022569" ref_url="https://www.suse.com/support/kb/doc/?id=7022569" source="SUSE-SU"/>
		<reference ref_id="TID7022571" ref_url="https://www.suse.com/support/kb/doc/?id=7022571" source="SUSE-SU"/>
		<reference ref_id="TID7022572" ref_url="https://www.suse.com/support/kb/doc/?id=7022572" source="SUSE-SU"/>
		<reference ref_id="TID7022578" ref_url="https://www.suse.com/support/kb/doc/?id=7022578" source="SUSE-SU"/>
		<reference ref_id="TID7022579" ref_url="https://www.suse.com/support/kb/doc/?id=7022579" source="SUSE-SU"/>
		<reference ref_id="TID7023075" ref_url="https://www.suse.com/support/kb/doc/?id=7023075" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0023-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0326-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00106.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1623-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1212-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5IDOTKMILRKOFD2ODQXJF3OOEYZ3EMR5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2861-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5MOJKTUHVZFZADZQ6EYELCLEJ5BD766Q/" source="SUSE-SU"/>
    <description>
    Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-09-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-5753/">CVE-2017-5753</cve>
	<bugzilla href="https://bugzilla.suse.com/1068032">SUSE bug 1068032</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074562">SUSE bug 1074562</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074578">SUSE bug 1074578</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074701">SUSE bug 1074701</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1075006">SUSE bug 1075006</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1075419">SUSE bug 1075419</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1075748">SUSE bug 1075748</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1080039">SUSE bug 1080039</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087084">SUSE bug 1087084</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087939">SUSE bug 1087939</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1089055">SUSE bug 1089055</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136865">SUSE bug 1136865</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209547">SUSE bug 1209547</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175754" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5754</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5754" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5754" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5754" ref_url="https://www.suse.com/security/cve/CVE-2017-5754" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0012-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0031-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0219-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0438-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0472-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0552-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-February/003755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0552-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0601-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0609-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0638-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1699-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0634-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013982.html" source="SUSE-SU"/>
		<reference ref_id="TID000019122" ref_url="https://www.suse.com/support/kb/doc/?id=000019122" source="SUSE-SU"/>
		<reference ref_id="TID7022512" ref_url="https://www.suse.com/support/kb/doc/?id=7022512" source="SUSE-SU"/>
		<reference ref_id="TID7022514" ref_url="https://www.suse.com/support/kb/doc/?id=7022514" source="SUSE-SU"/>
		<reference ref_id="TID7022531" ref_url="https://www.suse.com/support/kb/doc/?id=7022531" source="SUSE-SU"/>
		<reference ref_id="TID7022541" ref_url="https://www.suse.com/support/kb/doc/?id=7022541" source="SUSE-SU"/>
		<reference ref_id="TID7022548" ref_url="https://www.suse.com/support/kb/doc/?id=7022548" source="SUSE-SU"/>
		<reference ref_id="TID7022568" ref_url="https://www.suse.com/support/kb/doc/?id=7022568" source="SUSE-SU"/>
		<reference ref_id="TID7022569" ref_url="https://www.suse.com/support/kb/doc/?id=7022569" source="SUSE-SU"/>
		<reference ref_id="TID7022571" ref_url="https://www.suse.com/support/kb/doc/?id=7022571" source="SUSE-SU"/>
		<reference ref_id="TID7022572" ref_url="https://www.suse.com/support/kb/doc/?id=7022572" source="SUSE-SU"/>
		<reference ref_id="TID7022578" ref_url="https://www.suse.com/support/kb/doc/?id=7022578" source="SUSE-SU"/>
		<reference ref_id="TID7022579" ref_url="https://www.suse.com/support/kb/doc/?id=7022579" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0023-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0326-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00106.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1623-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00014.html" source="SUSE-SU"/>
    <description>
    Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-5754/">CVE-2017-5754</cve>
	<bugzilla href="https://bugzilla.suse.com/1068032">SUSE bug 1068032</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074562">SUSE bug 1074562</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074578">SUSE bug 1074578</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074701">SUSE bug 1074701</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1075006">SUSE bug 1075006</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1075008">SUSE bug 1075008</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087939">SUSE bug 1087939</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1089055">SUSE bug 1089055</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115045">SUSE bug 1115045</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136865">SUSE bug 1136865</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175837" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5837</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5837" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5837" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5837" ref_url="https://www.suse.com/security/cve/CVE-2017-5837" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002798.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1012-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002802.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002805.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1041-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002807.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005542.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0574-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00117.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1079-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00095.html" source="SUSE-SU"/>
    <description>
    The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted video file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5837/">CVE-2017-5837</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024076">SUSE bug 1024076</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024079">SUSE bug 1024079</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175838" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5838</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5838" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5838" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5838" ref_url="https://www.suse.com/security/cve/CVE-2017-5838" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0966-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0967-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002792.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0580-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00120.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1031-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00058.html" source="SUSE-SU"/>
    <description>
    The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5838/">CVE-2017-5838</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024051">SUSE bug 1024051</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175839" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5839</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5839" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5839" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5839" ref_url="https://www.suse.com/security/cve/CVE-2017-5839" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002805.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1041-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002807.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0574-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00117.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00095.html" source="SUSE-SU"/>
    <description>
    The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested WAVEFORMATEX.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5839/">CVE-2017-5839</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024047">SUSE bug 1024047</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175840" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5840</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5840" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5840" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5840" ref_url="https://www.suse.com/security/cve/CVE-2017-5840" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1004-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1010-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002801.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1066-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1076-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00081.html" source="SUSE-SU"/>
    <description>
    The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving the current stts index.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5840/">CVE-2017-5840</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024034">SUSE bug 1024034</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175841" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5841</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5841" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5841" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5841" ref_url="https://www.suse.com/security/cve/CVE-2017-5841" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1010-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002801.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1066-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1076-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00081.html" source="SUSE-SU"/>
    <description>
    The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving ncdt tags.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5841/">CVE-2017-5841</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024030">SUSE bug 1024030</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024062">SUSE bug 1024062</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175842" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5842</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5842" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5842" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5842" ref_url="https://www.suse.com/security/cve/CVE-2017-5842" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002805.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1041-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002807.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0574-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00117.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00095.html" source="SUSE-SU"/>
    <description>
    The html_context_handle_element function in gst/subparse/samiparse.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted SMI file, as demonstrated by OneNote_Manager.smi.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5842/">CVE-2017-5842</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024041">SUSE bug 1024041</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175843" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5843</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5843" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5843" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5843" ref_url="https://www.suse.com/security/cve/CVE-2017-5843" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002790.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1032-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00059.html" source="SUSE-SU"/>
    <description>
    Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5843/">CVE-2017-5843</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024044">SUSE bug 1024044</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175844" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5844</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5844" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5844" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5844" ref_url="https://www.suse.com/security/cve/CVE-2017-5844" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002798.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1012-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002802.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002805.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1041-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002807.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005542.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0574-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00117.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1079-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1106-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00095.html" source="SUSE-SU"/>
    <description>
    The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted ASF file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5844/">CVE-2017-5844</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024079">SUSE bug 1024079</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175845" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5845</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5845" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5845" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5845" ref_url="https://www.suse.com/security/cve/CVE-2017-5845" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1010-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002801.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1066-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1076-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00081.html" source="SUSE-SU"/>
    <description>
    The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a ncdt sub-tag that "goes behind" the surrounding tag.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5845/">CVE-2017-5845</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024062">SUSE bug 1024062</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175846" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5846</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5846" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5846" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5846" ref_url="https://www.suse.com/security/cve/CVE-2017-5846" source="SUSE CVE"/>
    <description>
    The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of languages in a video file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5846/">CVE-2017-5846</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175847" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5847</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5847" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5847" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5847" ref_url="https://www.suse.com/security/cve/CVE-2017-5847" source="SUSE CVE"/>
    <description>
    The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5847/">CVE-2017-5847</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175848" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5848</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5848" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5848" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5848" ref_url="https://www.suse.com/security/cve/CVE-2017-5848" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-April/002790.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1032-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-04/msg00059.html" source="SUSE-SU"/>
    <description>
    The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5848/">CVE-2017-5848</cve>
	<bugzilla href="https://bugzilla.suse.com/1023259">SUSE bug 1023259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024068">SUSE bug 1024068</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482016" comment="gstreamer-1.16.2-1.53 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482018" comment="libgstreamer-1_0-0-1.16.2-1.53 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175856" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5856</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5856" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5856" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5856" ref_url="https://www.suse.com/security/cve/CVE-2017-5856" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0661-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1135-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5856/">CVE-2017-5856</cve>
	<bugzilla href="https://bugzilla.suse.com/1023053">SUSE bug 1023053</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024186">SUSE bug 1024186</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175857" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5857</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5857" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5857" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5857" ref_url="https://www.suse.com/security/cve/CVE-2017-5857" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
    <description>
    Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_UNREF commands sent without detaching the backing storage beforehand.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5857/">CVE-2017-5857</cve>
	<bugzilla href="https://bugzilla.suse.com/1023073">SUSE bug 1023073</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175897" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5897</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5897" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5897" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5897" ref_url="https://www.suse.com/security/cve/CVE-2017-5897" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0575-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0547-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00037.html" source="SUSE-SU"/>
    <description>
    The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2017-5897/">CVE-2017-5897</cve>
	<bugzilla href="https://bugzilla.suse.com/1023762">SUSE bug 1023762</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175898" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5898</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5898" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5898" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5898" ref_url="https://www.suse.com/security/cve/CVE-2017-5898" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0625-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0661-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1135-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1241-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0707-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1312-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-05/msg00058.html" source="SUSE-SU"/>
    <description>
    Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5898/">CVE-2017-5898</cve>
	<bugzilla href="https://bugzilla.suse.com/1023907">SUSE bug 1023907</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1024307">SUSE bug 1024307</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175931" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5931</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5931" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5931" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5931" ref_url="https://www.suse.com/security/cve/CVE-2017-5931" source="SUSE CVE"/>
    <description>
    Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code on the host via a crafted virtio-crypto request, which triggers a heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-5931/">CVE-2017-5931</cve>
	<bugzilla href="https://bugzilla.suse.com/1024114">SUSE bug 1024114</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175937" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5937</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5937" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5937" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5937" ref_url="https://www.suse.com/security/cve/CVE-2017-5937" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002738.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0902-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-03/msg00119.html" source="SUSE-SU"/>
    <description>
    The util_format_is_pure_uint function in vrend_renderer.c in Virgil 3d project (aka virglrenderer) 0.6.0 and earlier allows local guest OS users to cause a denial of service (NULL pointer dereference) via a crafted VIRGL_CCMD_CLEAR command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5937/">CVE-2017-5937</cve>
	<bugzilla href="https://bugzilla.suse.com/1024232">SUSE bug 1024232</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1041089">SUSE bug 1041089</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009488549" comment="libvirglrenderer0-0.6.0-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175950" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5950</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5950" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5950" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5950" ref_url="https://www.suse.com/security/cve/CVE-2017-5950" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003791.html" source="SUSE-SU"/>
    <description>
    The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.3 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5950/">CVE-2017-5950</cve>
	<bugzilla href="https://bugzilla.suse.com/1032144">SUSE bug 1032144</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628930" comment="libyaml-cpp0_6-0.6.1-4.2.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175953" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5953</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5953" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5953" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5953" ref_url="https://www.suse.com/security/cve/CVE-2017-5953" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-July/003007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0511-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-02/msg00090.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1811-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-07/msg00039.html" source="SUSE-SU"/>
    <description>
    vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-5953/">CVE-2017-5953</cve>
	<bugzilla href="https://bugzilla.suse.com/1024724">SUSE bug 1024724</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123143">SUSE bug 1123143</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173534">SUSE bug 1173534</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760864" comment="vim-data-common-8.0.1568-5.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760865" comment="vim-small-8.0.1568-5.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175957" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5957</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5957" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5957" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5957" ref_url="https://www.suse.com/security/cve/CVE-2017-5957" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002738.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0902-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-03/msg00119.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the vrend_decode_set_framebuffer_state function in vrend_decode.c in virglrenderer before 926b9b3460a48f6454d8bbe9e44313d86a65447f, as used in Quick Emulator (QEMU), allows a local guest users to cause a denial of service (application crash) via the "nr_cbufs" argument.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5957/">CVE-2017-5957</cve>
	<bugzilla href="https://bugzilla.suse.com/1024993">SUSE bug 1024993</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009488549" comment="libvirglrenderer0-0.6.0-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175967" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5967</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5967" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5967" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5967" ref_url="https://www.suse.com/security/cve/CVE-2017-5967" source="SUSE CVE"/>
    <description>
    The time subsystem in the Linux kernel through 4.9.9, when CONFIG_TIMER_STATS is enabled, allows local users to discover real PID values (as distinguished from PID values inside a PID namespace) by reading the /proc/timer_list file, related to the print_timer function in kernel/time/timer_list.c and the __timer_stats_timer_set_start_info function in kernel/time/timer.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-5967/">CVE-2017-5967</cve>
	<bugzilla href="https://bugzilla.suse.com/1025209">SUSE bug 1025209</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175969" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5969</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5969" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5969" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5969" ref_url="https://www.suse.com/security/cve/CVE-2017-5969" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1670-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-July/003017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1746-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-07/msg00000.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document.  NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5969/">CVE-2017-5969</cve>
	<bugzilla href="https://bugzilla.suse.com/1024989">SUSE bug 1024989</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175972" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5972</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5972" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5972" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5972" ref_url="https://www.suse.com/security/cve/CVE-2017-5972" source="SUSE CVE"/>
    <description>
    The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demonstrated by an attack against the kernel-3.10.0 package in CentOS Linux 7. NOTE: third parties have been unable to discern any relationship between the GitHub Engineering finding and the Trigemini.c attack code.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5972/">CVE-2017-5972</cve>
	<bugzilla href="https://bugzilla.suse.com/1026173">SUSE bug 1026173</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175973" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5973</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5973" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5973" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5973" ref_url="https://www.suse.com/security/cve/CVE-2017-5973" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0582-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5973/">CVE-2017-5973</cve>
	<bugzilla href="https://bugzilla.suse.com/1025109">SUSE bug 1025109</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1025188">SUSE bug 1025188</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175987" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5987</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5987" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5987" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5987" ref_url="https://www.suse.com/security/cve/CVE-2017-5987" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors involving the transfer mode register during multi block transfer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5987/">CVE-2017-5987</cve>
	<bugzilla href="https://bugzilla.suse.com/1025311">SUSE bug 1025311</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175993" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5993</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5993" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5993" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5993" ref_url="https://www.suse.com/security/cve/CVE-2017-5993" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002738.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0902-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-03/msg00119.html" source="SUSE-SU"/>
    <description>
    Memory leak in the vrend_renderer_init_blit_ctx function in vrend_blitter.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_CCMD_BLIT commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5993/">CVE-2017-5993</cve>
	<bugzilla href="https://bugzilla.suse.com/1025505">SUSE bug 1025505</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009488549" comment="libvirglrenderer0-0.6.0-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20175994" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-5994</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-5994" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5994" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-5994" ref_url="https://www.suse.com/security/cve/CVE-2017-5994" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002738.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0902-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-03/msg00119.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and crash) via the num_elements parameter.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-5994/">CVE-2017-5994</cve>
	<bugzilla href="https://bugzilla.suse.com/1025507">SUSE bug 1025507</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009488549" comment="libvirglrenderer0-0.6.0-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176001" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6001</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6001" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6001" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6001" ref_url="https://www.suse.com/security/cve/CVE-2017-6001" source="SUSE CVE"/>
    <description>
    Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a software group into a hardware context.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6786.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-6001/">CVE-2017-6001</cve>
	<bugzilla href="https://bugzilla.suse.com/1015160">SUSE bug 1015160</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1025626">SUSE bug 1025626</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176004" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6004</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6004" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6004" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6004" ref_url="https://www.suse.com/security/cve/CVE-2017-6004" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009725.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3652-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009715.html" source="SUSE-SU"/>
    <description>
    The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-6004/">CVE-2017-6004</cve>
	<bugzilla href="https://bugzilla.suse.com/1025709">SUSE bug 1025709</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191803">SUSE bug 1191803</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193384">SUSE bug 1193384</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480657" comment="libpcre1-8.41-4.20 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176058" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6058</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6058" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6058" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6058" ref_url="https://www.suse.com/security/cve/CVE-2017-6058" source="SUSE CVE"/>
    <description>
    Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-6058/">CVE-2017-6058</cve>
	<bugzilla href="https://bugzilla.suse.com/1025837">SUSE bug 1025837</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176074" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6074</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6074" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6074" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6074" ref_url="https://www.suse.com/security/cve/CVE-2017-6074" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1183-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="TID7018645" ref_url="https://www.suse.com/support/kb/doc/?id=7018645" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0547-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-02/msg00037.html" source="SUSE-SU"/>
    <description>
    The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-6074/">CVE-2017-6074</cve>
	<bugzilla href="https://bugzilla.suse.com/1026024">SUSE bug 1026024</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1072204">SUSE bug 1072204</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176345" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6345</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6345" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6345" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6345" ref_url="https://www.suse.com/security/cve/CVE-2017-6345" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1183-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0906-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0907-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00001.html" source="SUSE-SU"/>
    <description>
    The LLC subsystem in the Linux kernel before 4.9.13 does not ensure that a certain destructor exists in required circumstances, which allows local users to cause a denial of service (BUG_ON) or possibly have unspecified other impact via crafted system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-6345/">CVE-2017-6345</cve>
	<bugzilla href="https://bugzilla.suse.com/1027179">SUSE bug 1027179</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1027190">SUSE bug 1027190</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176348" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6348</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6348" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6348" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6348" ref_url="https://www.suse.com/security/cve/CVE-2017-6348" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0906-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00000.html" source="SUSE-SU"/>
    <description>
    The hashbin_delete function in net/irda/irqueue.c in the Linux kernel before 4.9.13 improperly manages lock dropping, which allows local users to cause a denial of service (deadlock) via crafted operations on IrDA devices.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-6348/">CVE-2017-6348</cve>
	<bugzilla href="https://bugzilla.suse.com/1027178">SUSE bug 1027178</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176349" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6349</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6349" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6349" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6349" ref_url="https://www.suse.com/security/cve/CVE-2017-6349" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1811-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-07/msg00039.html" source="SUSE-SU"/>
    <description>
    An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-6349/">CVE-2017-6349</cve>
	<bugzilla href="https://bugzilla.suse.com/1027057">SUSE bug 1027057</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760864" comment="vim-data-common-8.0.1568-5.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760865" comment="vim-small-8.0.1568-5.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176350" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6350</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6350" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6350" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6350" ref_url="https://www.suse.com/security/cve/CVE-2017-6350" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1811-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-07/msg00039.html" source="SUSE-SU"/>
    <description>
    An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-6350/">CVE-2017-6350</cve>
	<bugzilla href="https://bugzilla.suse.com/1027053">SUSE bug 1027053</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760864" comment="vim-data-common-8.0.1568-5.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760865" comment="vim-small-8.0.1568-5.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176353" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6353</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6353" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6353" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6353" ref_url="https://www.suse.com/security/cve/CVE-2017-6353" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1183-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0906-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0907-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00001.html" source="SUSE-SU"/>
    <description>
    net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-6353/">CVE-2017-6353</cve>
	<bugzilla href="https://bugzilla.suse.com/1025235">SUSE bug 1025235</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1027066">SUSE bug 1027066</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176386" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6386</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6386" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6386" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6386" ref_url="https://www.suse.com/security/cve/CVE-2017-6386" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-March/002738.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0902-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-03/msg00119.html" source="SUSE-SU"/>
    <description>
    Memory leak in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_OBJECT_VERTEX_ELEMENTS commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-6386/">CVE-2017-6386</cve>
	<bugzilla href="https://bugzilla.suse.com/1027376">SUSE bug 1027376</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009488549" comment="libvirglrenderer0-0.6.0-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176414" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6414</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6414" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6414" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6414" ref_url="https://www.suse.com/security/cve/CVE-2017-6414" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1080-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1081-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00006.html" source="SUSE-SU"/>
    <description>
    Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-6414/">CVE-2017-6414</cve>
	<bugzilla href="https://bugzilla.suse.com/1027514">SUSE bug 1027514</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1027570">SUSE bug 1027570</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176419" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6419</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6419" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6419" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6419" ref_url="https://www.suse.com/security/cve/CVE-2017-6419" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0254-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0255-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0809-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0863-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0258-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0825-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00062.html" source="SUSE-SU"/>
    <description>
    mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-6419/">CVE-2017-6419</cve>
	<bugzilla href="https://bugzilla.suse.com/1052449">SUSE bug 1052449</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1083915">SUSE bug 1083915</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482310" comment="libmspack0-0.6-3.8.19 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176505" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6505</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6505" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6505" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6505" ref_url="https://www.suse.com/security/cve/CVE-2017-6505" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:0983-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1080-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1081-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1078-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    The ohci_service_ed_list function in hw/usb/hcd-ohci.c in QEMU (aka Quick Emulator) before 2.9.0 allows local guest OS users to cause a denial of service (infinite loop) via vectors involving the number of link endpoint list descriptors, a different vulnerability than CVE-2017-9330.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-6505/">CVE-2017-6505</cve>
	<bugzilla href="https://bugzilla.suse.com/1028184">SUSE bug 1028184</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1028235">SUSE bug 1028235</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176507" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6507</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6507" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6507" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6507" ref_url="https://www.suse.com/security/cve/CVE-2017-6507" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:0969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00011.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to handle 'restart' operations removing AppArmor profiles that aren't found in the typical filesystem locations, such as /etc/apparmor.d/. Userspace projects that manage their own AppArmor profiles in atypical directories, such as what's done by LXD and Docker, are affected by this flaw in the AppArmor init script logic.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-6507/">CVE-2017-6507</cve>
	<bugzilla href="https://bugzilla.suse.com/1029696">SUSE bug 1029696</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760773" comment="apparmor-parser-2.13.4-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176874" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6874</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6874" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6874" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6874" ref_url="https://www.suse.com/security/cve/CVE-2017-6874" source="SUSE CVE"/>
    <description>
    Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-6874/">CVE-2017-6874</cve>
	<bugzilla href="https://bugzilla.suse.com/1029314">SUSE bug 1029314</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176891" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6891</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6891" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6891" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6891" ref_url="https://www.suse.com/security/cve/CVE-2017-6891" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1886-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-July/003036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012726.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00018.html" source="SUSE-SU"/>
    <description>
    Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utility.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-6891/">CVE-2017-6891</cve>
	<bugzilla href="https://bugzilla.suse.com/1040621">SUSE bug 1040621</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1149679">SUSE bug 1149679</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009655543" comment="libgnutls30 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334127" comment="libtasn1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336122" comment="libtasn1-6 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20176951" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-6951</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-6951" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6951" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-6951" ref_url="https://www.suse.com/security/cve/CVE-2017-6951" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
    <description>
    The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-6951/">CVE-2017-6951</cve>
	<bugzilla href="https://bugzilla.suse.com/1029850">SUSE bug 1029850</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1030593">SUSE bug 1030593</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177186" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7186</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7186" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7186" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7186" ref_url="https://www.suse.com/security/cve/CVE-2017-7186" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009725.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3652-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009715.html" source="SUSE-SU"/>
    <description>
    libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-7186/">CVE-2017-7186</cve>
	<bugzilla href="https://bugzilla.suse.com/1030066">SUSE bug 1030066</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1037164">SUSE bug 1037164</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009480657" comment="libpcre1-8.41-4.20 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480667" comment="libpcre2-8-0-10.31-1.14 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177187" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7187</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7187" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7187" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7187" ref_url="https://www.suse.com/security/cve/CVE-2017-7187" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1183-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1247-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1301-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1140-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1215-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00016.html" source="SUSE-SU"/>
    <description>
    The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel through 4.10.4 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a large command size in an SG_NEXT_CMD_LEN ioctl call, leading to out-of-bounds write access in the sg_write function.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-7187/">CVE-2017-7187</cve>
	<bugzilla href="https://bugzilla.suse.com/1027179">SUSE bug 1027179</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1030213">SUSE bug 1030213</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177244" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7244</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7244" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7244" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7244" ref_url="https://www.suse.com/security/cve/CVE-2017-7244" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009725.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3652-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009715.html" source="SUSE-SU"/>
    <description>
    The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-7244/">CVE-2017-7244</cve>
	<bugzilla href="https://bugzilla.suse.com/1030807">SUSE bug 1030807</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480657" comment="libpcre1-8.41-4.20 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177245" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7245</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7245" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7245" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7245" ref_url="https://www.suse.com/security/cve/CVE-2017-7245" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009725.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3652-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009715.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 4) or possibly have unspecified other impact via a crafted file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-7245/">CVE-2017-7245</cve>
	<bugzilla href="https://bugzilla.suse.com/1030805">SUSE bug 1030805</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480657" comment="libpcre1-8.41-4.20 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177246" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7246</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7246" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7246" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7246" ref_url="https://www.suse.com/security/cve/CVE-2017-7246" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009725.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3652-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009715.html" source="SUSE-SU"/>
    <description>
    Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact via a crafted file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-7246/">CVE-2017-7246</cve>
	<bugzilla href="https://bugzilla.suse.com/1030803">SUSE bug 1030803</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1030805">SUSE bug 1030805</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480657" comment="libpcre1-8.41-4.20 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177273" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7273</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7273" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7273" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7273" ref_url="https://www.suse.com/security/cve/CVE-2017-7273" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3746-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3869-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004878.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13937-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005067.html" source="SUSE-SU"/>
    <description>
    The cp_report_fixup function in drivers/hid/hid-cypress.c in the Linux kernel 3.2 and 4.x before 4.9.4 allows physically proximate attackers to cause a denial of service (integer underflow) or possibly have unspecified other impact via a crafted HID report.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-7273/">CVE-2017-7273</cve>
	<bugzilla href="https://bugzilla.suse.com/1031240">SUSE bug 1031240</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177435" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7435</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7435" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7435" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7435" ref_url="https://www.suse.com/security/cve/CVE-2017-7435" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2264-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2688-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004553.html" source="SUSE-SU"/>
		<reference ref_id="TID000018998" ref_url="https://www.suse.com/support/kb/doc/?id=000018998" source="SUSE-SU"/>
		<reference ref_id="TID7021171" ref_url="https://www.suse.com/support/kb/doc/?id=7021171" source="SUSE-SU"/>
		<reference ref_id="TID7021201" ref_url="https://www.suse.com/support/kb/doc/?id=7021201" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2335-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00005.html" source="SUSE-SU"/>
    <description>
    In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-7435/">CVE-2017-7435</cve>
	<bugzilla href="https://bugzilla.suse.com/1009127">SUSE bug 1009127</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1038984">SUSE bug 1038984</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1045735">SUSE bug 1045735</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760839" comment="libzypp-17.25.6-3.28.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177436" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7436</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7436" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7436" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7436" ref_url="https://www.suse.com/security/cve/CVE-2017-7436" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2264-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2344-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2688-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004553.html" source="SUSE-SU"/>
		<reference ref_id="TID000018998" ref_url="https://www.suse.com/support/kb/doc/?id=000018998" source="SUSE-SU"/>
		<reference ref_id="TID7021171" ref_url="https://www.suse.com/support/kb/doc/?id=7021171" source="SUSE-SU"/>
		<reference ref_id="TID7021201" ref_url="https://www.suse.com/support/kb/doc/?id=7021201" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2335-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2370-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00014.html" source="SUSE-SU"/>
    <description>
    In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-7436/">CVE-2017-7436</cve>
	<bugzilla href="https://bugzilla.suse.com/1008325">SUSE bug 1008325</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1009127">SUSE bug 1009127</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1038984">SUSE bug 1038984</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1045735">SUSE bug 1045735</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760839" comment="libzypp-17.25.6-3.28.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760870" comment="zypper-1.14.42-3.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760871" comment="zypper-needs-restarting-1.14.42-3.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177468" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7468</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7468" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7468" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7468" ref_url="https://www.suse.com/security/cve/CVE-2017-7468" source="SUSE CVE"/>
    <description>
    In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is unacceptable since a server by specification is allowed to skip the client certificate check on resume, and may instead use the old identity which was established by the previous certificate (or no certificate). libcurl supports by default the use of TLS session id/ticket to resume previous TLS sessions to speed up subsequent TLS handshakes. They are used when for any reason an existing TLS connection couldn't be kept alive to make the next handshake faster. This flaw is a regression and identical to CVE-2016-5419 reported on August 3rd 2016, but affecting a different version range.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2017-7468/">CVE-2017-7468</cve>
	<bugzilla href="https://bugzilla.suse.com/1033413">SUSE bug 1033413</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1033442">SUSE bug 1033442</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1042181">SUSE bug 1042181</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/991389">SUSE bug 991389</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177471" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7471</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7471" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7471" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7471" ref_url="https://www.suse.com/security/cve/CVE-2017-7471" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing files on a shared host directory. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-7471/">CVE-2017-7471</cve>
	<bugzilla href="https://bugzilla.suse.com/1034866">SUSE bug 1034866</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1034990">SUSE bug 1034990</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177472" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7472</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7472" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7472" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7472" ref_url="https://www.suse.com/security/cve/CVE-2017-7472" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005476.html" source="SUSE-SU"/>
    <description>
    The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-7472/">CVE-2017-7472</cve>
	<bugzilla href="https://bugzilla.suse.com/1034862">SUSE bug 1034862</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177475" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7475</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7475" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7475" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7475" ref_url="https://www.suse.com/security/cve/CVE-2017-7475" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1453-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004095.html" source="SUSE-SU"/>
    <description>
    Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-7475/">CVE-2017-7475</cve>
	<bugzilla href="https://bugzilla.suse.com/1036789">SUSE bug 1036789</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481783" comment="libcairo2-1.16.0-1.55 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177476" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7476</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7476" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7476" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7476" ref_url="https://www.suse.com/security/cve/CVE-2017-7476" source="SUSE CVE"/>
    <description>
    Gnulib before 2017-04-26 has a heap-based buffer overflow with the TZ environment variable. The error is in the save_abbr function in time_rz.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-17"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-7476/">CVE-2017-7476</cve>
	<bugzilla href="https://bugzilla.suse.com/1036636">SUSE bug 1036636</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1037124">SUSE bug 1037124</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1037125">SUSE bug 1037125</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1037142">SUSE bug 1037142</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009480143" comment="coreutils-8.29-2.12 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655543" comment="libgnutls30 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177482" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7482</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7482" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7482" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7482" ref_url="https://www.suse.com/security/cve/CVE-2017-7482" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3410-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3358-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3359-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00079.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going over the end of the buffer. This could possibly lead to memory corruption and possible privilege escalation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2017-7482/">CVE-2017-7482</cve>
	<bugzilla href="https://bugzilla.suse.com/1046107">SUSE bug 1046107</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177487" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7487</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7487" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7487" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7487" ref_url="https://www.suse.com/security/cve/CVE-2017-7487" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00006.html" source="SUSE-SU"/>
    <description>
    The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-7487/">CVE-2017-7487</cve>
	<bugzilla href="https://bugzilla.suse.com/1038879">SUSE bug 1038879</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1038883">SUSE bug 1038883</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1038981">SUSE bug 1038981</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1038982">SUSE bug 1038982</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1072204">SUSE bug 1072204</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/870618">SUSE bug 870618</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177493" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7493</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7493" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7493" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7493" ref_url="https://www.suse.com/security/cve/CVE-2017-7493" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to escalate their privileges inside guest.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-7493/">CVE-2017-7493</cve>
	<bugzilla href="https://bugzilla.suse.com/1039495">SUSE bug 1039495</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177495" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7495</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7495" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7495" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7495" ref_url="https://www.suse.com/security/cve/CVE-2017-7495" source="SUSE CVE"/>
    <description>
    fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-before-commit list, which allows local users to obtain sensitive information from other users' files in opportunistic circumstances by waiting for a hardware reset, creating a new file, making write system calls, and reading this file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-7495/">CVE-2017-7495</cve>
	<bugzilla href="https://bugzilla.suse.com/1039010">SUSE bug 1039010</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177500" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7500</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7500" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7500" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7500" ref_url="https://www.suse.com/security/cve/CVE-2017-7500" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004319.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3286-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3884-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3884-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005393.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2215-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3373-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00058.html" source="SUSE-SU"/>
    <description>
    It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-7500/">CVE-2017-7500</cve>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135195">SUSE bug 1135195</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157882">SUSE bug 1157882</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157883">SUSE bug 1157883</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/943457">SUSE bug 943457</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/964063">SUSE bug 964063</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482536" comment="rpm-4.14.1-20.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177501" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7501</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7501" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7501" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7501" ref_url="https://www.suse.com/security/cve/CVE-2017-7501" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3286-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3884-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3884-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005393.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3373-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00058.html" source="SUSE-SU"/>
    <description>
    It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-7501/">CVE-2017-7501</cve>
	<bugzilla href="https://bugzilla.suse.com/1119217">SUSE bug 1119217</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135195">SUSE bug 1135195</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157882">SUSE bug 1157882</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157883">SUSE bug 1157883</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/943457">SUSE bug 943457</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009347616" comment="rpm is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177518" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7518</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7518" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7518" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7518" ref_url="https://www.suse.com/security/cve/CVE-2017-7518" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2869-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2956-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1825-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00010.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process inside a guest could use this flaw to potentially escalate their privileges inside the guest. Linux guests are not affected by this.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-7518/">CVE-2017-7518</cve>
	<bugzilla href="https://bugzilla.suse.com/1045922">SUSE bug 1045922</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177526" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7526</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7526" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7526" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7526" ref_url="https://www.suse.com/security/cve/CVE-2017-7526" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-July/003013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-July/003014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1866-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-July/003034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1822-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-07/msg00043.html" source="SUSE-SU"/>
    <description>
    libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-7526/">CVE-2017-7526</cve>
	<bugzilla href="https://bugzilla.suse.com/1046607">SUSE bug 1046607</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1047462">SUSE bug 1047462</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123792">SUSE bug 1123792</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482233" comment="libgcrypt20-1.8.2-8.36.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177542" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7542</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7542" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7542" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7542" ref_url="https://www.suse.com/security/cve/CVE-2017-7542" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2286-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2869-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2956-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2110-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2112-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00032.html" source="SUSE-SU"/>
    <description>
    The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel through 4.12.3 allows local users to cause a denial of service (integer overflow and infinite loop) by leveraging the ability to open a raw socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-7542/">CVE-2017-7542</cve>
	<bugzilla href="https://bugzilla.suse.com/1049882">SUSE bug 1049882</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1061936">SUSE bug 1061936</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177555" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7555</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7555" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7555" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7555" ref_url="https://www.suse.com/security/cve/CVE-2017-7555" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0652-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003801.html" source="SUSE-SU"/>
    <description>
    Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-7555/">CVE-2017-7555</cve>
	<bugzilla href="https://bugzilla.suse.com/1054171">SUSE bug 1054171</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009480071" comment="augeas-1.10.1-1.11 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480073" comment="augeas-lenses-1.10.1-1.11 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480074" comment="libaugeas0-1.10.1-1.11 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177607" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7607</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7607" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7607" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7607" ref_url="https://www.suse.com/security/cve/CVE-2017-7607" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-7607/">CVE-2017-7607</cve>
	<bugzilla href="https://bugzilla.suse.com/1033084">SUSE bug 1033084</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177608" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7608</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7608" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7608" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7608" ref_url="https://www.suse.com/security/cve/CVE-2017-7608" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-7608/">CVE-2017-7608</cve>
	<bugzilla href="https://bugzilla.suse.com/1033085">SUSE bug 1033085</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177609" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7609</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7609" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7609" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7609" ref_url="https://www.suse.com/security/cve/CVE-2017-7609" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-7609/">CVE-2017-7609</cve>
	<bugzilla href="https://bugzilla.suse.com/1033086">SUSE bug 1033086</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177610" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7610</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7610" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7610" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7610" ref_url="https://www.suse.com/security/cve/CVE-2017-7610" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-7610/">CVE-2017-7610</cve>
	<bugzilla href="https://bugzilla.suse.com/1033087">SUSE bug 1033087</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177611" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7611</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7611" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7611" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7611" ref_url="https://www.suse.com/security/cve/CVE-2017-7611" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-7611/">CVE-2017-7611</cve>
	<bugzilla href="https://bugzilla.suse.com/1033088">SUSE bug 1033088</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177612" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7612</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7612" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7612" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7612" ref_url="https://www.suse.com/security/cve/CVE-2017-7612" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-7612/">CVE-2017-7612</cve>
	<bugzilla href="https://bugzilla.suse.com/1033089">SUSE bug 1033089</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177613" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7613</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7613" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7613" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7613" ref_url="https://www.suse.com/security/cve/CVE-2017-7613" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-7613/">CVE-2017-7613</cve>
	<bugzilla href="https://bugzilla.suse.com/1033090">SUSE bug 1033090</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177618" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7618</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7618" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7618" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7618" ref_url="https://www.suse.com/security/cve/CVE-2017-7618" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1140-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1215-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00016.html" source="SUSE-SU"/>
    <description>
    crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-12"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-7618/">CVE-2017-7618</cve>
	<bugzilla href="https://bugzilla.suse.com/1033340">SUSE bug 1033340</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177645" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7645</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7645" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7645" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7645" ref_url="https://www.suse.com/security/cve/CVE-2017-7645" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2043-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2046-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2049-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2060-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2062-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2064-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2065-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2066-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2070-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2072-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2088-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2091-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2092-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2095-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2096-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2098-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2099-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2100-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2475-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2476-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2775-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00006.html" source="SUSE-SU"/>
    <description>
    The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c, and fs/nfsd/nfsxdr.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-7645/">CVE-2017-7645</cve>
	<bugzilla href="https://bugzilla.suse.com/1034670">SUSE bug 1034670</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1036741">SUSE bug 1036741</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1046191">SUSE bug 1046191</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177869" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7869</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7869" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7869" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7869" ref_url="https://www.suse.com/security/cve/CVE-2017-7869" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-July/003024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1886-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-July/003036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1875-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-07/msg00064.html" source="SUSE-SU"/>
    <description>
    GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function in opencdk/read-packet.c. This issue (which is a subset of the vendor's GNUTLS-SA-2017-3 report) is fixed in 3.5.10.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-7869/">CVE-2017-7869</cve>
	<bugzilla href="https://bugzilla.suse.com/1034173">SUSE bug 1034173</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1038337">SUSE bug 1038337</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1149679">SUSE bug 1149679</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177874" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7874</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7874" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7874" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7874" ref_url="https://www.suse.com/security/cve/CVE-2017-7874" source="SUSE CVE"/>
    <description>
    ** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2017-7874/">CVE-2017-7874</cve>
	<bugzilla href="https://bugzilla.suse.com/1034330">SUSE bug 1034330</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/493158">SUSE bug 493158</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177889" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7889</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7889" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7889" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7889" ref_url="https://www.suse.com/security/cve/CVE-2017-7889" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
    <description>
    The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access restrictions) via an application that opens the /dev/mem file, related to arch/x86/mm/init.c and drivers/char/mem.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-7889/">CVE-2017-7889</cve>
	<bugzilla href="https://bugzilla.suse.com/1034405">SUSE bug 1034405</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177960" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7960</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7960" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7960" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7960" ref_url="https://www.suse.com/security/cve/CVE-2017-7960" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1468-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005549.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1575-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00043.html" source="SUSE-SU"/>
    <description>
    The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-7960/">CVE-2017-7960</cve>
	<bugzilla href="https://bugzilla.suse.com/1034481">SUSE bug 1034481</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482151" comment="libcroco-0_6-3-0.6.13-1.26 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177961" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7961</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7961" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7961" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7961" ref_url="https://www.suse.com/security/cve/CVE-2017-7961" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1468-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005549.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1575-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00043.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file. NOTE: third-party analysis reports "This is not a security issue in my view. The conversion surely is truncating the double into a long value, but there is no impact as the value is one of the RGB components."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-7961/">CVE-2017-7961</cve>
	<bugzilla href="https://bugzilla.suse.com/1034482">SUSE bug 1034482</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1132069">SUSE bug 1132069</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482151" comment="libcroco-0_6-3-0.6.13-1.26 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20177980" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-7980</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-7980" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7980" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-7980" ref_url="https://www.suse.com/security/cve/CVE-2017-7980" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1145-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1146-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1148-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-7980/">CVE-2017-7980</cve>
	<bugzilla href="https://bugzilla.suse.com/1035406">SUSE bug 1035406</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1035483">SUSE bug 1035483</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178105" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8105</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8105" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8105" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8105" ref_url="https://www.suse.com/security/cve/CVE-2017-8105" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0414-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0462-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-February/003736.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0420-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00016.html" source="SUSE-SU"/>
    <description>
    FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-8105/">CVE-2017-8105</cve>
	<bugzilla href="https://bugzilla.suse.com/1034186">SUSE bug 1034186</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1035807">SUSE bug 1035807</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1036457">SUSE bug 1036457</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1079459">SUSE bug 1079459</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178106" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8106</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8106" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8106" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8106" ref_url="https://www.suse.com/security/cve/CVE-2017-8106" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1360-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
    <description>
    The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointer.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-12"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-8106/">CVE-2017-8106</cve>
	<bugzilla href="https://bugzilla.suse.com/1035877">SUSE bug 1035877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178112" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8112</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8112" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8112" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8112" ref_url="https://www.suse.com/security/cve/CVE-2017-8112" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1770-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1795-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-8112/">CVE-2017-8112</cve>
	<bugzilla href="https://bugzilla.suse.com/1036211">SUSE bug 1036211</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1036470">SUSE bug 1036470</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178287" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8287</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8287" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8287" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8287" ref_url="https://www.suse.com/security/cve/CVE-2017-8287" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0414-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0462-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-February/003736.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0420-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00016.html" source="SUSE-SU"/>
    <description>
    FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-8287/">CVE-2017-8287</cve>
	<bugzilla href="https://bugzilla.suse.com/1034186">SUSE bug 1034186</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1035807">SUSE bug 1035807</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1036457">SUSE bug 1036457</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1079459">SUSE bug 1079459</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178309" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8309</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8309" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8309" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8309" ref_url="https://www.suse.com/security/cve/CVE-2017-8309" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1715-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1742-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1770-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1795-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1826-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-8309/">CVE-2017-8309</cve>
	<bugzilla href="https://bugzilla.suse.com/1037242">SUSE bug 1037242</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1037243">SUSE bug 1037243</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178379" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8379</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8379" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8379" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8379" ref_url="https://www.suse.com/security/cve/CVE-2017-8379" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-8379/">CVE-2017-8379</cve>
	<bugzilla href="https://bugzilla.suse.com/1037334">SUSE bug 1037334</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178380" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8380</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8380" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8380" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8380" ref_url="https://www.suse.com/security/cve/CVE-2017-8380" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact via unknown vectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-8380/">CVE-2017-8380</cve>
	<bugzilla href="https://bugzilla.suse.com/1037336">SUSE bug 1037336</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178779" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8779</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8779" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8779" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8779" ref_url="https://www.suse.com/security/cve/CVE-2017-8779" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1306-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1314-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1328-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00080.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1381-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1412-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-05/msg00071.html" source="SUSE-SU"/>
    <description>
    rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-8779/">CVE-2017-8779</cve>
	<bugzilla href="https://bugzilla.suse.com/1037559">SUSE bug 1037559</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1037930">SUSE bug 1037930</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1101814">SUSE bug 1101814</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/798028">SUSE bug 798028</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482535" comment="rpcbind-0.2.3-5.9.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178786" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8786</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8786" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8786" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8786" ref_url="https://www.suse.com/security/cve/CVE-2017-8786" source="SUSE CVE"/>
    <description>
    pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-8786/">CVE-2017-8786</cve>
	<bugzilla href="https://bugzilla.suse.com/1036942">SUSE bug 1036942</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1037718">SUSE bug 1037718</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480667" comment="libpcre2-8-0-10.31-1.14 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178797" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8797</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8797" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8797" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8797" ref_url="https://www.suse.com/security/cve/CVE-2017-8797" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2043-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2046-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2062-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2064-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2065-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2066-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2070-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00015.html" source="SUSE-SU"/>
    <description>
    The NFSv4 server in the Linux kernel before 4.11.3 does not properly validate the layout type when processing the NFSv4 pNFS GETDEVICEINFO or LAYOUTGET operand in a UDP packet from a remote attacker. This type value is uninitialized upon encountering certain error conditions. This value is used as an array index for dereferencing, which leads to an OOPS and eventually a DoS of knfsd and a soft-lockup of the whole system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-8797/">CVE-2017-8797</cve>
	<bugzilla href="https://bugzilla.suse.com/1046202">SUSE bug 1046202</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1046206">SUSE bug 1046206</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178813" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8813</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8813" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8813" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8813" ref_url="https://www.suse.com/security/cve/CVE-2017-8813" source="SUSE CVE"/>
    <description>
    ** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2017-8831.  Reason: This candidate is a duplicate of CVE-2017-8831.  A typo caused the wrong ID to be used.  Notes: All CVE users should reference CVE-2017-8831 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-8813/">CVE-2017-8813</cve>
	<bugzilla href="https://bugzilla.suse.com/1070849">SUSE bug 1070849</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178816" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8816</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8816" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8816" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8816" ref_url="https://www.suse.com/security/cve/CVE-2017-8816" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003607.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0161-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00064.html" source="SUSE-SU"/>
    <description>
    The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2017-8816/">CVE-2017-8816</cve>
	<bugzilla href="https://bugzilla.suse.com/1069226">SUSE bug 1069226</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1106019">SUSE bug 1106019</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178817" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8817</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8817" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8817" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8817" ref_url="https://www.suse.com/security/cve/CVE-2017-8817" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003607.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0161-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00064.html" source="SUSE-SU"/>
    <description>
    The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2017-8817/">CVE-2017-8817</cve>
	<bugzilla href="https://bugzilla.suse.com/1069222">SUSE bug 1069222</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178818" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8818</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8818" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8818" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8818" ref_url="https://www.suse.com/security/cve/CVE-2017-8818" source="SUSE CVE"/>
    <description>
    curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact because too little memory is allocated for interfacing to an SSL library.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-8818/">CVE-2017-8818</cve>
	<bugzilla href="https://bugzilla.suse.com/1069714">SUSE bug 1069714</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178824" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8824</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8824" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8824" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8824" ref_url="https://www.suse.com/security/cve/CVE-2017-8824" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:3398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3410-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0031-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0180-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0213-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3358-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:3359-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00079.html" source="SUSE-SU"/>
    <description>
    The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-8824/">CVE-2017-8824</cve>
	<bugzilla href="https://bugzilla.suse.com/1070771">SUSE bug 1070771</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1076734">SUSE bug 1076734</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1092904">SUSE bug 1092904</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178831" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8831</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8831" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8831" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8831" ref_url="https://www.suse.com/security/cve/CVE-2017-8831" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2286-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2694-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2869-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2956-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2171-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00047.html" source="SUSE-SU"/>
    <description>
    The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact by changing a certain sequence-number value, aka a "double fetch" vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-8831/">CVE-2017-8831</cve>
	<bugzilla href="https://bugzilla.suse.com/1037994">SUSE bug 1037994</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1061936">SUSE bug 1061936</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178834" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8834</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8834" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8834" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8834" ref_url="https://www.suse.com/security/cve/CVE-2017-8834" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1468-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005549.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006883.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1575-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0780-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00007.html" source="SUSE-SU"/>
    <description>
    The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-8834/">CVE-2017-8834</cve>
	<bugzilla href="https://bugzilla.suse.com/1043898">SUSE bug 1043898</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1043899">SUSE bug 1043899</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482151" comment="libcroco-0_6-3-0.6.13-1.26 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178871" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8871</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8871" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8871" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8871" ref_url="https://www.suse.com/security/cve/CVE-2017-8871" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1468-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005549.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006883.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1575-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0780-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00007.html" source="SUSE-SU"/>
    <description>
    The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-8871/">CVE-2017-8871</cve>
	<bugzilla href="https://bugzilla.suse.com/1043898">SUSE bug 1043898</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1043899">SUSE bug 1043899</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482151" comment="libcroco-0_6-3-0.6.13-1.26 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178872" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8872</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8872" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8872" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8872" ref_url="https://www.suse.com/security/cve/CVE-2017-8872" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003125.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2190-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-08/msg00067.html" source="SUSE-SU"/>
    <description>
    The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-8872/">CVE-2017-8872</cve>
	<bugzilla href="https://bugzilla.suse.com/1038444">SUSE bug 1038444</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009337751" comment="libxml2-2 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009337752" comment="libxml2-tools is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20178890" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-8890</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-8890" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8890" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-8890" ref_url="https://www.suse.com/security/cve/CVE-2017-8890" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2043-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2046-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2049-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2060-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2062-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2064-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2065-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2066-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2070-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2072-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2088-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2089-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2090-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2091-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2092-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2094-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2446-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-September/003209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2447-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2448-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2791-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00006.html" source="SUSE-SU"/>
    <description>
    The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-8890/">CVE-2017-8890</cve>
	<bugzilla href="https://bugzilla.suse.com/1038544">SUSE bug 1038544</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1038564">SUSE bug 1038564</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039883">SUSE bug 1039883</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039885">SUSE bug 1039885</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1040069">SUSE bug 1040069</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1042364">SUSE bug 1042364</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1051906">SUSE bug 1051906</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179047" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9047</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9047" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9047" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9047" ref_url="https://www.suse.com/security/cve/CVE-2017-9047" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1454-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002939.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1510-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1612-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-06/msg00071.html" source="SUSE-SU"/>
    <description>
    A buffer overflow was discovered in libxml2 20904-GITv2.9.4-16-g0741801. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. The variable len is assigned strlen(buf). If the content-&gt;type is XML_ELEMENT_CONTENT_ELEMENT, then (i) the content-&gt;prefix is appended to buf (if it actually fits) whereupon (ii) content-&gt;name is written to the buffer. However, the check for whether the content-&gt;name actually fits also uses 'len' rather than the updated buffer length strlen(buf). This allows us to write about "size" many bytes beyond the allocated memory. This vulnerability causes programs that use libxml2, such as PHP, to crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-9047/">CVE-2017-9047</cve>
	<bugzilla href="https://bugzilla.suse.com/1039063">SUSE bug 1039063</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039066">SUSE bug 1039066</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039657">SUSE bug 1039657</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179048" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9048</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9048" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9048" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9048" ref_url="https://www.suse.com/security/cve/CVE-2017-9048" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1454-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002939.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1510-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1612-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-06/msg00071.html" source="SUSE-SU"/>
    <description>
    libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end of the routine, the function may strcat two more characters without checking whether the current strlen(buf) + 2 &lt; size. This vulnerability causes programs that use libxml2, such as PHP, to crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-9048/">CVE-2017-9048</cve>
	<bugzilla href="https://bugzilla.suse.com/1039064">SUSE bug 1039064</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039066">SUSE bug 1039066</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039658">SUSE bug 1039658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179049" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9049</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9049" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9049" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9049" ref_url="https://www.suse.com/security/cve/CVE-2017-9049" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1454-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-May/002931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002939.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1510-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1612-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-06/msg00071.html" source="SUSE-SU"/>
    <description>
    libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug 759398.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-9049/">CVE-2017-9049</cve>
	<bugzilla href="https://bugzilla.suse.com/1039063">SUSE bug 1039063</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039064">SUSE bug 1039064</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039066">SUSE bug 1039066</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039659">SUSE bug 1039659</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039661">SUSE bug 1039661</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1069690">SUSE bug 1069690</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123919">SUSE bug 1123919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179074" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9074</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9074" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9074" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9074" ref_url="https://www.suse.com/security/cve/CVE-2017-9074" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00006.html" source="SUSE-SU"/>
    <description>
    The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact via crafted socket and send system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-9074/">CVE-2017-9074</cve>
	<bugzilla href="https://bugzilla.suse.com/1039882">SUSE bug 1039882</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179075" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9075</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9075" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9075" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9075" ref_url="https://www.suse.com/security/cve/CVE-2017-9075" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00006.html" source="SUSE-SU"/>
    <description>
    The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-9075/">CVE-2017-9075</cve>
	<bugzilla href="https://bugzilla.suse.com/1038544">SUSE bug 1038544</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039883">SUSE bug 1039883</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1051906">SUSE bug 1051906</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179076" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9076</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9076" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9076" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9076" ref_url="https://www.suse.com/security/cve/CVE-2017-9076" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00006.html" source="SUSE-SU"/>
    <description>
    The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-9076/">CVE-2017-9076</cve>
	<bugzilla href="https://bugzilla.suse.com/1038544">SUSE bug 1038544</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1039885">SUSE bug 1039885</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1040069">SUSE bug 1040069</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1051906">SUSE bug 1051906</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179077" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9077</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9077" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9077" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9077" ref_url="https://www.suse.com/security/cve/CVE-2017-9077" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2043-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2046-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2062-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2064-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2065-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2066-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2070-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1513-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00006.html" source="SUSE-SU"/>
    <description>
    The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-9077/">CVE-2017-9077</cve>
	<bugzilla href="https://bugzilla.suse.com/1038544">SUSE bug 1038544</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1040069">SUSE bug 1040069</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1042364">SUSE bug 1042364</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179227" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9227</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9227" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9227" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9227" ref_url="https://www.suse.com/security/cve/CVE-2017-9227" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-June/002994.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1757-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1800-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-07/msg00029.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in mbc_enc_len() during regular expression searching. Invalid handling of reg-&gt;dmin in forward_search_range() could result in an invalid pointer dereference, as an out-of-bounds read from a stack buffer.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-9227/">CVE-2017-9227</cve>
	<bugzilla href="https://bugzilla.suse.com/1040883">SUSE bug 1040883</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1044976">SUSE bug 1044976</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009348236" comment="libruby2_5-2_5 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348228" comment="ruby2.5 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348239" comment="ruby2.5-stdlib is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179233" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9233</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9233" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9233" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9233" ref_url="https://www.suse.com/security/cve/CVE-2017-9233" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2299-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-September/003189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2700-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006536.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2336-1" ref_url="https://lists.opensuse.org/opensuse-updates/2017-09/msg00004.html" source="SUSE-SU"/>
    <description>
    XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-9233/">CVE-2017-9233</cve>
	<bugzilla href="https://bugzilla.suse.com/1030296">SUSE bug 1030296</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1047236">SUSE bug 1047236</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1073350">SUSE bug 1073350</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123115">SUSE bug 1123115</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/983216">SUSE bug 983216</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481944" comment="libexpat1-2.2.5-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179242" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9242</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9242" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9242" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9242" ref_url="https://www.suse.com/security/cve/CVE-2017-9242" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1853-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1990-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2043-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2046-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2049-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2060-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2062-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2064-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2065-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2066-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2067-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2070-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2072-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2088-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2089-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2090-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2091-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2092-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2094-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2095-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2096-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2098-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2099-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2100-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2342-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2446-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-September/003209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2447-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2448-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2475-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2476-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2497-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2775-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2791-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1633-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00026.html" source="SUSE-SU"/>
    <description>
    The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb data structure may occur, which allows local users to cause a denial of service (system crash) via crafted system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-12"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-9242/">CVE-2017-9242</cve>
	<bugzilla href="https://bugzilla.suse.com/1041431">SUSE bug 1041431</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1042892">SUSE bug 1042892</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179269" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9269</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9269" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9269" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9269" ref_url="https://www.suse.com/security/cve/CVE-2017-9269" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2040-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2264-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2470-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2688-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2690-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2716-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004713.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004582.html" source="SUSE-SU"/>
		<reference ref_id="TID000018998" ref_url="https://www.suse.com/support/kb/doc/?id=000018998" source="SUSE-SU"/>
		<reference ref_id="TID7021171" ref_url="https://www.suse.com/support/kb/doc/?id=7021171" source="SUSE-SU"/>
		<reference ref_id="TID7021201" ref_url="https://www.suse.com/support/kb/doc/?id=7021201" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2335-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2739-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00035.html" source="SUSE-SU"/>
    <description>
    In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" href="https://www.suse.com/security/cve/CVE-2017-9269/">CVE-2017-9269</cve>
	<bugzilla href="https://bugzilla.suse.com/1038984">SUSE bug 1038984</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1045735">SUSE bug 1045735</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760839" comment="libzypp-17.25.6-3.28.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760870" comment="zypper-1.14.42-3.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760871" comment="zypper-needs-restarting-1.14.42-3.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179271" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9271</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9271" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9271" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9271" ref_url="https://www.suse.com/security/cve/CVE-2017-9271" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:162-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:21-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:50-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:51-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008286.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008193.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0956-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008560.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FB5G3FIS4OQH3FX723SLMBOC4P37HKHV/" source="SUSE-SU"/>
    <description>
    The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2017-9271/">CVE-2017-9271</cve>
	<bugzilla href="https://bugzilla.suse.com/1050625">SUSE bug 1050625</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760839" comment="libzypp-17.25.6-3.28.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009373564" comment="zypper is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009654588" comment="zypper-needs-restarting is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179330" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9330</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9330" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9330" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9330" ref_url="https://www.suse.com/security/cve/CVE-2017-9330" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1715-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1742-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-06/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1770-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1795-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1826-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value, a different vulnerability than CVE-2017-6505.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-9330/">CVE-2017-9330</cve>
	<bugzilla href="https://bugzilla.suse.com/1042159">SUSE bug 1042159</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1042160">SUSE bug 1042160</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1043157">SUSE bug 1043157</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179445" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9445</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9445" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9445" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9445" ref_url="https://www.suse.com/security/cve/CVE-2017-9445" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1898-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2031-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2017-August/003077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2701-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-10/msg00012.html" source="SUSE-SU"/>
    <description>
    In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-9445/">CVE-2017-9445</cve>
	<bugzilla href="https://bugzilla.suse.com/1045290">SUSE bug 1045290</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1063249">SUSE bug 1063249</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179502" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9502</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9502" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9502" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9502" ref_url="https://www.suse.com/security/cve/CVE-2017-9502" source="SUSE CVE"/>
    <description>
    In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes. If the default protocol is specified to be FILE or a file: URL lacks two slashes, the given "URL" starts with a drive letter, and libcurl is built for Windows or DOS, then libcurl would copy the path 7 bytes off, so that the end of the given path would write beyond the malloc buffer (7 bytes being the length in bytes of the ascii string "file://").
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-9502/">CVE-2017-9502</cve>
	<bugzilla href="https://bugzilla.suse.com/1044243">SUSE bug 1044243</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179503" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9503</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9503" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9503" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9503" ref_url="https://www.suse.com/security/cve/CVE-2017-9503" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:1770-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1774-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1795-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:1812-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2946-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:2969-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2017:3084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:1872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-07/msg00023.html" source="SUSE-SU"/>
    <description>
    QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command processing.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-9503/">CVE-2017-9503</cve>
	<bugzilla href="https://bugzilla.suse.com/1043296">SUSE bug 1043296</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1043297">SUSE bug 1043297</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1043312">SUSE bug 1043312</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179524" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9524</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9524" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9524" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9524" ref_url="https://www.suse.com/security/cve/CVE-2017-9524" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2017:2936-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2017:2941-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00008.html" source="SUSE-SU"/>
    <description>
    The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging failure to ensure that all initialization occurs before talking to a client in the nbd_negotiate function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-9524/">CVE-2017-9524</cve>
	<bugzilla href="https://bugzilla.suse.com/1043808">SUSE bug 1043808</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179614" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9614</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9614" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9614" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9614" ref_url="https://www.suse.com/security/cve/CVE-2017-9614" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file. NOTE: Maintainer asserts the issue is due to a bug in downstream code caused by misuse of the libjpeg API.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-04"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2017-9614/">CVE-2017-9614</cve>
	<bugzilla href="https://bugzilla.suse.com/1050231">SUSE bug 1050231</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179814" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9814</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9814" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9814" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9814" ref_url="https://www.suse.com/security/cve/CVE-2017-9814" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/003991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1453-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1873-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1937-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007144.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1215-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-05/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1895-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1003-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00042.html" source="SUSE-SU"/>
    <description>
    cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2017-9814/">CVE-2017-9814</cve>
	<bugzilla href="https://bugzilla.suse.com/1049092">SUSE bug 1049092</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481783" comment="libcairo2-1.16.0-1.55 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179984" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9984</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9984" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9984" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9984" ref_url="https://www.suse.com/security/cve/CVE-2017-9984" source="SUSE CVE"/>
    <description>
    The snd_msnd_interrupt function in sound/isa/msnd/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between two kernel reads of that value, aka a "double fetch" vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-9984/">CVE-2017-9984</cve>
	<bugzilla href="https://bugzilla.suse.com/1046599">SUSE bug 1046599</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/187396">SUSE bug 187396</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179985" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9985</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9985" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9985" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9985" ref_url="https://www.suse.com/security/cve/CVE-2017-9985" source="SUSE CVE"/>
    <description>
    The snd_msndmidi_input_read function in sound/isa/msnd/msnd_midi.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between two kernel reads of that value, aka a "double fetch" vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-9985/">CVE-2017-9985</cve>
	<bugzilla href="https://bugzilla.suse.com/1046601">SUSE bug 1046601</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20179986" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2017-9986</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2017-9986" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9986" source="CVE"/>
    <reference ref_id="SUSE CVE-2017-9986" ref_url="https://www.suse.com/security/cve/CVE-2017-9986" source="SUSE CVE"/>
    <description>
    The intr function in sound/oss/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between two kernel reads of that value, aka a "double fetch" vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2017-9986/">CVE-2017-9986</cve>
	<bugzilla href="https://bugzilla.suse.com/1046600">SUSE bug 1046600</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20180495" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-0495</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-0495" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0495" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-0495" ref_url="https://www.suse.com/security/cve/CVE-2018-0495" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1993-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004331.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2452-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4236-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005339.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2122-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2178-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4283-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00070.html" source="SUSE-SU"/>
    <description>
    Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-0495/">CVE-2018-0495</cve>
	<bugzilla href="https://bugzilla.suse.com/1097410">SUSE bug 1097410</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121207">SUSE bug 1121207</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482233" comment="libgcrypt20-1.8.2-8.36.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20180500" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-0500</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-0500" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0500" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-0500" ref_url="https://www.suse.com/security/cve/CVE-2018-0500" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2423-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004471.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2431-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00065.html" source="SUSE-SU"/>
    <description>
    Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a nonstandard --limit-rate argument or CURLOPT_BUFFERSIZE value).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-0500/">CVE-2018-0500</cve>
	<bugzilla href="https://bugzilla.suse.com/1099793">SUSE bug 1099793</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20180732" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-0732</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-0732" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0732" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-0732" ref_url="https://www.suse.com/security/cve/CVE-2018-0732" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004245.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1887-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1968-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2036-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2041-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004375.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2449-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2534-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20182534-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004540.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2683-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004549.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2956-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2965-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1553-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005586.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1906-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2117-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2129-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2667-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2816-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2855-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3013-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3015-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00009.html" source="SUSE-SU"/>
    <description>
    During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-0732/">CVE-2018-0732</cve>
	<bugzilla href="https://bugzilla.suse.com/1077628">SUSE bug 1077628</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1097158">SUSE bug 1097158</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1099502">SUSE bug 1099502</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1106692">SUSE bug 1106692</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1108542">SUSE bug 1108542</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1110163">SUSE bug 1110163</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1112097">SUSE bug 1112097</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122198">SUSE bug 1122198</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1148697">SUSE bug 1148697</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20180734" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-0734</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-0734" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0734" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-0734" ref_url="https://www.suse.com/security/cve/CVE-2018-0734" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3863-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3864-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004873.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3864-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3866-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004875.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3945-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183945-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3964-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183964-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3989-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4001-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0395-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1553-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005586.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3890-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3903-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4050-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4104-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0088-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0234-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1547-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1814-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html" source="SUSE-SU"/>
    <description>
    The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-0734/">CVE-2018-0734</cve>
	<bugzilla href="https://bugzilla.suse.com/1113534">SUSE bug 1113534</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113652">SUSE bug 1113652</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113742">SUSE bug 1113742</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122198">SUSE bug 1122198</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122212">SUSE bug 1122212</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1148697">SUSE bug 1148697</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20180735" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-0735</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-0735" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0735" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-0735" ref_url="https://www.suse.com/security/cve/CVE-2018-0735" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3863-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3945-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183945-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3890-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00043.html" source="SUSE-SU"/>
    <description>
    The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-0735/">CVE-2018-0735</cve>
	<bugzilla href="https://bugzilla.suse.com/1113534">SUSE bug 1113534</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113651">SUSE bug 1113651</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20180737" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-0737</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-0737" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0737" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-0737" ref_url="https://www.suse.com/security/cve/CVE-2018-0737" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2683-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004549.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2928-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2928-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004729.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2965-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3864-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004873.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3864-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1553-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005586.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2957-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00087.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3015-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0152-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00009.html" source="SUSE-SU"/>
    <description>
    The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2b-1.0.2o).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-0737/">CVE-2018-0737</cve>
	<bugzilla href="https://bugzilla.suse.com/1089039">SUSE bug 1089039</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1089041">SUSE bug 1089041</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1089044">SUSE bug 1089044</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1089045">SUSE bug 1089045</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1108542">SUSE bug 1108542</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123780">SUSE bug 1123780</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20180739" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-0739</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-0739" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0739" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-0739" ref_url="https://www.suse.com/security/cve/CVE-2018-0739" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0902-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0905-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0906-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0975-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2534-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20182534-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2683-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004549.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006535.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0936-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-04/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1057-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2208-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2238-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2293-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2524-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00080.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00023.html" source="SUSE-SU"/>
    <description>
    Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-0739/">CVE-2018-0739</cve>
	<bugzilla href="https://bugzilla.suse.com/1087102">SUSE bug 1087102</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1089997">SUSE bug 1089997</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1094291">SUSE bug 1094291</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1108542">SUSE bug 1108542</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000001" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000001</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000001" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000001" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000001" ref_url="https://www.suse.com/security/cve/CVE-2018-1000001" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0071-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0075-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0076-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0451-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0565-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004372.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0089-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00039.html" source="SUSE-SU"/>
    <description>
    In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-1000001/">CVE-2018-1000001</cve>
	<bugzilla href="https://bugzilla.suse.com/1074293">SUSE bug 1074293</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1099047">SUSE bug 1099047</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000004" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000004</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000004" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000004" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000004" ref_url="https://www.suse.com/security/cve/CVE-2018-1000004" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0383-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0416-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0437-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0482-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0525-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0555-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0660-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0841-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0986-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0989-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0992-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0993-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0994-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0995-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0996-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0997-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0999-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1000-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1001-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1004-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1006-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1007-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1008-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1009-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003925.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1010-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1012-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1013-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1014-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1015-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1018-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1019-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1020-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1023-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1024-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1025-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1027-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1028-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1029-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1031-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1032-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1033-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1034-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0408-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00013.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel 4.12, 3.10, 2.6 and possibly earlier versions a race condition vulnerability exists in the sound system, this can lead to a deadlock and denial of service condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-1000004/">CVE-2018-1000004</cve>
	<bugzilla href="https://bugzilla.suse.com/1076017">SUSE bug 1076017</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1091815">SUSE bug 1091815</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000005" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000005</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000005" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000005" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000005" ref_url="https://www.suse.com/security/cve/CVE-2018-1000005" source="SUSE CVE"/>
    <description>
    libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers since the stored size was one byte less than required. The problem is that the code that creates HTTP/1-like headers from the HTTP/2 trailer data once appended a string like `:` to the target buffer, while this was recently changed to `: ` (a space was added after the colon) but the following math wasn't updated correspondingly. When accessed, the data is read out of bounds and causes either a crash or that the (too large) data gets passed to client write. This could lead to a denial-of-service situation or an information disclosure if someone has a service that echoes back or uses the trailers for something.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-1000005/">CVE-2018-1000005</cve>
	<bugzilla href="https://bugzilla.suse.com/1076360">SUSE bug 1076360</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000007" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000007</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000007" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000007" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000007" ref_url="https://www.suse.com/security/cve/CVE-2018-1000007" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003634.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0236-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00101.html" source="SUSE-SU"/>
    <description>
    libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the `Location:` response header value. Sending the same set of headers to subsequent hosts is in particular a problem for applications that pass on custom `Authorization:` headers, as this header often contains privacy sensitive information or data that could allow others to impersonate the libcurl-using client's request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-1000007/">CVE-2018-1000007</cve>
	<bugzilla href="https://bugzilla.suse.com/1077001">SUSE bug 1077001</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1145903">SUSE bug 1145903</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1185551">SUSE bug 1185551</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192797">SUSE bug 1192797</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198766">SUSE bug 1198766</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000073" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000073</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000073" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000073" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000073" ref_url="https://www.suse.com/security/cve/CVE-2018-1000073" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in install_location function of package.rb that can result in path traversal when writing to a symlinked basedir outside of the root. This vulnerability appears to have been fixed in 2.7.6.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-1000073/">CVE-2018-1000073</cve>
	<bugzilla href="https://bugzilla.suse.com/1082007">SUSE bug 1082007</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000074" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000074</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000074" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000074" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000074" ref_url="https://www.suse.com/security/cve/CVE-2018-1000074" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack appear to be exploitable via victim must run the `gem owner` command on a gem with a specially crafted YAML file. This vulnerability appears to have been fixed in 2.7.6.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-1000074/">CVE-2018-1000074</cve>
	<bugzilla href="https://bugzilla.suse.com/1082008">SUSE bug 1082008</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1175764">SUSE bug 1175764</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000075" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000075</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000075" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000075" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000075" ref_url="https://www.suse.com/security/cve/CVE-2018-1000075" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a infinite loop caused by negative size vulnerability in ruby gem package tar header that can result in a negative size could cause an infinite loop.. This vulnerability appears to have been fixed in 2.7.6.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-1000075/">CVE-2018-1000075</cve>
	<bugzilla href="https://bugzilla.suse.com/1082014">SUSE bug 1082014</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000076" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000076</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000076" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000076" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000076" ref_url="https://www.suse.com/security/cve/CVE-2018-1000076" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature vulnerability in package.rb that can result in a mis-signed gem could be installed, as the tarball would contain multiple gem signatures.. This vulnerability appears to have been fixed in 2.7.6.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-1000076/">CVE-2018-1000076</cve>
	<bugzilla href="https://bugzilla.suse.com/1082009">SUSE bug 1082009</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000077" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000077</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000077" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000077" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000077" ref_url="https://www.suse.com/security/cve/CVE-2018-1000077" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Input Validation vulnerability in ruby gems specification homepage attribute that can result in a malicious gem could set an invalid homepage URL. This vulnerability appears to have been fixed in 2.7.6.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-1000077/">CVE-2018-1000077</cve>
	<bugzilla href="https://bugzilla.suse.com/1082010">SUSE bug 1082010</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183937">SUSE bug 1183937</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000078" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000078</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000078" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000078" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000078" ref_url="https://www.suse.com/security/cve/CVE-2018-1000078" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability in gem server display of homepage attribute that can result in XSS. This attack appear to be exploitable via the victim must browse to a malicious gem on a vulnerable gem server. This vulnerability appears to have been fixed in 2.7.6.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-1000078/">CVE-2018-1000078</cve>
	<bugzilla href="https://bugzilla.suse.com/1082011">SUSE bug 1082011</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000079" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000079</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000079" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000079" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000079" ref_url="https://www.suse.com/security/cve/CVE-2018-1000079" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-1000079/">CVE-2018-1000079</cve>
	<bugzilla href="https://bugzilla.suse.com/1082058">SUSE bug 1082058</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000120" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000120</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000120" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000120" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000120" ref_url="https://www.suse.com/security/cve/CVE-2018-1000120" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0769-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20180769-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2629-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004533.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0794-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-03/msg00084.html" source="SUSE-SU"/>
    <description>
    A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-1000120/">CVE-2018-1000120</cve>
	<bugzilla href="https://bugzilla.suse.com/1084521">SUSE bug 1084521</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1101811">SUSE bug 1101811</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1112526">SUSE bug 1112526</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000121" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000121</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000121" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000121" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000121" ref_url="https://www.suse.com/security/cve/CVE-2018-1000121" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0769-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20180769-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0794-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-03/msg00084.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-1000121/">CVE-2018-1000121</cve>
	<bugzilla href="https://bugzilla.suse.com/1084524">SUSE bug 1084524</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1085215">SUSE bug 1085215</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1101811">SUSE bug 1101811</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1112526">SUSE bug 1112526</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000122" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000122</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000122" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000122" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000122" ref_url="https://www.suse.com/security/cve/CVE-2018-1000122" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0769-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20180769-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0794-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-03/msg00084.html" source="SUSE-SU"/>
    <description>
    A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-1000122/">CVE-2018-1000122</cve>
	<bugzilla href="https://bugzilla.suse.com/1084532">SUSE bug 1084532</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1101811">SUSE bug 1101811</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1112526">SUSE bug 1112526</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000135" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000135</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000135" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000135" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000135" ref_url="https://www.suse.com/security/cve/CVE-2018-1000135" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1369-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005511.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00005.html" source="SUSE-SU"/>
    <description>
    GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN. This vulnerability appears to have been fixed in Some Ubuntu 16.04 packages were fixed, but later updates removed the fix. cf. https://bugs.launchpad.net/ubuntu/+bug/1754671 an upstream fix does not appear to be available at this time.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-1000135/">CVE-2018-1000135</cve>
	<bugzilla href="https://bugzilla.suse.com/1086263">SUSE bug 1086263</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760817" comment="libnm0-1.22.10-3.3.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760818" comment="typelib-1_0-NM-1_0-1.22.10-3.3.4 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000168" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000168</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000168" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000168" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000168" ref_url="https://www.suse.com/security/cve/CVE-2018-1000168" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004253.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008541.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1963-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00021.html" source="SUSE-SU"/>
    <description>
    nghttp2 version &gt;= 1.10.0 and nghttp2 &lt;= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in &gt;= 1.31.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-1000168/">CVE-2018-1000168</cve>
	<bugzilla href="https://bugzilla.suse.com/1088639">SUSE bug 1088639</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1097401">SUSE bug 1097401</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482322" comment="libnghttp2-14-1.40.0-1.15 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000204" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000204</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000204" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000204" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000204" ref_url="https://www.suse.com/security/cve/CVE-2018-1000204" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1855-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1855-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004334.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004417.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2366-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005456.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. This has been fixed upstream in https://github.com/torvalds/linux/commit/a45b599ad808c3c982fdcdc12b0b8611c2f92824 already. The problem has limited scope, as users don't usually have permissions to access SCSI devices. On the other hand, e.g. the Nero user manual suggests doing `chmod o+r+w /dev/sg*` to make the devices accessible. NOTE: third parties dispute the relevance of this report, noting that the requirement for an attacker to have both the CAP_SYS_ADMIN and CAP_SYS_RAWIO capabilities makes it "virtually impossible to exploit."
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-1000204/">CVE-2018-1000204</cve>
	<bugzilla href="https://bugzilla.suse.com/1096728">SUSE bug 1096728</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105412">SUSE bug 1105412</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000300" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000300</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000300" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000300" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000300" ref_url="https://www.suse.com/security/cve/CVE-2018-1000300" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2018:1624-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00015.html" source="SUSE-SU"/>
    <description>
    curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection with very long server command replies.. This vulnerability appears to have been fixed in curl &lt; 7.54.1 and curl &gt;= 7.60.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-1000300/">CVE-2018-1000300</cve>
	<bugzilla href="https://bugzilla.suse.com/1092094">SUSE bug 1092094</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000301" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000301</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000301" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000301" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000301" ref_url="https://www.suse.com/security/cve/CVE-2018-1000301" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1327-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1327-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004707.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004103.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1344-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1624-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00015.html" source="SUSE-SU"/>
    <description>
    curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl &lt; 7.20.0 and curl &gt;= 7.60.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-1000301/">CVE-2018-1000301</cve>
	<bugzilla href="https://bugzilla.suse.com/1092098">SUSE bug 1092098</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122464">SUSE bug 1122464</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000654" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000654</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000654" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000654" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000654" ref_url="https://www.suse.com/security/cve/CVE-2018-1000654" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1372-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012726.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1498-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00018.html" source="SUSE-SU"/>
    <description>
    GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-1000654/">CVE-2018-1000654</cve>
	<bugzilla href="https://bugzilla.suse.com/1105435">SUSE bug 1105435</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482427" comment="libtasn1-4.13-4.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482428" comment="libtasn1-6-4.13-4.5.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000802" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000802</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000802" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000802" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000802" ref_url="https://www.suse.com/security/cve/CVE-2018-1000802" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3002-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3554-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2053-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006445.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3052-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-1000802/">CVE-2018-1000802</cve>
	<bugzilla href="https://bugzilla.suse.com/1109663">SUSE bug 1109663</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000807" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000807</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000807" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000807" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000807" ref_url="https://www.suse.com/security/cve/CVE-2018-1000807" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:4063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004944.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1104-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00014.html" source="SUSE-SU"/>
    <description>
    Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitable via Depends on the calling application and if it retains a reference to the memory.. This vulnerability appears to have been fixed in 17.5.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-1000807/">CVE-2018-1000807</cve>
	<bugzilla href="https://bugzilla.suse.com/1111634">SUSE bug 1111634</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1111635">SUSE bug 1111635</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009656853" comment="python3-pyOpenSSL is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000808" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000808</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000808" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000808" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000808" ref_url="https://www.suse.com/security/cve/CVE-2018-1000808" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:4063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004944.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1104-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00014.html" source="SUSE-SU"/>
    <description>
    Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denial of service if memory runs low or is exhausted. This attack appear to be exploitable via Depends upon calling application, however it could be as simple as initiating a TLS connection. Anything that would cause the calling application to reload certificates from a PKCS #12 store.. This vulnerability appears to have been fixed in 17.5.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-1000808/">CVE-2018-1000808</cve>
	<bugzilla href="https://bugzilla.suse.com/1111634">SUSE bug 1111634</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1111635">SUSE bug 1111635</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009656853" comment="python3-pyOpenSSL is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181000858" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1000858</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1000858" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000858" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1000858" ref_url="https://www.suse.com/security/cve/CVE-2018-1000858" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0023-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0020-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00009.html" source="SUSE-SU"/>
    <description>
    GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in the composer window of Thunderbird/Enigmail. This vulnerability appears to have been fixed in after commit 4a4bb874f63741026bd26264c43bb32b1099f060.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-1000858/">CVE-2018-1000858</cve>
	<bugzilla href="https://bugzilla.suse.com/1120346">SUSE bug 1120346</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482000" comment="gpg2-2.2.5-4.14.4 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810021" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10021</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10021" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10021" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10021" ref_url="https://www.suse.com/security/cve/CVE-2018-10021" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** drivers/scsi/libsas/sas_scsi_host.c in the Linux kernel before 4.16 allows local users to cause a denial of service (ata qc leak) by triggering certain failure conditions. NOTE: a third party disputes the relevance of this report because the failure can only occur for physically proximate attackers who unplug SAS Host Bus Adapter cables.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-10021/">CVE-2018-10021</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1089281">SUSE bug 1089281</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810322" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10322</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10322" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10322" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10322" ref_url="https://www.suse.com/security/cve/CVE-2018-10322" source="SUSE CVE"/>
    <description>
    The xfs_dinode_verify function in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_ilock_attr_map_shared invalid pointer dereference) via a crafted xfs image.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-10322/">CVE-2018-10322</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1090749">SUSE bug 1090749</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810323" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10323</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10323" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10323" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10323" ref_url="https://www.suse.com/security/cve/CVE-2018-10323" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2018:2119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00036.html" source="SUSE-SU"/>
    <description>
    The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_bmapi_write NULL pointer dereference) via a crafted xfs image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-10323/">CVE-2018-10323</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1090717">SUSE bug 1090717</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810360" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10360</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10360" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10360" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10360" ref_url="https://www.suse.com/security/cve/CVE-2018-10360" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2044-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0571-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190571-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005284.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2694-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0345-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1197-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html" source="SUSE-SU"/>
    <description>
    The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-10360/">CVE-2018-10360</cve>
	<bugzilla href="https://bugzilla.suse.com/1096974">SUSE bug 1096974</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1096984">SUSE bug 1096984</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126118">SUSE bug 1126118</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628435" comment="file-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628437" comment="file-magic-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628438" comment="libmagic1-5.32-7.11.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810392" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10392</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10392" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10392" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10392" ref_url="https://www.suse.com/security/cve/CVE-2018-10392" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1565-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004158.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1885-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004243.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1622-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1953-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00015.html" source="SUSE-SU"/>
    <description>
    mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-10392/">CVE-2018-10392</cve>
	<bugzilla href="https://bugzilla.suse.com/1091070">SUSE bug 1091070</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481533" comment="libvorbis0-1.3.6-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481534" comment="libvorbisenc2-1.3.6-4.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810393" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10393</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10393" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10393" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10393" ref_url="https://www.suse.com/security/cve/CVE-2018-10393" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1345-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00084.html" source="SUSE-SU"/>
    <description>
    bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-10393/">CVE-2018-10393</cve>
	<bugzilla href="https://bugzilla.suse.com/1091072">SUSE bug 1091072</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481533" comment="libvorbis0-1.3.6-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481534" comment="libvorbisenc2-1.3.6-4.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810471" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10471</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10471" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10471" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10471" ref_url="https://www.suse.com/security/cve/CVE-2018-10471" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1177-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1202-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1216-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004740.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00059.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-10471/">CVE-2018-10471</cve>
	<bugzilla href="https://bugzilla.suse.com/1089635">SUSE bug 1089635</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810472" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10472</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10472" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10472" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10472" ref_url="https://www.suse.com/security/cve/CVE-2018-10472" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1177-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1202-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1216-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004740.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00059.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-10472/">CVE-2018-10472</cve>
	<bugzilla href="https://bugzilla.suse.com/1089152">SUSE bug 1089152</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181060" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1060</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1060" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1060" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1060" ref_url="https://www.suse.com/security/cve/CVE-2018-1060" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2696-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3554-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006445.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2712-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-1060/">CVE-2018-1060</cve>
	<bugzilla href="https://bugzilla.suse.com/1088009">SUSE bug 1088009</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181061" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1061</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1061" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1061" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1061" ref_url="https://www.suse.com/security/cve/CVE-2018-1061" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2696-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3554-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2712-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method.  An attacker could use this flaw to cause denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-1061/">CVE-2018-1061</cve>
	<bugzilla href="https://bugzilla.suse.com/1088004">SUSE bug 1088004</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181063" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1063</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1063" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1063" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1063" ref_url="https://www.suse.com/security/cve/CVE-2018-1063" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0926-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003887.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0927-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003888.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0937-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-04/msg00028.html" source="SUSE-SU"/>
    <description>
    Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restrictions. This only happens when the relabeling process is done, usually when taking SELinux state from disabled to enable (permissive or enforcing). The issue was found in policycoreutils 2.5-11.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-1063/">CVE-2018-1063</cve>
	<bugzilla href="https://bugzilla.suse.com/1083624">SUSE bug 1083624</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760844" comment="policycoreutils-3.1-1.25 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760845" comment="policycoreutils-python-utils-3.1-1.25 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760846" comment="python3-policycoreutils-3.1-1.25 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181064" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1064</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1064" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1064" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1064" ref_url="https://www.suse.com/security/cve/CVE-2018-1064" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0838-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0861-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0920-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004357.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0939-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00011.html" source="SUSE-SU"/>
    <description>
    libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-1064/">CVE-2018-1064</cve>
	<bugzilla href="https://bugzilla.suse.com/1076500">SUSE bug 1076500</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1083625">SUSE bug 1083625</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087887">SUSE bug 1087887</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1088147">SUSE bug 1088147</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810675" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10675</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10675" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10675" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10675" ref_url="https://www.suse.com/security/cve/CVE-2018-10675" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1368-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004230.html" source="SUSE-SU"/>
    <description>
    The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-10675/">CVE-2018-10675</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1091755">SUSE bug 1091755</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810839" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10839</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10839" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10839" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10839" ref_url="https://www.suse.com/security/cve/CVE-2018-10839" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004891.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3927-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183973-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3975-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183975-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3987-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4004-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00043.html" source="SUSE-SU"/>
    <description>
    Qemu emulator &lt;= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-10839/">CVE-2018-10839</cve>
	<bugzilla href="https://bugzilla.suse.com/1110910">SUSE bug 1110910</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1110924">SUSE bug 1110924</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810844" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10844</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10844" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10844" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10844" ref_url="https://www.suse.com/security/cve/CVE-2018-10844" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2825-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004620.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2854-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2958-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00000.html" source="SUSE-SU"/>
    <description>
    It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-10844/">CVE-2018-10844</cve>
	<bugzilla href="https://bugzilla.suse.com/1105437">SUSE bug 1105437</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105459">SUSE bug 1105459</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810845" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10845</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10845" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10845" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10845" ref_url="https://www.suse.com/security/cve/CVE-2018-10845" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2825-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004620.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2854-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2958-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00000.html" source="SUSE-SU"/>
    <description>
    It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-10845/">CVE-2018-10845</cve>
	<bugzilla href="https://bugzilla.suse.com/1105437">SUSE bug 1105437</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105459">SUSE bug 1105459</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810846" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10846</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10846" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10846" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10846" ref_url="https://www.suse.com/security/cve/CVE-2018-10846" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2825-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005483.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2854-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2958-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00000.html" source="SUSE-SU"/>
    <description>
    A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-10846/">CVE-2018-10846</cve>
	<bugzilla href="https://bugzilla.suse.com/1105460">SUSE bug 1105460</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810856" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10856</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10856" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10856" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10856" ref_url="https://www.suse.com/security/cve/CVE-2018-10856" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004558.html" source="SUSE-SU"/>
    <description>
    It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-10856/">CVE-2018-10856</cve>
	<bugzilla href="https://bugzilla.suse.com/1097970">SUSE bug 1097970</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629073" comment="podman-2.1.1-4.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629074" comment="podman-cni-config-2.1.1-4.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810873" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10873</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10873" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10873" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10873" ref_url="https://www.suse.com/security/cve/CVE-2018-10873" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2566-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2593-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004526.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2594-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2709-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004559.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008077.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2598-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2601-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2602-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2730-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00029.html" source="SUSE-SU"/>
    <description>
    A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-10873/">CVE-2018-10873</cve>
	<bugzilla href="https://bugzilla.suse.com/1104448">SUSE bug 1104448</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810880" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10880</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10880" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10880" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10880" ref_url="https://www.suse.com/security/cve/CVE-2018-10880" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2908-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004660.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2404-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00064.html" source="SUSE-SU"/>
    <description>
    Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_update_inline_data(). An attacker could use this to cause a system crash and a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-10880/">CVE-2018-10880</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1099845">SUSE bug 1099845</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810882" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10882</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10882" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10882" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10882" ref_url="https://www.suse.com/security/cve/CVE-2018-10882" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2908-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004660.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2404-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00064.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-10882/">CVE-2018-10882</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1099849">SUSE bug 1099849</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810892" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10892</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10892" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10892" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10892" ref_url="https://www.suse.com/security/cve/CVE-2018-10892" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005814.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html" source="SUSE-SU"/>
    <description>
    The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-10892/">CVE-2018-10892</cve>
	<bugzilla href="https://bugzilla.suse.com/1100331">SUSE bug 1100331</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1100838">SUSE bug 1100838</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810893" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10893</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10893" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10893" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10893" ref_url="https://www.suse.com/security/cve/CVE-2018-10893" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2566-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2593-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004526.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2594-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2709-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004559.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008077.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2598-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2601-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2602-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2730-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00029.html" source="SUSE-SU"/>
    <description>
    Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.6/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" href="https://www.suse.com/security/cve/CVE-2018-10893/">CVE-2018-10893</cve>
	<bugzilla href="https://bugzilla.suse.com/1101295">SUSE bug 1101295</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810906" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10906</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10906" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10906" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10906" ref_url="https://www.suse.com/security/cve/CVE-2018-10906" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3260-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005097.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3325-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3326-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00052.html" source="SUSE-SU"/>
    <description>
    In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-10906/">CVE-2018-10906</cve>
	<bugzilla href="https://bugzilla.suse.com/1101797">SUSE bug 1101797</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1127346">SUSE bug 1127346</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1127350">SUSE bug 1127350</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481128" comment="fuse-2.9.7-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481131" comment="libfuse2-2.9.7-3.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810932" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10932</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10932" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10932" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10932" ref_url="https://www.suse.com/security/cve/CVE-2018-10932" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:3520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009652.html" source="SUSE-SU"/>
    <description>
    lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-28"/>
	<updated date="2023-06-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-10932/">CVE-2018-10932</cve>
	<bugzilla href="https://bugzilla.suse.com/1104624">SUSE bug 1104624</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009654591" comment="liblldp_clif1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009654592" comment="open-lldp is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810933" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10933</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10933" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10933" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10933" ref_url="https://www.suse.com/security/cve/CVE-2018-10933" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3162-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004676.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3253-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004747.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3200-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00042.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-10933/">CVE-2018-10933</cve>
	<bugzilla href="https://bugzilla.suse.com/1108020">SUSE bug 1108020</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122198">SUSE bug 1122198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482409" comment="libssh4-0.8.7-10.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181095" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1095</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1095" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1095" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1095" ref_url="https://www.suse.com/security/cve/CVE-2018-1095" source="SUSE CVE"/>
    <description>
    The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-1095/">CVE-2018-1095</cve>
	<bugzilla href="https://bugzilla.suse.com/1087004">SUSE bug 1087004</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810981" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10981</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10981" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10981" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10981" ref_url="https://www.suse.com/security/cve/CVE-2018-10981" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1456-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1487-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00002.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-10981/">CVE-2018-10981</cve>
	<bugzilla href="https://bugzilla.suse.com/1090823">SUSE bug 1090823</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201810982" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-10982</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-10982" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10982" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-10982" ref_url="https://www.suse.com/security/cve/CVE-2018-10982" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1456-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1487-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00002.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun, and hypervisor crash) or possibly gain hypervisor privileges by setting up an HPET timer to deliver interrupts in IO-APIC mode, aka vHPET interrupt injection.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-10982/">CVE-2018-10982</cve>
	<bugzilla href="https://bugzilla.suse.com/1090822">SUSE bug 1090822</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181116" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1116</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1116" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1116" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1116" ref_url="https://www.suse.com/security/cve/CVE-2018-1116" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004366.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2284-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00030.html" source="SUSE-SU"/>
    <description>
    A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-1116/">CVE-2018-1116</cve>
	<bugzilla href="https://bugzilla.suse.com/1099031">SUSE bug 1099031</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482356" comment="libpolkit0-0.116-1.51 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482357" comment="polkit-0.116-1.51 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181122" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1122</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1122" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1122" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1122" ref_url="https://www.suse.com/security/cve/CVE-2018-1122" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2042-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2451-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004889.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0450-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1848-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0291-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2376-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2379-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html" source="SUSE-SU"/>
    <description>
    procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<cve href="https://www.suse.com/security/cve/CVE-2018-1122/">CVE-2018-1122</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1092100">SUSE bug 1092100</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1093158">SUSE bug 1093158</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123135">SUSE bug 1123135</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1128955">SUSE bug 1128955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760821" comment="libprocps7-3.3.15-7.13.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760822" comment="procps-3.3.15-7.13.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181123" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1123</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1123" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1123" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1123" ref_url="https://www.suse.com/security/cve/CVE-2018-1123" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2042-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2451-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004889.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0450-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1848-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0291-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2376-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2379-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html" source="SUSE-SU"/>
    <description>
    procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the impact of this flaw is limited to a crash (temporary denial of service).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<cve href="https://www.suse.com/security/cve/CVE-2018-1123/">CVE-2018-1123</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1092100">SUSE bug 1092100</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1093158">SUSE bug 1093158</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123135">SUSE bug 1123135</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1128955">SUSE bug 1128955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760821" comment="libprocps7-3.3.15-7.13.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760822" comment="procps-3.3.15-7.13.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201811236" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-11236</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-11236" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11236" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-11236" ref_url="https://www.suse.com/security/cve/CVE-2018-11236" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1562-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004156.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1562-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1991-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004403.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1600-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2159-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00000.html" source="SUSE-SU"/>
    <description>
    stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-11236/">CVE-2018-11236</cve>
	<bugzilla href="https://bugzilla.suse.com/1094161">SUSE bug 1094161</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1110160">SUSE bug 1110160</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118435">SUSE bug 1118435</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201811237" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-11237</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-11237" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11237" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-11237" ref_url="https://www.suse.com/security/cve/CVE-2018-11237" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1562-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004156.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1562-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1991-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004285.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1600-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1633-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2159-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00000.html" source="SUSE-SU"/>
    <description>
    An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-11237/">CVE-2018-11237</cve>
	<bugzilla href="https://bugzilla.suse.com/1092877">SUSE bug 1092877</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1094154">SUSE bug 1094154</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118435">SUSE bug 1118435</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181124" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1124</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1124" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1124" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1124" ref_url="https://www.suse.com/security/cve/CVE-2018-1124" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2042-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2451-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004889.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0450-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1848-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0291-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2376-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2379-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html" source="SUSE-SU"/>
    <description>
    procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<cve href="https://www.suse.com/security/cve/CVE-2018-1124/">CVE-2018-1124</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1092100">SUSE bug 1092100</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1093158">SUSE bug 1093158</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123135">SUSE bug 1123135</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1128955">SUSE bug 1128955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760821" comment="libprocps7-3.3.15-7.13.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760822" comment="procps-3.3.15-7.13.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181125" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1125</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1125" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1125" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1125" ref_url="https://www.suse.com/security/cve/CVE-2018-1125" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2042-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2451-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004889.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0450-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1848-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0291-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2376-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2379-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html" source="SUSE-SU"/>
    <description>
    procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<cve href="https://www.suse.com/security/cve/CVE-2018-1125/">CVE-2018-1125</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1092100">SUSE bug 1092100</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1093158">SUSE bug 1093158</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123135">SUSE bug 1123135</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1128955">SUSE bug 1128955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760821" comment="libprocps7-3.3.15-7.13.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760822" comment="procps-3.3.15-7.13.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181126" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1126</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1126" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1126" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1126" ref_url="https://www.suse.com/security/cve/CVE-2018-1126" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2042-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2451-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004889.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0450-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1848-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0291-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2376-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2379-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00059.html" source="SUSE-SU"/>
    <description>
    procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<cve href="https://www.suse.com/security/cve/CVE-2018-1126/">CVE-2018-1126</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1092100">SUSE bug 1092100</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1093158">SUSE bug 1093158</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123135">SUSE bug 1123135</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1128955">SUSE bug 1128955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760821" comment="libprocps7-3.3.15-7.13.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760822" comment="procps-3.3.15-7.13.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201811412" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-11412</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-11412" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11412" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-11412" ref_url="https://www.suse.com/security/cve/CVE-2018-11412" source="SUSE CVE"/>
    <description>
    In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-11412/">CVE-2018-11412</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1094678">SUSE bug 1094678</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20181152" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-1152</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-1152" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1152" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-1152" ref_url="https://www.suse.com/security/cve/CVE-2018-1152" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004223.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0711-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005415.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1118-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1343-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00015.html" source="SUSE-SU"/>
    <description>
    libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-1152/">CVE-2018-1152</cve>
	<bugzilla href="https://bugzilla.suse.com/1098155">SUSE bug 1098155</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628779" comment="libjpeg8-8.1.2-5.15.7 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201811806" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-11806</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-11806" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11806" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-11806" ref_url="https://www.suse.com/security/cve/CVE-2018-11806" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2069-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004315.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2081-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2340-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2565-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004532.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004631.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2973-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004715.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004810.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2211-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2402-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3709-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00013.html" source="SUSE-SU"/>
    <description>
    m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-11806/">CVE-2018-11806</cve>
	<bugzilla href="https://bugzilla.suse.com/1096223">SUSE bug 1096223</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1096224">SUSE bug 1096224</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201811813" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-11813</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-11813" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11813" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-11813" ref_url="https://www.suse.com/security/cve/CVE-2018-11813" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004223.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0711-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005415.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1118-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1343-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00015.html" source="SUSE-SU"/>
    <description>
    libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-11813/">CVE-2018-11813</cve>
	<bugzilla href="https://bugzilla.suse.com/1096209">SUSE bug 1096209</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172994">SUSE bug 1172994</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172995">SUSE bug 1172995</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628779" comment="libjpeg8-8.1.2-5.15.7 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812015" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12015</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12015" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12015" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12015" ref_url="https://www.suse.com/security/cve/CVE-2018-12015" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1972-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004279.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1992-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004286.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2447-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004474.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00023.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2011-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00024.html" source="SUSE-SU"/>
    <description>
    In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-12015/">CVE-2018-12015</cve>
	<bugzilla href="https://bugzilla.suse.com/1096718">SUSE bug 1096718</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1099497">SUSE bug 1099497</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1099507">SUSE bug 1099507</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1106717">SUSE bug 1106717</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760842" comment="perl-5.26.1-7.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760843" comment="perl-base-5.26.1-7.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812020" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12020</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12020" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12020" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12020" ref_url="https://www.suse.com/security/cve/CVE-2018-12020" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1696-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004193.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1698-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1698-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004384.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1706-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1708-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1722-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1724-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00034.html" source="SUSE-SU"/>
    <description>
    mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-12020/">CVE-2018-12020</cve>
	<bugzilla href="https://bugzilla.suse.com/1096745">SUSE bug 1096745</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1101134">SUSE bug 1101134</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482000" comment="gpg2-2.2.5-4.14.4 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812126" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12126</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12126" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12126" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12126" ref_url="https://www.suse.com/security/cve/CVE-2018-12126" source="SUSE CVE"/>
		<reference ref_id="MDS-BLOG-SUSE" ref_url="https://www.suse.com/c/suse-addresses-microarchitectural-data-sampling-vulnerabilities/" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005464.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14052-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1423-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005540.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1909-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="TID000019406" ref_url="https://www.suse.com/support/kb/doc/?id=000019406" source="SUSE-SU"/>
		<reference ref_id="TID000019455" ref_url="https://www.suse.com/support/kb/doc/?id=000019455" source="SUSE-SU"/>
		<reference ref_id="TID7023736" ref_url="https://www.suse.com/support/kb/doc/?id=7023736" source="SUSE-SU"/>
		<reference ref_id="TID7023881" ref_url="https://www.suse.com/support/kb/doc/?id=7023881" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1402-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1403-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1404-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1405-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1408-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1419-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1420-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1505-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1805-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1806-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00052.html" source="SUSE-SU"/>
    <description>
    Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-12126/">CVE-2018-12126</cve>
	<bugzilla href="https://bugzilla.suse.com/1103186">SUSE bug 1103186</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1111331">SUSE bug 1111331</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1132686">SUSE bug 1132686</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135409">SUSE bug 1135409</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135524">SUSE bug 1135524</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1137916">SUSE bug 1137916</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138534">SUSE bug 1138534</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1141977">SUSE bug 1141977</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1149725">SUSE bug 1149725</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1149726">SUSE bug 1149726</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1149729">SUSE bug 1149729</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812127" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12127</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12127" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12127" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12127" ref_url="https://www.suse.com/security/cve/CVE-2018-12127" source="SUSE CVE"/>
		<reference ref_id="MDS-BLOG-SUSE" ref_url="https://www.suse.com/c/suse-addresses-microarchitectural-data-sampling-vulnerabilities/" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005464.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14052-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1423-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005540.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1909-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="TID000019406" ref_url="https://www.suse.com/support/kb/doc/?id=000019406" source="SUSE-SU"/>
		<reference ref_id="TID000019455" ref_url="https://www.suse.com/support/kb/doc/?id=000019455" source="SUSE-SU"/>
		<reference ref_id="TID7023736" ref_url="https://www.suse.com/support/kb/doc/?id=7023736" source="SUSE-SU"/>
		<reference ref_id="TID7023881" ref_url="https://www.suse.com/support/kb/doc/?id=7023881" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1402-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1403-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1404-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1405-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1408-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1419-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1420-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1505-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1805-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1806-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00052.html" source="SUSE-SU"/>
    <description>
    Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-12127/">CVE-2018-12127</cve>
	<bugzilla href="https://bugzilla.suse.com/1103186">SUSE bug 1103186</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1111331">SUSE bug 1111331</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1132686">SUSE bug 1132686</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135409">SUSE bug 1135409</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138534">SUSE bug 1138534</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1141977">SUSE bug 1141977</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812130" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12130</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12130" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12130" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12130" ref_url="https://www.suse.com/security/cve/CVE-2018-12130" source="SUSE CVE"/>
		<reference ref_id="MDS-BLOG-SUSE" ref_url="https://www.suse.com/c/suse-addresses-microarchitectural-data-sampling-vulnerabilities/" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005464.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14052-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1423-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005540.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1909-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="TID000019406" ref_url="https://www.suse.com/support/kb/doc/?id=000019406" source="SUSE-SU"/>
		<reference ref_id="TID000019455" ref_url="https://www.suse.com/support/kb/doc/?id=000019455" source="SUSE-SU"/>
		<reference ref_id="TID7023736" ref_url="https://www.suse.com/support/kb/doc/?id=7023736" source="SUSE-SU"/>
		<reference ref_id="TID7023881" ref_url="https://www.suse.com/support/kb/doc/?id=7023881" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1402-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1403-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1404-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1405-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1408-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1419-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1420-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1505-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1805-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1806-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00052.html" source="SUSE-SU"/>
    <description>
    Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-12130/">CVE-2018-12130</cve>
	<bugzilla href="https://bugzilla.suse.com/1103186">SUSE bug 1103186</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1111331">SUSE bug 1111331</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1132686">SUSE bug 1132686</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135409">SUSE bug 1135409</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1137916">SUSE bug 1137916</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138534">SUSE bug 1138534</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1141977">SUSE bug 1141977</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812207" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12207</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12207" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12207" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12207" ref_url="https://www.suse.com/security/cve/CVE-2018-12207" source="SUSE CVE"/>
		<reference ref_id="SUSE-BLOG-TAA-IFU" ref_url="https://www.suse.com/c/suse-addresses-transactional-asynchronous-abort-and-machine-check-error-on-page-size-changes-issues/" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2946-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192946-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2947-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192947-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2951-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2952-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2953-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192953-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2955-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192955-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2956-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2961-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192961-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006253.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3340-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0334-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007221.html" source="SUSE-SU"/>
		<reference ref_id="TID000019411" ref_url="https://www.suse.com/support/kb/doc/?id=000019411" source="SUSE-SU"/>
		<reference ref_id="TID7023735" ref_url="https://www.suse.com/support/kb/doc/?id=7023735" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2503-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2505-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2506-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2710-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00042.html" source="SUSE-SU"/>
    <description>
    Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-12207/">CVE-2018-12207</cve>
	<bugzilla href="https://bugzilla.suse.com/1117665">SUSE bug 1117665</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1139073">SUSE bug 1139073</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1152505">SUSE bug 1152505</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1155812">SUSE bug 1155812</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1155817">SUSE bug 1155817</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1155945">SUSE bug 1155945</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812232" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12232</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12232" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12232" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12232" ref_url="https://www.suse.com/security/cve/CVE-2018-12232" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0224-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005235.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0065-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00023.html" source="SUSE-SU"/>
    <description>
    In net/socket.c in the Linux kernel through 4.17.1, there is a race condition between fchownat and close in cases where they target the same socket file descriptor, related to the sock_close and sockfs_setattr functions. fchownat does not increment the file descriptor reference count, which allows close to set the socket to NULL during fchownat's execution, leading to a NULL pointer dereference and system crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<cve href="https://www.suse.com/security/cve/CVE-2018-12232/">CVE-2018-12232</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1097593">SUSE bug 1097593</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1125907">SUSE bug 1125907</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1127757">SUSE bug 1127757</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812384" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12384</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12384" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12384" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12384" ref_url="https://www.suse.com/security/cve/CVE-2018-12384" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4236-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005339.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4117-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00030.html" source="SUSE-SU"/>
    <description>
    When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.8/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-12384/">CVE-2018-12384</cve>
	<bugzilla href="https://bugzilla.suse.com/1106873">SUSE bug 1106873</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1119105">SUSE bug 1119105</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121207">SUSE bug 1121207</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812404" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12404</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12404" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12404" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12404" ref_url="https://www.suse.com/security/cve/CVE-2018-12404" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4236-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005091.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4117-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0183-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1758-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00021.html" source="SUSE-SU"/>
    <description>
    A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-12404/">CVE-2018-12404</cve>
	<bugzilla href="https://bugzilla.suse.com/1119069">SUSE bug 1119069</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1119105">SUSE bug 1119105</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121207">SUSE bug 1121207</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812617" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12617</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12617" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12617" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12617" ref_url="https://www.suse.com/security/cve/CVE-2018-12617" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2069-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004315.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2565-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004532.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004631.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2973-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004715.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004810.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3709-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00013.html" source="SUSE-SU"/>
    <description>
    qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. The vulnerability can be exploited by sending a crafted QMP command (including guest-file-read with a large count value) to the agent via the listening socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-12617/">CVE-2018-12617</cve>
	<bugzilla href="https://bugzilla.suse.com/1098735">SUSE bug 1098735</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1098744">SUSE bug 1098744</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812891" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12891</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12891" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12891" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12891" ref_url="https://www.suse.com/security/cve/CVE-2018-12891" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1981-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2069-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004315.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2081-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2116-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2211-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00012.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.10.x. Certain PV MMU operations may take a long time to process. For that reason Xen explicitly checks for the need to preempt the current vCPU at certain points. A few rarely taken code paths did bypass such checks. By suitably enforcing the conditions through its own page table contents, a malicious guest may cause such bypasses to be used for an unbounded number of iterations. A malicious or buggy PV guest may cause a Denial of Service (DoS) affecting the entire host. Specifically, it may prevent use of a physical CPU for an indeterminate period of time. All Xen versions from 3.4 onwards are vulnerable. Xen versions 3.3 and earlier are vulnerable to an even wider class of attacks, due to them lacking preemption checks altogether in the affected code paths. Only x86 systems are affected. ARM systems are not affected. Only multi-vCPU x86 PV guests can leverage the vulnerability. x86 HVM or PVH guests as well as x86 single-vCPU PV ones cannot leverage the vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="2.5/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-12891/">CVE-2018-12891</cve>
	<bugzilla href="https://bugzilla.suse.com/1097521">SUSE bug 1097521</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812892" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12892</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12892" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12892" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12892" ref_url="https://www.suse.com/security/cve/CVE-2018-12892" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1981-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2081-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004736.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2116-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2211-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00012.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious guest administrators or (in some situations) users may be able to write to supposedly read-only disk images. Only emulated SCSI disks (specified as "sd" in the libxl disk configuration, or an equivalent) are affected. IDE disks ("hd") are not affected (because attempts to make them readonly are rejected). Additionally, CDROM devices (that is, devices specified to be presented to the guest as CDROMs, regardless of the nature of the backing storage on the host) are not affected; they are always read only. Only systems using qemu-xen (rather than qemu-xen-traditional) as the device model version are vulnerable. Only systems using libxl or libxl-based toolstacks are vulnerable. (This includes xl, and libvirt with the libxl driver.) The vulnerability is present in Xen versions 4.7 and later. (In earlier versions, provided that the patch for XSA-142 has been applied, attempts to create read only disks are rejected.) If the host and guest together usually support PVHVM, the issue is exploitable only if the malicious guest administrator has control of the guest kernel or guest kernel command line.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-12892/">CVE-2018-12892</cve>
	<bugzilla href="https://bugzilla.suse.com/1097523">SUSE bug 1097523</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812893" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12893</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12893" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12893" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12893" ref_url="https://www.suse.com/security/cve/CVE-2018-12893" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1981-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2069-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004315.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2081-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2116-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2211-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00012.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.10.x. One of the fixes in XSA-260 added some safety checks to help prevent Xen livelocking with debug exceptions. Unfortunately, due to an oversight, at least one of these safety checks can be triggered by a guest. A malicious PV guest can crash Xen, leading to a Denial of Service. All Xen systems which have applied the XSA-260 fix are vulnerable. Only x86 systems are vulnerable. ARM systems are not vulnerable. Only x86 PV guests can exploit the vulnerability. x86 HVM and PVH guests cannot exploit the vulnerability. An attacker needs to be able to control hardware debugging facilities to exploit the vulnerability, but such permissions are typically available to unprivileged users.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-12893/">CVE-2018-12893</cve>
	<bugzilla href="https://bugzilla.suse.com/1097522">SUSE bug 1097522</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812928" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12928</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12928" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12928" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12928" ref_url="https://www.suse.com/security/cve/CVE-2018-12928" source="SUSE CVE"/>
    <description>
    In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur during a mount of a crafted hfs filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-12928/">CVE-2018-12928</cve>
	<bugzilla href="https://bugzilla.suse.com/1099613">SUSE bug 1099613</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201812930" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-12930</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-12930" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12930" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-12930" ref_url="https://www.suse.com/security/cve/CVE-2018-12930" source="SUSE CVE"/>
    <description>
    ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-12930/">CVE-2018-12930</cve>
	<bugzilla href="https://bugzilla.suse.com/1099619">SUSE bug 1099619</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201813053" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-13053</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-13053" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13053" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-13053" ref_url="https://www.suse.com/security/cve/CVE-2018-13053" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004334.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004417.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2344-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2366-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2384-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004537.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2118-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00036.html" source="SUSE-SU"/>
    <description>
    The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow via a large relative timeout because ktime_add_safe is not used.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-13053/">CVE-2018-13053</cve>
	<bugzilla href="https://bugzilla.suse.com/1099924">SUSE bug 1099924</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201813096" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-13096</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-13096" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13096" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-13096" ref_url="https://www.suse.com/security/cve/CVE-2018-13096" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2018:3202-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A denial of service (out-of-bounds memory access and BUG) can occur upon encountering an abnormal bitmap size when mounting a crafted f2fs image.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-13096/">CVE-2018-13096</cve>
	<bugzilla href="https://bugzilla.suse.com/1100062">SUSE bug 1100062</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201813405" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-13405</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-13405" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13405" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-13405" ref_url="https://www.suse.com/security/cve/CVE-2018-13405" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004334.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2344-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2384-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2118-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2119-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-13405/">CVE-2018-13405</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1100416">SUSE bug 1100416</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1129735">SUSE bug 1129735</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195161">SUSE bug 1195161</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198702">SUSE bug 1198702</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201813785" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-13785</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-13785" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13785" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-13785" ref_url="https://www.suse.com/security/cve/CVE-2018-13785" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3868-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3920-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004893.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3921-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004894.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3933-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4064-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4064-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005396.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0049-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0057-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1398-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1398-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005664.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0042-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0043-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1530-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00021.html" source="SUSE-SU"/>
    <description>
    In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-13785/">CVE-2018-13785</cve>
	<bugzilla href="https://bugzilla.suse.com/1100687">SUSE bug 1100687</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1112153">SUSE bug 1112153</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1116574">SUSE bug 1116574</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482352" comment="libpng16-16-1.6.34-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814404" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14404</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14404" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14404" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14404" ref_url="https://www.suse.com/security/cve/CVE-2018-14404" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13985-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005217.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3107-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3110-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0185-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00026.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-14404/">CVE-2018-14404</cve>
	<bugzilla href="https://bugzilla.suse.com/1102046">SUSE bug 1102046</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1148896">SUSE bug 1148896</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814498" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14498</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14498" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14498" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14498" ref_url="https://www.suse.com/security/cve/CVE-2018-14498" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0711-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005415.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14069-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005518.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1118-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1343-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00015.html" source="SUSE-SU"/>
    <description>
    get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-14498/">CVE-2018-14498</cve>
	<bugzilla href="https://bugzilla.suse.com/1128712">SUSE bug 1128712</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628779" comment="libjpeg8-8.1.2-5.15.7 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814526" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14526</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14526" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14526" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14526" ref_url="https://www.suse.com/security/cve/CVE-2018-14526" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004798.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005409.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3527-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00080.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3539-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00083.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1345-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to recover sensitive information.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-14526/">CVE-2018-14526</cve>
	<bugzilla href="https://bugzilla.suse.com/1104205">SUSE bug 1104205</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814550" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14550</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14550" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14550" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14550" ref_url="https://www.suse.com/security/cve/CVE-2018-14550" source="SUSE CVE"/>
    <description>
    An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-15"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-14550/">CVE-2018-14550</cve>
	<bugzilla href="https://bugzilla.suse.com/1102846">SUSE bug 1102846</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336008" comment="libpng16-16 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814567" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14567</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14567" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14567" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14567" ref_url="https://www.suse.com/security/cve/CVE-2018-14567" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004657.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3107-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3110-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00029.html" source="SUSE-SU"/>
    <description>
    libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-14567/">CVE-2018-14567</cve>
	<bugzilla href="https://bugzilla.suse.com/1088279">SUSE bug 1088279</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1088601">SUSE bug 1088601</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105166">SUSE bug 1105166</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814598" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14598</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14598" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14598" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14598" ref_url="https://www.suse.com/security/cve/CVE-2018-14598" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2934-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004626.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004665.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2567-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3012-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00006.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS (segmentation fault).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-14598/">CVE-2018-14598</cve>
	<bugzilla href="https://bugzilla.suse.com/1102073">SUSE bug 1102073</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760801" comment="libX11-6-1.6.5-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760802" comment="libX11-data-1.6.5-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760803" comment="libX11-xcb1-1.6.5-3.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814599" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14599</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14599" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14599" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14599" ref_url="https://www.suse.com/security/cve/CVE-2018-14599" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2934-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004626.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004665.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2567-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3012-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00006.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-14599/">CVE-2018-14599</cve>
	<bugzilla href="https://bugzilla.suse.com/1102062">SUSE bug 1102062</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760801" comment="libX11-6-1.6.5-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760802" comment="libX11-data-1.6.5-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760803" comment="libX11-xcb1-1.6.5-3.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814600" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14600</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14600" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14600" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14600" ref_url="https://www.suse.com/security/cve/CVE-2018-14600" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2934-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004626.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004665.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2567-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3012-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00006.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or remote code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-14600/">CVE-2018-14600</cve>
	<bugzilla href="https://bugzilla.suse.com/1102068">SUSE bug 1102068</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178417">SUSE bug 1178417</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760801" comment="libX11-6-1.6.5-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760802" comment="libX11-data-1.6.5-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760803" comment="libX11-xcb1-1.6.5-3.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814618" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14618</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14618" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14618" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14618" ref_url="https://www.suse.com/security/cve/CVE-2018-14618" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2629-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004560.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004561.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004563.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2731-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2736-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00033.html" source="SUSE-SU"/>
    <description>
    curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate output into the allocated storage buffer. On systems with a 32 bit size_t, the math to calculate SUM triggers an integer overflow when the password length exceeds 2GB (2^31 bytes). This integer overflow usually causes a very small buffer to actually get allocated instead of the intended very huge one, making the use of that buffer end up in a heap buffer overflow. (This bug is almost identical to CVE-2017-8816.)
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-14618/">CVE-2018-14618</cve>
	<bugzilla href="https://bugzilla.suse.com/1106019">SUSE bug 1106019</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1112758">SUSE bug 1112758</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122464">SUSE bug 1122464</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814619" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14619</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14619" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14619" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14619" ref_url="https://www.suse.com/security/cve/CVE-2018-14619" source="SUSE CVE"/>
    <description>
    A flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was being dropped when each af_alg_ctx was freed instead of when the aead_tfm was freed. This can cause the null skcipher to be freed while it is still in use leading to a local user being able to crash the system or possibly escalate privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-14619/">CVE-2018-14619</cve>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1106174">SUSE bug 1106174</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814647" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14647</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14647" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14647" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14647" ref_url="https://www.suse.com/security/cve/CVE-2018-14647" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006375.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004672.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0482-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2053-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007449.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0292-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-14647/">CVE-2018-14647</cve>
	<bugzilla href="https://bugzilla.suse.com/1109847">SUSE bug 1109847</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814679" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14679</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14679" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14679" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14679" ref_url="https://www.suse.com/security/cve/CVE-2018-14679" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004412.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2323-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004722.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009806.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009322.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009804.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2406-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1200-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CB3MRNYWFKRQUSWOFW43J2YAPXGFTDWP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2802-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2ZGPJK567IBN35AOF3QFMOJCRA2NANSF/" source="SUSE-SU"/>
    <description>
    An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-14679/">CVE-2018-14679</cve>
	<bugzilla href="https://bugzilla.suse.com/1102922">SUSE bug 1102922</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1103032">SUSE bug 1103032</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1103040">SUSE bug 1103040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704936" comment="libmspack0-0.6-3.11.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814681" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14681</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14681" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14681" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14681" ref_url="https://www.suse.com/security/cve/CVE-2018-14681" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3250-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3436-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005398.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009302.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009322.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3315-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3505-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1200-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CB3MRNYWFKRQUSWOFW43J2YAPXGFTDWP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2802-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2ZGPJK567IBN35AOF3QFMOJCRA2NANSF/" source="SUSE-SU"/>
    <description>
    An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-14681/">CVE-2018-14681</cve>
	<bugzilla href="https://bugzilla.suse.com/1102922">SUSE bug 1102922</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1103032">SUSE bug 1103032</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1103040">SUSE bug 1103040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704936" comment="libmspack0-0.6-3.11.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814682" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14682</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14682" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14682" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14682" ref_url="https://www.suse.com/security/cve/CVE-2018-14682" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3250-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3436-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005398.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009302.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009322.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3315-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3505-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1200-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CB3MRNYWFKRQUSWOFW43J2YAPXGFTDWP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2802-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2ZGPJK567IBN35AOF3QFMOJCRA2NANSF/" source="SUSE-SU"/>
    <description>
    An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-14682/">CVE-2018-14682</cve>
	<bugzilla href="https://bugzilla.suse.com/1102922">SUSE bug 1102922</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1103032">SUSE bug 1103032</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1103040">SUSE bug 1103040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704936" comment="libmspack0-0.6-3.11.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201814722" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-14722</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-14722" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14722" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-14722" ref_url="https://www.suse.com/security/cve/CVE-2018-14722" source="SUSE CVE"/>
    <description>
    An issue was discovered in evaluate_auto_mountpoint in btrfsmaintenance-functions in btrfsmaintenance through 0.4.1. Code execution as root can occur via a specially crafted filesystem label if btrfs-{scrub,balance,trim} are set to auto in /etc/sysconfig/btrfsmaintenance (this is not the default, though).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-14722/">CVE-2018-14722</cve>
	<bugzilla href="https://bugzilla.suse.com/1102721">SUSE bug 1102721</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481038" comment="btrfsmaintenance-0.4.2-1.11 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815120" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15120</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15120" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15120" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15120" ref_url="https://www.suse.com/security/cve/CVE-2018-15120" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004568.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2790-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00043.html" source="SUSE-SU"/>
    <description>
    libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15120/">CVE-2018-15120</cve>
	<bugzilla href="https://bugzilla.suse.com/1103877">SUSE bug 1103877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482345" comment="libpango-1_0-0-1.44.7+11-1.25 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815468" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15468</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15468" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15468" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15468" ref_url="https://www.suse.com/security/cve/CVE-2018-15468" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004769.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00073.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do not. In particular, Branch Trace Store is not virtualised by the processor, and software has to be careful to configure it suitably not to lock up the core. As a result, it must only be available to fully trusted guests. Unfortunately, in the case that vPMU is disabled, all value checking was skipped, allowing the guest to choose any MSR_DEBUGCTL setting it likes. A malicious or buggy guest administrator (on Intel x86 HVM or PVH) can lock up the entire host, causing a Denial of Service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-15468/">CVE-2018-15468</cve>
	<bugzilla href="https://bugzilla.suse.com/1103276">SUSE bug 1103276</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815469" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15469</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15469" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15469" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15469" ref_url="https://www.suse.com/security/cve/CVE-2018-15469" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00073.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an ARM guest can still request v2 grant tables; they will simply not be properly set up, resulting in subsequent grant-related hypercalls hitting BUG() checks. An unprivileged guest can cause a BUG() check in the hypervisor, resulting in a denial-of-service (crash).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-15469/">CVE-2018-15469</cve>
	<bugzilla href="https://bugzilla.suse.com/1103275">SUSE bug 1103275</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815470" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15470</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15470" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15470" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15470" ref_url="https://www.suse.com/security/cve/CVE-2018-15470" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00073.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handling writes depended on the order of evaluation of expressions making up a tuple. As indicated in section 7.7.3 "Operations on data structures" of the OCaml manual, the order of evaluation of subexpressions is not specified. In practice, different implementations behave differently. Thus, oxenstored may not enforce the configured quota-maxentity. This allows a malicious or buggy guest to write as many xenstore entries as it wishes, causing unbounded memory usage in oxenstored. This can lead to a system-wide DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-15470/">CVE-2018-15470</cve>
	<bugzilla href="https://bugzilla.suse.com/1103279">SUSE bug 1103279</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815664" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15664</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15664" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15664" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15664" ref_url="https://www.suse.com/security/cve/CVE-2018-15664" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1562-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005844.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1621-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00001.html" source="SUSE-SU"/>
    <description>
    In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.1/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-15664/">CVE-2018-15664</cve>
	<bugzilla href="https://bugzilla.suse.com/1096726">SUSE bug 1096726</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1139649">SUSE bug 1139649</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628652" comment="libcontainers-common-20200727-3.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815686" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15686</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15686" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15686" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15686" ref_url="https://www.suse.com/security/cve/CVE-2018-15686" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3644-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3767-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0054-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0054-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005328.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3803-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00025.html" source="SUSE-SU"/>
    <description>
    A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.6/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-15686/">CVE-2018-15686</cve>
	<bugzilla href="https://bugzilla.suse.com/1113665">SUSE bug 1113665</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1120323">SUSE bug 1120323</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815687" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15687</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15687" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15687" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15687" ref_url="https://www.suse.com/security/cve/CVE-2018-15687" source="SUSE CVE"/>
    <description>
    A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-15687/">CVE-2018-15687</cve>
	<bugzilla href="https://bugzilla.suse.com/1113666">SUSE bug 1113666</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815688" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15688</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15688" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15688" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15688" ref_url="https://www.suse.com/security/cve/CVE-2018-15688" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3644-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3767-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004941.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3695-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3803-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00025.html" source="SUSE-SU"/>
    <description>
    A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-15688/">CVE-2018-15688</cve>
	<bugzilla href="https://bugzilla.suse.com/1113632">SUSE bug 1113632</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113668">SUSE bug 1113668</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113669">SUSE bug 1113669</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760817" comment="libnm0-1.22.10-3.3.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760818" comment="typelib-1_0-NM-1_0-1.22.10-3.3.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815746" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15746</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15746" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15746" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15746" ref_url="https://www.suse.com/security/cve/CVE-2018-15746" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004891.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3927-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183973-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3975-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183975-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3987-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4004-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00043.html" source="SUSE-SU"/>
    <description>
    qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy for threads other than the main thread.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-15746/">CVE-2018-15746</cve>
	<bugzilla href="https://bugzilla.suse.com/1106222">SUSE bug 1106222</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815750" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15750</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15750" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15750" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15750" ref_url="https://www.suse.com/security/cve/CVE-2018-15750" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3815-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004868.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3862-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0881-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0882-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1974-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007156.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4197-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0899-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6E3YAO2VV3WBUS7PMAT26ZYDS3AXW5VL/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2106-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MU6P3NIODW6ZMC4HZLBROO6ZEOD5KAUX/" source="SUSE-SU"/>
    <description>
    Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.7/CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-15750/">CVE-2018-15750</cve>
	<bugzilla href="https://bugzilla.suse.com/1113698">SUSE bug 1113698</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009494057" comment="python3-distro-1.5.0-3.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504114" comment="python3-salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504115" comment="salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504120" comment="salt-minion-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504125" comment="salt-transactional-update-3002.2-37.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815751" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15751</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15751" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15751" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15751" ref_url="https://www.suse.com/security/cve/CVE-2018-15751" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3815-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004868.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3862-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0881-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0882-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1974-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007156.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4197-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0899-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6E3YAO2VV3WBUS7PMAT26ZYDS3AXW5VL/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2106-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MU6P3NIODW6ZMC4HZLBROO6ZEOD5KAUX/" source="SUSE-SU"/>
    <description>
    SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-15751/">CVE-2018-15751</cve>
	<bugzilla href="https://bugzilla.suse.com/1113698">SUSE bug 1113698</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113699">SUSE bug 1113699</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009494057" comment="python3-distro-1.5.0-3.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504114" comment="python3-salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504115" comment="salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504120" comment="salt-minion-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504125" comment="salt-transactional-update-3002.2-37.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815853" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15853</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15853" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15853" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15853" ref_url="https://www.suse.com/security/cve/CVE-2018-15853" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004841.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00024.html" source="SUSE-SU"/>
    <description>
    Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15853/">CVE-2018-15853</cve>
	<bugzilla href="https://bugzilla.suse.com/1105832">SUSE bug 1105832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481580" comment="libxkbcommon0-0.8.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815854" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15854</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15854" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15854" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15854" ref_url="https://www.suse.com/security/cve/CVE-2018-15854" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004841.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00024.html" source="SUSE-SU"/>
    <description>
    Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because geometry tokens were desupported incorrectly.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15854/">CVE-2018-15854</cve>
	<bugzilla href="https://bugzilla.suse.com/1105832">SUSE bug 1105832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481580" comment="libxkbcommon0-0.8.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815855" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15855</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15855" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15855" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15855" ref_url="https://www.suse.com/security/cve/CVE-2018-15855" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004841.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00024.html" source="SUSE-SU"/>
    <description>
    Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because the XkbFile for an xkb_geometry section was mishandled.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15855/">CVE-2018-15855</cve>
	<bugzilla href="https://bugzilla.suse.com/1105832">SUSE bug 1105832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481580" comment="libxkbcommon0-0.8.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815856" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15856</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15856" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15856" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15856" ref_url="https://www.suse.com/security/cve/CVE-2018-15856" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004841.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00024.html" source="SUSE-SU"/>
    <description>
    An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbcommon before 0.8.1 could be used by local attackers to cause a denial of service during parsing of crafted keymap files.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15856/">CVE-2018-15856</cve>
	<bugzilla href="https://bugzilla.suse.com/1105832">SUSE bug 1105832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481580" comment="libxkbcommon0-0.8.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815857" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15857</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15857" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15857" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15857" ref_url="https://www.suse.com/security/cve/CVE-2018-15857" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004841.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00024.html" source="SUSE-SU"/>
    <description>
    An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local attackers to crash xkbcommon keymap parsers or possibly have unspecified other impact by supplying a crafted keymap file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15857/">CVE-2018-15857</cve>
	<bugzilla href="https://bugzilla.suse.com/1105832">SUSE bug 1105832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481580" comment="libxkbcommon0-0.8.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815858" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15858</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15858" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15858" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15858" ref_url="https://www.suse.com/security/cve/CVE-2018-15858" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004841.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00024.html" source="SUSE-SU"/>
    <description>
    Unchecked NULL pointer usage when handling invalid aliases in CopyKeyAliasesToKeymap in xkbcomp/keycodes.c in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15858/">CVE-2018-15858</cve>
	<bugzilla href="https://bugzilla.suse.com/1105832">SUSE bug 1105832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481580" comment="libxkbcommon0-0.8.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815859" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15859</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15859" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15859" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15859" ref_url="https://www.suse.com/security/cve/CVE-2018-15859" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004841.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00024.html" source="SUSE-SU"/>
    <description>
    Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because lookup failures are mishandled.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15859/">CVE-2018-15859</cve>
	<bugzilla href="https://bugzilla.suse.com/1105832">SUSE bug 1105832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481580" comment="libxkbcommon0-0.8.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815861" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15861</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15861" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15861" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15861" ref_url="https://www.suse.com/security/cve/CVE-2018-15861" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004841.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00024.html" source="SUSE-SU"/>
    <description>
    Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file that triggers an xkb_intern_atom failure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15861/">CVE-2018-15861</cve>
	<bugzilla href="https://bugzilla.suse.com/1105832">SUSE bug 1105832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481580" comment="libxkbcommon0-0.8.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815862" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15862</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15862" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15862" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15862" ref_url="https://www.suse.com/security/cve/CVE-2018-15862" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004841.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00024.html" source="SUSE-SU"/>
    <description>
    Unchecked NULL pointer usage in LookupModMask in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file with invalid virtual modifiers.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15862/">CVE-2018-15862</cve>
	<bugzilla href="https://bugzilla.suse.com/1105832">SUSE bug 1105832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481580" comment="libxkbcommon0-0.8.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815863" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15863</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15863" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15863" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15863" ref_url="https://www.suse.com/security/cve/CVE-2018-15863" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004841.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00024.html" source="SUSE-SU"/>
    <description>
    Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file with a no-op modmask expression.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15863/">CVE-2018-15863</cve>
	<bugzilla href="https://bugzilla.suse.com/1105832">SUSE bug 1105832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481580" comment="libxkbcommon0-0.8.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201815864" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-15864</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-15864" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15864" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-15864" ref_url="https://www.suse.com/security/cve/CVE-2018-15864" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004841.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00024.html" source="SUSE-SU"/>
    <description>
    Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because a map access attempt can occur for a map that was never created.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-15864/">CVE-2018-15864</cve>
	<bugzilla href="https://bugzilla.suse.com/1105832">SUSE bug 1105832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481580" comment="libxkbcommon0-0.8.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816062" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16062</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16062" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16062" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16062" ref_url="https://www.suse.com/security/cve/CVE-2018-16062" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-16062/">CVE-2018-16062</cve>
	<bugzilla href="https://bugzilla.suse.com/1106390">SUSE bug 1106390</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816276" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16276</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16276" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16276" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16276" ref_url="https://www.suse.com/security/cve/CVE-2018-16276" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2908-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3003-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183003-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3004-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004661.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3618-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3202-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-16276/">CVE-2018-16276</cve>
	<bugzilla href="https://bugzilla.suse.com/1106095">SUSE bug 1106095</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115593">SUSE bug 1115593</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816395" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16395</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16395" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16395" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16395" ref_url="https://www.suse.com/security/cve/CVE-2018-16395" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:15034-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012115.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When two OpenSSL::X509::Name objects are compared using ==, depending on the ordering, non-equal objects may return true. When the first argument is one character longer than the second, or the second argument contains a character that is one less than a character in the same position of the first argument, the result of == will be true. This could be leveraged to create an illegitimate certificate that may be accepted as legitimate and then used in signing or encryption operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-16395/">CVE-2018-16395</cve>
	<bugzilla href="https://bugzilla.suse.com/1112530">SUSE bug 1112530</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136906">SUSE bug 1136906</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816396" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16396</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16396" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16396" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16396" ref_url="https://www.suse.com/security/cve/CVE-2018-16396" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.8/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-16396/">CVE-2018-16396</cve>
	<bugzilla href="https://bugzilla.suse.com/1112532">SUSE bug 1112532</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136906">SUSE bug 1136906</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816402" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16402</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16402" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16402" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16402" ref_url="https://www.suse.com/security/cve/CVE-2018-16402" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-16402/">CVE-2018-16402</cve>
	<bugzilla href="https://bugzilla.suse.com/1107066">SUSE bug 1107066</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816403" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16403</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16403" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16403" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16403" ref_url="https://www.suse.com/security/cve/CVE-2018-16403" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.c, leading to a heap-based buffer over-read and an application crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-16403/">CVE-2018-16403</cve>
	<bugzilla href="https://bugzilla.suse.com/1107067">SUSE bug 1107067</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816428" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16428</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16428" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16428" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16428" ref_url="https://www.suse.com/security/cve/CVE-2018-16428" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1722-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005644.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00005.html" source="SUSE-SU"/>
    <description>
    In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-16428/">CVE-2018-16428</cve>
	<bugzilla href="https://bugzilla.suse.com/1107121">SUSE bug 1107121</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760781" comment="glib2-tools-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760782" comment="libgio-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760783" comment="libglib-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760784" comment="libgmodule-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760785" comment="libgobject-2_0-0-2.62.6-3.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816429" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16429</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16429" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16429" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16429" ref_url="https://www.suse.com/security/cve/CVE-2018-16429" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3966-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183966-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1722-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005644.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4005-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00005.html" source="SUSE-SU"/>
    <description>
    GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-16429/">CVE-2018-16429</cve>
	<bugzilla href="https://bugzilla.suse.com/1107116">SUSE bug 1107116</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760781" comment="glib2-tools-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760782" comment="libgio-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760783" comment="libglib-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760784" comment="libgmodule-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760785" comment="libgobject-2_0-0-2.62.6-3.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816597" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16597</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16597" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16597" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16597" ref_url="https://www.suse.com/security/cve/CVE-2018-16597" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3003-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183003-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3004-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3202-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by local attackers to modify or truncate files in the underlying filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-16597/">CVE-2018-16597</cve>
	<bugzilla href="https://bugzilla.suse.com/1106512">SUSE bug 1106512</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816839" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16839</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16839" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16839" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16839" ref_url="https://www.suse.com/security/cve/CVE-2018-16839" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0996-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3706-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00012.html" source="SUSE-SU"/>
    <description>
    Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-16839/">CVE-2018-16839</cve>
	<bugzilla href="https://bugzilla.suse.com/1112758">SUSE bug 1112758</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113029">SUSE bug 1113029</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131886">SUSE bug 1131886</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816840" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16840</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16840" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16840" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16840" ref_url="https://www.suse.com/security/cve/CVE-2018-16840" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3681-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004839.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005111.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3706-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00012.html" source="SUSE-SU"/>
    <description>
    A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` function, the library code first frees a struct (without nulling the pointer) and might then subsequently erroneously write to a struct field within that already freed struct.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-16840/">CVE-2018-16840</cve>
	<bugzilla href="https://bugzilla.suse.com/1112758">SUSE bug 1112758</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113029">SUSE bug 1113029</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122464">SUSE bug 1122464</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816842" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16842</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16842" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16842" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16842" ref_url="https://www.suse.com/security/cve/CVE-2018-16842" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3681-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004839.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005111.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3699-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3706-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00012.html" source="SUSE-SU"/>
    <description>
    Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-16842/">CVE-2018-16842</cve>
	<bugzilla href="https://bugzilla.suse.com/1113660">SUSE bug 1113660</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122464">SUSE bug 1122464</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816846" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16846</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16846" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16846" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16846" ref_url="https://www.suse.com/security/cve/CVE-2018-16846" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0586-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005185.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0306-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1284-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.html" source="SUSE-SU"/>
    <description>
    It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-16846/">CVE-2018-16846</cve>
	<bugzilla href="https://bugzilla.suse.com/1114710">SUSE bug 1114710</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009335684" comment="librados2 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335686" comment="librbd1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816847" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16847</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16847" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16847" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16847" ref_url="https://www.suse.com/security/cve/CVE-2018-16847" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3927-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004979.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4004-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4135-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00036.html" source="SUSE-SU"/>
    <description>
    An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cmb_ops routines in nvme device. A guest user/process could use this flaw to crash the QEMU process resulting in DoS or potentially run arbitrary code with privileges of the QEMU process.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-16847/">CVE-2018-16847</cve>
	<bugzilla href="https://bugzilla.suse.com/1114529">SUSE bug 1114529</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1114540">SUSE bug 1114540</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816864" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16864</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16864" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16864" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16864" ref_url="https://www.suse.com/security/cve/CVE-2018-16864" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0054-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0054-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005328.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0135-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005054.html" source="SUSE-SU"/>
		<reference ref_id="SYSTEM-DOWN-BLOG" ref_url="https://www.suse.com/c/stack-clashing-systemd-aka-system-down/" source="SUSE-SU"/>
		<reference ref_id="TID000019368" ref_url="https://www.suse.com/support/kb/doc/?id=000019368" source="SUSE-SU"/>
		<reference ref_id="TID7023611" ref_url="https://www.suse.com/support/kb/doc/?id=7023611" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0097-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0098-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00043.html" source="SUSE-SU"/>
    <description>
    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-16864/">CVE-2018-16864</cve>
	<bugzilla href="https://bugzilla.suse.com/1108912">SUSE bug 1108912</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1120323">SUSE bug 1120323</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122265">SUSE bug 1122265</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188063">SUSE bug 1188063</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816865" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16865</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16865" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16865" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16865" ref_url="https://www.suse.com/security/cve/CVE-2018-16865" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0054-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0054-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005328.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0135-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005054.html" source="SUSE-SU"/>
		<reference ref_id="SYSTEM-DOWN-BLOG" ref_url="https://www.suse.com/c/stack-clashing-systemd-aka-system-down/" source="SUSE-SU"/>
		<reference ref_id="TID000019368" ref_url="https://www.suse.com/support/kb/doc/?id=000019368" source="SUSE-SU"/>
		<reference ref_id="TID7023611" ref_url="https://www.suse.com/support/kb/doc/?id=7023611" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0097-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0098-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00043.html" source="SUSE-SU"/>
    <description>
    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-16865/">CVE-2018-16865</cve>
	<bugzilla href="https://bugzilla.suse.com/1108912">SUSE bug 1108912</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1120323">SUSE bug 1120323</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122265">SUSE bug 1122265</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188063">SUSE bug 1188063</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816868" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16868</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16868" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16868" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16868" ref_url="https://www.suse.com/security/cve/CVE-2018-16868" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1351-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005638.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1353-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1477-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00068.html" source="SUSE-SU"/>
    <description>
    A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-16868/">CVE-2018-16868</cve>
	<bugzilla href="https://bugzilla.suse.com/1117951">SUSE bug 1117951</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118087">SUSE bug 1118087</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1134856">SUSE bug 1134856</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816869" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16869</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16869" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16869" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16869" ref_url="https://www.suse.com/security/cve/CVE-2018-16869" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004985.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4260-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00065.html" source="SUSE-SU"/>
    <description>
    A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS connections to a vulnerable server.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-16869/">CVE-2018-16869</cve>
	<bugzilla href="https://bugzilla.suse.com/1117951">SUSE bug 1117951</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118086">SUSE bug 1118086</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118087">SUSE bug 1118087</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1134856">SUSE bug 1134856</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482241" comment="libhogweed4-3.4.1-4.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482244" comment="libnettle6-3.4.1-4.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816872" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16872</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16872" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16872" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16872" ref_url="https://www.suse.com/security/cve/CVE-2018-16872" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0423-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0471-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0471-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005184.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0254-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00042.html" source="SUSE-SU"/>
    <description>
    A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories in usb_mtp_object_readdir doesn't consider that the underlying filesystem may have changed since the time lstat(2) was called in usb_mtp_object_alloc, a classical TOCTTOU problem. An attacker with write access to the host filesystem shared with a guest can use this property to navigate the host filesystem in the context of the QEMU process and read any file the QEMU process has access to. Access to the filesystem may be local or via a network share protocol such as CIFS.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-16872/">CVE-2018-16872</cve>
	<bugzilla href="https://bugzilla.suse.com/1119493">SUSE bug 1119493</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1119494">SUSE bug 1119494</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816873" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16873</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16873" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16873" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16873" ref_url="https://www.suse.com/security/cve/CVE-2018-16873" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1007-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0048-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0286-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0330-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1234-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005468.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008717.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4255-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4306-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0170-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0189-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0208-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0295-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1079-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1444-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1499-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1506-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0554-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.html" source="SUSE-SU"/>
    <description>
    In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at https://golang.org/cmd/go/#hdr-Module_aware_go_get). Using custom domains, it's possible to arrange things so that a Git repository is cloned to a folder named ".git" by using a vanity import path that ends with "/.git". If the Git repository root contains a "HEAD" file, a "config" file, an "objects" directory, a "refs" directory, with some work to ensure the proper ordering of operations, "go get -u" can be tricked into considering the parent directory as a repository root, and running Git commands on it. That will use the "config" file in the original Git repository root for its configuration, and if that config file contains malicious commands, they will execute on the system running "go get -u".
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-16873/">CVE-2018-16873</cve>
	<bugzilla href="https://bugzilla.suse.com/1118897">SUSE bug 1118897</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118898">SUSE bug 1118898</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118899">SUSE bug 1118899</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629067" comment="containerd-1.3.9-5.29.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629071" comment="docker-libnetwork-0.7.0.1+gitr2908_55e924b8a842-4.31.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629072" comment="docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-6.45.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482602" comment="runc-1.0.0~rc10-1.9.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816874" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16874</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16874" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16874" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16874" ref_url="https://www.suse.com/security/cve/CVE-2018-16874" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1007-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0048-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0286-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1234-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005468.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008717.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4255-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4306-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0170-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0189-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0208-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0295-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1079-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1444-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1499-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1506-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0554-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.html" source="SUSE-SU"/>
    <description>
    In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at https://golang.org/cmd/go/#hdr-Module_aware_go_get). The attacker can cause an arbitrary filesystem write, which can lead to code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-16874/">CVE-2018-16874</cve>
	<bugzilla href="https://bugzilla.suse.com/1118897">SUSE bug 1118897</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118898">SUSE bug 1118898</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118899">SUSE bug 1118899</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629067" comment="containerd-1.3.9-5.29.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629071" comment="docker-libnetwork-0.7.0.1+gitr2908_55e924b8a842-4.31.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629072" comment="docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-6.45.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482602" comment="runc-1.0.0~rc10-1.9.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816875" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16875</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16875" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16875" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16875" ref_url="https://www.suse.com/security/cve/CVE-2018-16875" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1007-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0048-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0286-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1234-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005468.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008717.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4255-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4306-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00076.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0170-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0189-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0208-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0295-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1079-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1444-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1499-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1506-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1703-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00010.html" source="SUSE-SU"/>
    <description>
    The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-16875/">CVE-2018-16875</cve>
	<bugzilla href="https://bugzilla.suse.com/1118897">SUSE bug 1118897</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118898">SUSE bug 1118898</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118899">SUSE bug 1118899</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629067" comment="containerd-1.3.9-5.29.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629071" comment="docker-libnetwork-0.7.0.1+gitr2908_55e924b8a842-4.31.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629072" comment="docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-6.45.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482602" comment="runc-1.0.0~rc10-1.9.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009659879" comment="cni-plugins is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816885" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16885</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16885" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16885" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16885" ref_url="https://www.suse.com/security/cve/CVE-2018-16885" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault and a system halt by accessing invalid memory address. This issue only affects kernel version 3.10.x as shipped with Red Hat Enterprise Linux 7.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-16885/">CVE-2018-16885</cve>
	<bugzilla href="https://bugzilla.suse.com/1120258">SUSE bug 1120258</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816889" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16889</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16889" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16889" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16889" ref_url="https://www.suse.com/security/cve/CVE-2018-16889" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005774.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005910.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0306-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00016.html" source="SUSE-SU"/>
    <description>
    Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-16889/">CVE-2018-16889</cve>
	<bugzilla href="https://bugzilla.suse.com/1121567">SUSE bug 1121567</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009335684" comment="librados2 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335686" comment="librbd1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201816890" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-16890</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-16890" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16890" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-16890" ref_url="https://www.suse.com/security/cve/CVE-2018-16890" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0249-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005111.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0173-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00023.html" source="SUSE-SU"/>
    <description>
    libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer read out-of-bounds.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-16890/">CVE-2018-16890</cve>
	<bugzilla href="https://bugzilla.suse.com/1123371">SUSE bug 1123371</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123378">SUSE bug 1123378</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1141798">SUSE bug 1141798</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201817953" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-17953</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-17953" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17953" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-17953" ref_url="https://www.suse.com/security/cve/CVE-2018-17953" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3965-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183965-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4043-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00015.html" source="SUSE-SU"/>
    <description>
    A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-17953/">CVE-2018-17953</cve>
	<bugzilla href="https://bugzilla.suse.com/1115640">SUSE bug 1115640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197654">SUSE bug 1197654</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628960" comment="pam-1.3.0-6.29.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201817958" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-17958</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-17958" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17958" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-17958" ref_url="https://www.suse.com/security/cve/CVE-2018-17958" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004891.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3927-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183973-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3975-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183975-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3987-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4004-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00043.html" source="SUSE-SU"/>
    <description>
    Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-17958/">CVE-2018-17958</cve>
	<bugzilla href="https://bugzilla.suse.com/1111006">SUSE bug 1111006</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1111007">SUSE bug 1111007</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201817962" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-17962</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-17962" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17962" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-17962" ref_url="https://www.suse.com/security/cve/CVE-2018-17962" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004891.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3927-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183973-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3975-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183975-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3987-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4004-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00043.html" source="SUSE-SU"/>
    <description>
    Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-17962/">CVE-2018-17962</cve>
	<bugzilla href="https://bugzilla.suse.com/1111010">SUSE bug 1111010</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1111011">SUSE bug 1111011</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201817963" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-17963</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-17963" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17963" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-17963" ref_url="https://www.suse.com/security/cve/CVE-2018-17963" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004769.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004891.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3927-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183973-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3975-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183975-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3987-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4004-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00043.html" source="SUSE-SU"/>
    <description>
    qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-17963/">CVE-2018-17963</cve>
	<bugzilla href="https://bugzilla.suse.com/1111013">SUSE bug 1111013</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1111014">SUSE bug 1111014</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818064" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18064</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18064" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18064" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18064" ref_url="https://www.suse.com/security/cve/CVE-2018-18064" source="SUSE CVE"/>
    <description>
    cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.6/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-18064/">CVE-2018-18064</cve>
	<bugzilla href="https://bugzilla.suse.com/1111329">SUSE bug 1111329</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009339036" comment="libcairo2 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818074" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18074</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18074" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18074" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18074" ref_url="https://www.suse.com/security/cve/CVE-2018-18074" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1487-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005761.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005773.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006561.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1792-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011137.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1754-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-18074/">CVE-2018-18074</cve>
	<bugzilla href="https://bugzilla.suse.com/1111622">SUSE bug 1111622</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482524" comment="python3-requests-2.20.1-6.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818310" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18310</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18310" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18310" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18310" ref_url="https://www.suse.com/security/cve/CVE-2018-18310" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by consider_notes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-18310/">CVE-2018-18310</cve>
	<bugzilla href="https://bugzilla.suse.com/1111973">SUSE bug 1111973</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818311" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18311</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18311" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18311" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18311" ref_url="https://www.suse.com/security/cve/CVE-2018-18311" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2264-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192264-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4258-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00063.html" source="SUSE-SU"/>
    <description>
    Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-18311/">CVE-2018-18311</cve>
	<bugzilla href="https://bugzilla.suse.com/1114674">SUSE bug 1114674</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1132018">SUSE bug 1132018</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760842" comment="perl-5.26.1-7.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760843" comment="perl-base-5.26.1-7.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818312" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18312</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18312" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18312" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18312" ref_url="https://www.suse.com/security/cve/CVE-2018-18312" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004980.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4258-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00063.html" source="SUSE-SU"/>
    <description>
    Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-18312/">CVE-2018-18312</cve>
	<bugzilla href="https://bugzilla.suse.com/1114675">SUSE bug 1114675</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760842" comment="perl-5.26.1-7.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760843" comment="perl-base-5.26.1-7.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818313" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18313</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18313" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18313" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18313" ref_url="https://www.suse.com/security/cve/CVE-2018-18313" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004980.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4258-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00063.html" source="SUSE-SU"/>
    <description>
    Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-18313/">CVE-2018-18313</cve>
	<bugzilla href="https://bugzilla.suse.com/1114681">SUSE bug 1114681</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760842" comment="perl-5.26.1-7.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760843" comment="perl-base-5.26.1-7.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818314" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18314</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18314" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18314" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18314" ref_url="https://www.suse.com/security/cve/CVE-2018-18314" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004980.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4258-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00063.html" source="SUSE-SU"/>
    <description>
    Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.5/CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-18314/">CVE-2018-18314</cve>
	<bugzilla href="https://bugzilla.suse.com/1114686">SUSE bug 1114686</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760842" comment="perl-5.26.1-7.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760843" comment="perl-base-5.26.1-7.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818438" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18438</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18438" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18438" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18438" ref_url="https://www.suse.com/security/cve/CVE-2018-18438" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3975-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183975-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3987-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
    <description>
    Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-18438/">CVE-2018-18438</cve>
	<bugzilla href="https://bugzilla.suse.com/1112185">SUSE bug 1112185</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1112188">SUSE bug 1112188</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818508" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18508</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18508" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18508" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18508" ref_url="https://www.suse.com/security/cve/CVE-2018-18508" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3395-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006294.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00006.html" source="SUSE-SU"/>
    <description>
    In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-18508/">CVE-2018-18508</cve>
	<bugzilla href="https://bugzilla.suse.com/1124571">SUSE bug 1124571</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818520" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18520</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18520" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18520" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18520" ref_url="https://www.suse.com/security/cve/CVE-2018-18520" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entries. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-18520/">CVE-2018-18520</cve>
	<bugzilla href="https://bugzilla.suse.com/1112726">SUSE bug 1112726</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818521" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18521</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18521" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18521" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18521" ref_url="https://www.suse.com/security/cve/CVE-2018-18521" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-18521/">CVE-2018-18521</cve>
	<bugzilla href="https://bugzilla.suse.com/1112723">SUSE bug 1112723</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818584" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18584</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18584" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18584" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18584" ref_url="https://www.suse.com/security/cve/CVE-2018-18584" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005239.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13992-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2711-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007450.html" source="SUSE-SU"/>
    <description>
    In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-18584/">CVE-2018-18584</cve>
	<bugzilla href="https://bugzilla.suse.com/1113038">SUSE bug 1113038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113039">SUSE bug 1113039</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482310" comment="libmspack0-0.6-3.8.19 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818585" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18585</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18585" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18585" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18585" ref_url="https://www.suse.com/security/cve/CVE-2018-18585" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005239.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13992-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2711-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007450.html" source="SUSE-SU"/>
    <description>
    chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-18585/">CVE-2018-18585</cve>
	<bugzilla href="https://bugzilla.suse.com/1113038">SUSE bug 1113038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113039">SUSE bug 1113039</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482310" comment="libmspack0-0.6-3.8.19 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818586" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18586</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18586" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18586" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18586" ref_url="https://www.suse.com/security/cve/CVE-2018-18586" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0069-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0069-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013155.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0069-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IRYD4Y2CDUYSBVQUIDXTTBL6H6XYW54G/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0069-2" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OUTOW52AMZBWLZJOXYYD2UOLF2KPJEKX/" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against absolute/relative pathnames in CHM files, leading to Directory Traversal. NOTE: the vendor disputes that this is a libmspack vulnerability, because chmextract.c was only intended as a source-code example, not a supported application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-18586/">CVE-2018-18586</cve>
	<bugzilla href="https://bugzilla.suse.com/1113038">SUSE bug 1113038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113039">SUSE bug 1113039</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113040">SUSE bug 1113040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667510" comment="libmspack0-0.6-3.14.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818751" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18751</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18751" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18751" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18751" ref_url="https://www.suse.com/security/cve/CVE-2018-18751" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4060-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009904.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1270-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1278-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00065.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1385-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00025.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-18751/">CVE-2018-18751</cve>
	<bugzilla href="https://bugzilla.suse.com/1113719">SUSE bug 1113719</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760780" comment="gettext-runtime-0.19.8.1-4.11.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818849" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18849</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18849" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18849" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18849" ref_url="https://www.suse.com/security/cve/CVE-2018-18849" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004891.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3927-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183973-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3973-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3975-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183975-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3987-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4070-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0020-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4004-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00043.html" source="SUSE-SU"/>
    <description>
    In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-18849/">CVE-2018-18849</cve>
	<bugzilla href="https://bugzilla.suse.com/1114422">SUSE bug 1114422</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1114423">SUSE bug 1114423</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201818883" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-18883</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-18883" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18883" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-18883" ref_url="https://www.suse.com/security/cve/CVE-2018-18883" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:4070-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00073.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a host OS denial of service (NULL pointer dereference) or possibly have unspecified other impact because nested VT-x is not properly restricted.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.8/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-18883/">CVE-2018-18883</cve>
	<bugzilla href="https://bugzilla.suse.com/1114405">SUSE bug 1114405</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819211" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19211</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19211" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19211" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19211" ref_url="https://www.suse.com/security/cve/CVE-2018-19211" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3967-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183967-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4000-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004929.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4034-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4055-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00022.html" source="SUSE-SU"/>
    <description>
    In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-19211/">CVE-2018-19211</cve>
	<bugzilla href="https://bugzilla.suse.com/1115929">SUSE bug 1115929</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131830">SUSE bug 1131830</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482311" comment="libncurses6-6.1-5.6.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482314" comment="ncurses-utils-6.1-5.6.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482316" comment="terminfo-6.1-5.6.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482317" comment="terminfo-base-6.1-5.6.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819489" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19489</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19489" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19489" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19489" ref_url="https://www.suse.com/security/cve/CVE-2018-19489" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0423-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0457-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0471-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0471-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005126.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0254-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00042.html" source="SUSE-SU"/>
    <description>
    v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.8/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-19489/">CVE-2018-19489</cve>
	<bugzilla href="https://bugzilla.suse.com/1117275">SUSE bug 1117275</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1117279">SUSE bug 1117279</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819637" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19637</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19637" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19637" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19637" ref_url="https://www.suse.com/security/cve/CVE-2018-19637" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005417.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0293-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1351-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html" source="SUSE-SU"/>
    <description>
    Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-19637/">CVE-2018-19637</cve>
	<bugzilla href="https://bugzilla.suse.com/1063385">SUSE bug 1063385</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1117776">SUSE bug 1117776</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482553" comment="supportutils-3.1.9-5.24.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819638" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19638</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19638" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19638" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19638" ref_url="https://www.suse.com/security/cve/CVE-2018-19638" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005417.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13976-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005187.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0293-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1351-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html" source="SUSE-SU"/>
    <description>
    In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-19638/">CVE-2018-19638</cve>
	<bugzilla href="https://bugzilla.suse.com/1063385">SUSE bug 1063385</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118460">SUSE bug 1118460</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118462">SUSE bug 1118462</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118463">SUSE bug 1118463</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482553" comment="supportutils-3.1.9-5.24.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819639" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19639</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19639" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19639" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19639" ref_url="https://www.suse.com/security/cve/CVE-2018-19639" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005417.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13976-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005187.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0293-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1351-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html" source="SUSE-SU"/>
    <description>
    If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-19639/">CVE-2018-19639</cve>
	<bugzilla href="https://bugzilla.suse.com/1063385">SUSE bug 1063385</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118460">SUSE bug 1118460</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118462">SUSE bug 1118462</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482553" comment="supportutils-3.1.9-5.24.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819640" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19640</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19640" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19640" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19640" ref_url="https://www.suse.com/security/cve/CVE-2018-19640" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005417.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13976-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005187.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0293-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1351-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00018.html" source="SUSE-SU"/>
    <description>
    If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-19640/">CVE-2018-19640</cve>
	<bugzilla href="https://bugzilla.suse.com/1063385">SUSE bug 1063385</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118463">SUSE bug 1118463</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482553" comment="supportutils-3.1.9-5.24.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819788" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19788</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19788" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19788" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19788" ref_url="https://www.suse.com/security/cve/CVE-2018-19788" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0019-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0019-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005371.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4282-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00004.html" source="SUSE-SU"/>
    <description>
    A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-19788/">CVE-2018-19788</cve>
	<bugzilla href="https://bugzilla.suse.com/1118274">SUSE bug 1118274</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1118277">SUSE bug 1118277</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1119056">SUSE bug 1119056</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482356" comment="libpolkit0-0.116-1.51 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482357" comment="polkit-0.116-1.51 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819961" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19961</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19961" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19961" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19961" ref_url="https://www.suse.com/security/cve/CVE-2018-19961" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:4070-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0020-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-19961/">CVE-2018-19961</cve>
	<bugzilla href="https://bugzilla.suse.com/1115040">SUSE bug 1115040</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819962" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19962</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19962" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19962" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19962" ref_url="https://www.suse.com/security/cve/CVE-2018-19962" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:4070-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0020-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-19962/">CVE-2018-19962</cve>
	<bugzilla href="https://bugzilla.suse.com/1115040">SUSE bug 1115040</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819963" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19963</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19963" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19963" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19963" ref_url="https://www.suse.com/security/cve/CVE-2018-19963" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005011.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because x86 IOREQ server resource accounting (for external emulators) was mishandled.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-19963/">CVE-2018-19963</cve>
	<bugzilla href="https://bugzilla.suse.com/1115043">SUSE bug 1115043</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819964" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19964</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19964" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19964" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19964" ref_url="https://www.suse.com/security/cve/CVE-2018-19964" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005011.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen 4.11.x allowing x86 guest OS users to cause a denial of service (host OS hang) because the p2m lock remains unavailable indefinitely in certain error conditions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-19964/">CVE-2018-19964</cve>
	<bugzilla href="https://bugzilla.suse.com/1115044">SUSE bug 1115044</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819965" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19965</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19965" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19965" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19965" ref_url="https://www.suse.com/security/cve/CVE-2018-19965" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:4070-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0020-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-19965/">CVE-2018-19965</cve>
	<bugzilla href="https://bugzilla.suse.com/1115045">SUSE bug 1115045</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819966" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19966</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19966" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19966" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19966" ref_url="https://www.suse.com/security/cve/CVE-2018-19966" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:4070-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/004952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0020-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4111-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00028.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-19966/">CVE-2018-19966</cve>
	<bugzilla href="https://bugzilla.suse.com/1115047">SUSE bug 1115047</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201819967" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-19967</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-19967" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19967" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-19967" ref_url="https://www.suse.com/security/cve/CVE-2018-19967" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0921-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005320.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13921-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913921-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1199-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen does not work around Intel's mishandling of certain HLE transactions associated with the KACQUIRE instruction prefix.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-19967/">CVE-2018-19967</cve>
	<bugzilla href="https://bugzilla.suse.com/1114988">SUSE bug 1114988</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820123" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20123</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20123" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20123" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20123" ref_url="https://www.suse.com/security/cve/CVE-2018-20123" source="SUSE CVE"/>
    <description>
    pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-20123/">CVE-2018-20123</cve>
	<bugzilla href="https://bugzilla.suse.com/1119437">SUSE bug 1119437</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1119438">SUSE bug 1119438</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820124" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20124</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20124" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20124" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20124" ref_url="https://www.suse.com/security/cve/CVE-2018-20124" source="SUSE CVE"/>
    <description>
    hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-20124/">CVE-2018-20124</cve>
	<bugzilla href="https://bugzilla.suse.com/1119840">SUSE bug 1119840</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1119841">SUSE bug 1119841</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820125" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20125</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20125" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20125" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20125" ref_url="https://www.suse.com/security/cve/CVE-2018-20125" source="SUSE CVE"/>
    <description>
    hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-20125/">CVE-2018-20125</cve>
	<bugzilla href="https://bugzilla.suse.com/1119989">SUSE bug 1119989</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820126" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20126</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20126" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20126" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20126" ref_url="https://www.suse.com/security/cve/CVE-2018-20126" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2955-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192955-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2956-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006129.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2505-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.html" source="SUSE-SU"/>
    <description>
    hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-20126/">CVE-2018-20126</cve>
	<bugzilla href="https://bugzilla.suse.com/1119991">SUSE bug 1119991</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820191" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20191</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20191" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20191" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20191" ref_url="https://www.suse.com/security/cve/CVE-2018-20191" source="SUSE CVE"/>
    <description>
    hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-20191/">CVE-2018-20191</cve>
	<bugzilla href="https://bugzilla.suse.com/1119979">SUSE bug 1119979</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1119980">SUSE bug 1119980</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820216" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20216</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20216" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20216" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20216" ref_url="https://www.suse.com/security/cve/CVE-2018-20216" source="SUSE CVE"/>
    <description>
    QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-20216/">CVE-2018-20216</cve>
	<bugzilla href="https://bugzilla.suse.com/1119984">SUSE bug 1119984</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1119985">SUSE bug 1119985</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820217" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20217</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20217" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20217" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20217" ref_url="https://www.suse.com/security/cve/CVE-2018-20217" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0113-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005342.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0063-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0085-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00033.html" source="SUSE-SU"/>
    <description>
    A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DES, triple-DES, or RC4), the attacker can crash the KDC by making an S4U2Self request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-20217/">CVE-2018-20217</cve>
	<bugzilla href="https://bugzilla.suse.com/1120489">SUSE bug 1120489</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820346" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20346</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20346" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20346" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20346" ref_url="https://www.suse.com/security/cve/CVE-2018-20346" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0788-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190788-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1159-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1222-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00070.html" source="SUSE-SU"/>
    <description>
    SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-20346/">CVE-2018-20346</cve>
	<bugzilla href="https://bugzilla.suse.com/1119687">SUSE bug 1119687</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1120335">SUSE bug 1120335</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131576">SUSE bug 1131576</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131918">SUSE bug 1131918</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131919">SUSE bug 1131919</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1148893">SUSE bug 1148893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1169664">SUSE bug 1169664</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482404" comment="libsqlite3-0-3.28.0-3.9.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820406" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20406</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20406" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20406" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20406" ref_url="https://www.suse.com/security/cve/CVE-2018-20406" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005085.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0243-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0155-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to twice the size" attempt. This issue might cause memory exhaustion, but is only relevant if the pickle format is used for serializing tens or hundreds of gigabytes of data. This issue is fixed in: v3.4.10, v3.4.10rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.7rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.7, v3.6.7rc1, v3.6.7rc2, v3.6.8, v3.6.8rc1, v3.6.9, v3.6.9rc1; v3.7.1, v3.7.1rc1, v3.7.1rc2, v3.7.2, v3.7.2rc1, v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-20406/">CVE-2018-20406</cve>
	<bugzilla href="https://bugzilla.suse.com/1120644">SUSE bug 1120644</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820482" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20482</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20482" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20482" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20482" ref_url="https://www.suse.com/security/cve/CVE-2018-20482" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1101-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:917-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:919-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:680-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:683-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:689-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0926-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005322.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007506.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010950.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1237-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00077.html" source="SUSE-SU"/>
    <description>
    GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-20482/">CVE-2018-20482</cve>
	<bugzilla href="https://bugzilla.suse.com/1120610">SUSE bug 1120610</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705032" comment="tar-1.34-150000.3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820511" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20511</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20511" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20511" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20511" ref_url="https://www.suse.com/security/cve/CVE-2018-20511" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next fields via an SIOCFINDIPDDPRT ioctl call.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-20511/">CVE-2018-20511</cve>
	<bugzilla href="https://bugzilla.suse.com/1120388">SUSE bug 1120388</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820532" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20532</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20532" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20532" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20532" ref_url="https://www.suse.com/security/cve/CVE-2018-20532" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005763.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2265-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192265-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2660-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007438.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1927-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00057.html" source="SUSE-SU"/>
    <description>
    There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-20532/">CVE-2018-20532</cve>
	<bugzilla href="https://bugzilla.suse.com/1120629">SUSE bug 1120629</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760827" comment="libsolv-tools-0.7.16-3.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820533" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20533</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20533" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20533" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20533" ref_url="https://www.suse.com/security/cve/CVE-2018-20533" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005763.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2265-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192265-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2660-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007438.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1927-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00057.html" source="SUSE-SU"/>
    <description>
    There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-20533/">CVE-2018-20533</cve>
	<bugzilla href="https://bugzilla.suse.com/1120630">SUSE bug 1120630</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760827" comment="libsolv-tools-0.7.16-3.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820534" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20534</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20534" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20534" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20534" ref_url="https://www.suse.com/security/cve/CVE-2018-20534" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005763.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2265-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192265-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2660-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007438.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1927-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00057.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-20534/">CVE-2018-20534</cve>
	<bugzilla href="https://bugzilla.suse.com/1120631">SUSE bug 1120631</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760827" comment="libsolv-tools-0.7.16-3.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820573" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20573</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20573" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20573" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20573" ref_url="https://www.suse.com/security/cve/CVE-2018-20573" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:481-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:483-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010626.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010628.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:488-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010629.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010631.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:500-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010643.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010644.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:515-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:525-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010658.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010617.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1073-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1740-3" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014346.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1073-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/U5JRSH3JEFDRI2LLKIUVXRRMZJAO5ZPH/" source="SUSE-SU"/>
    <description>
    The Scanner::EnsureTokensInQueue function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-20573/">CVE-2018-20573</cve>
	<bugzilla href="https://bugzilla.suse.com/1121227">SUSE bug 1121227</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705024" comment="libyaml-cpp0_6-0.6.1-4.5.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820574" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20574</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20574" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20574" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20574" ref_url="https://www.suse.com/security/cve/CVE-2018-20574" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:481-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:483-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010626.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010628.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:488-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010629.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010631.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:500-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010643.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010644.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:515-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:525-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010658.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010617.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1073-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1740-3" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014346.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1073-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/U5JRSH3JEFDRI2LLKIUVXRRMZJAO5ZPH/" source="SUSE-SU"/>
    <description>
    The SingleDocParser::HandleFlowMap function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-20574/">CVE-2018-20574</cve>
	<bugzilla href="https://bugzilla.suse.com/1121230">SUSE bug 1121230</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705024" comment="libyaml-cpp0_6-0.6.1-4.5.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820669" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20669</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20669" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20669" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20669" ref_url="https://www.suse.com/security/cve/CVE-2018-20669" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005240.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005245.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0784-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190784-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0785-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190785-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2193-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4YRSQJNKLIOJJTD3P2UKMHRFMCIG3JDN/" source="SUSE-SU"/>
    <description>
    An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to overwrite arbitrary kernel memory, resulting in a Denial of Service or privilege escalation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-20669/">CVE-2018-20669</cve>
	<bugzilla href="https://bugzilla.suse.com/1122971">SUSE bug 1122971</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820685" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20685</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20685" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20685" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20685" ref_url="https://www.suse.com/security/cve/CVE-2018-20685" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0125-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005404.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005049.html" source="SUSE-SU"/>
		<reference ref_id="TID000019375" ref_url="https://www.suse.com/support/kb/doc/?id=000019375" source="SUSE-SU"/>
		<reference ref_id="TID7023647" ref_url="https://www.suse.com/support/kb/doc/?id=7023647" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0091-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00041.html" source="SUSE-SU"/>
    <description>
    In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-20685/">CVE-2018-20685</cve>
	<bugzilla href="https://bugzilla.suse.com/1121571">SUSE bug 1121571</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123220">SUSE bug 1123220</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131109">SUSE bug 1131109</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1134932">SUSE bug 1134932</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820699" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20699</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20699" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20699" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20699" ref_url="https://www.suse.com/security/cve/CVE-2018-20699" source="SUSE CVE"/>
    <description>
    Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-20699/">CVE-2018-20699</cve>
	<bugzilla href="https://bugzilla.suse.com/1121768">SUSE bug 1121768</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820784" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20784</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20784" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20784" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20784" ref_url="https://www.suse.com/security/cve/CVE-2018-20784" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:2077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015468.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3324-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031024.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by inducing a high load.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-08-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-20784/">CVE-2018-20784</cve>
	<bugzilla href="https://bugzilla.suse.com/1126703">SUSE bug 1126703</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820796" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20796</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20796" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20796" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20796" ref_url="https://www.suse.com/security/cve/CVE-2018-20796" source="SUSE CVE"/>
    <description>
    In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-20796/">CVE-2018-20796</cve>
	<bugzilla href="https://bugzilla.suse.com/1127311">SUSE bug 1127311</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182116">SUSE bug 1182116</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333938" comment="glibc is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334828" comment="glibc-locale is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009339499" comment="glibc-locale-base is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820815" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20815</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20815" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20815" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20815" ref_url="https://www.suse.com/security/cve/CVE-2018-20815" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14052-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1405-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1419-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00045.html" source="SUSE-SU"/>
    <description>
    In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow risk.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-09-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-20815/">CVE-2018-20815</cve>
	<bugzilla href="https://bugzilla.suse.com/1118900">SUSE bug 1118900</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1130675">SUSE bug 1130675</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1130680">SUSE bug 1130680</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138043">SUSE bug 1138043</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820843" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20843</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20843" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20843" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20843" ref_url="https://www.suse.com/security/cve/CVE-2018-20843" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:616-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005700.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1777-1" ref_url="https://lists.opensuse.org/opensuse-updates/2019-07/msg00104.html" source="SUSE-SU"/>
    <description>
    In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-20843/">CVE-2018-20843</cve>
	<bugzilla href="https://bugzilla.suse.com/1139937">SUSE bug 1139937</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481944" comment="libexpat1-2.2.5-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820852" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20852</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20852" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20852" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20852" ref_url="https://www.suse.com/security/cve/CVE-2018-20852" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005803.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005811.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006064.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007449.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1988-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1989-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g., pythonicexample.com to steal cookies for example.com). When a program uses http.cookiejar.DefaultPolicy and tries to do an HTTP connection to an attacker-controlled server, existing cookies can be leaked to the attacker. This affects 2.x through 2.7.16, 3.x before 3.4.10, 3.5.x before 3.5.7, 3.6.x before 3.6.9, and 3.7.x before 3.7.3.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-20852/">CVE-2018-20852</cve>
	<bugzilla href="https://bugzilla.suse.com/1141853">SUSE bug 1141853</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201820854" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-20854</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-20854" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20854" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-20854" ref_url="https://www.suse.com/security/cve/CVE-2018-20854" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 4.20. drivers/phy/mscc/phy-ocelot-serdes.c has an off-by-one error with a resultant ctrl-&gt;phys out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-20854/">CVE-2018-20854</cve>
	<bugzilla href="https://bugzilla.suse.com/1143038">SUSE bug 1143038</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201821029" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-21029</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-21029" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-21029" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-21029" ref_url="https://www.suse.com/security/cve/CVE-2018-21029" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-21029/">CVE-2018-21029</cve>
	<bugzilla href="https://bugzilla.suse.com/1155539">SUSE bug 1155539</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201825015" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-25015</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-25015" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25015" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-25015" ref_url="https://www.suse.com/security/cve/CVE-2018-25015" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-25015/">CVE-2018-25015</cve>
	<bugzilla href="https://bugzilla.suse.com/1187046">SUSE bug 1187046</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201825032" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-25032</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-25032" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25032" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-25032" ref_url="https://www.suse.com/security/cve/CVE-2018-25032" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1052-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-May/023165.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1228-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1229-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011214.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:447-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:449-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010595.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:453-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010596.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:457-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:459-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:464-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:465-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010609.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:467-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:470-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:472-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:500-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010643.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010644.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:525-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010658.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010662.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:590-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010696.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:592-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:720-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010881.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010882.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010887.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010888.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010893.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010894.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:871-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010942.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:872-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010943.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:873-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:874-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010958.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:917-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:919-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1023-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1043-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1061-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010707.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010586.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3225-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012197.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:10126-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3URMJJJ2MKM4FNDYFMSSIEJDTNENDZRU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1061-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q3IAWI5KYTN2PXEFZY7OU7STBINLC3H6/" source="SUSE-SU"/>
    <description>
    zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-25032/">CVE-2018-25032</cve>
	<bugzilla href="https://bugzilla.suse.com/1197459">SUSE bug 1197459</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197893">SUSE bug 1197893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198667">SUSE bug 1198667</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199104">SUSE bug 1199104</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200049">SUSE bug 1200049</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201732">SUSE bug 1201732</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1202688">SUSE bug 1202688</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009676998" comment="libz1-1.2.11-150000.3.30.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20183639" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-3639</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-3639" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3639" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-3639" ref_url="https://www.suse.com/security/cve/CVE-2018-3639" source="SUSE CVE"/>
		<reference ref_id="BLOG-SPECTREV4" ref_url="https://www.suse.com/c/suse-addresses-spectre-variant-4/" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1362-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1363-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1366-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1368-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1377-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1377-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1378-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1456-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1475-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004165.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1699-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1926-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1935-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004322.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004334.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004357.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2304-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004404.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004416.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2331-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004716.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2335-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004419.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2340-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2565-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004532.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004631.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2973-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004715.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3064-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3064-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3064-3" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0049-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1211-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2028-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005762.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007375.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007405.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3007-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3324-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3333-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015911.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3349-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031064.html" source="SUSE-SU"/>
		<reference ref_id="TID000019189" ref_url="https://www.suse.com/support/kb/doc/?id=000019189" source="SUSE-SU"/>
		<reference ref_id="TID000019439" ref_url="https://www.suse.com/support/kb/doc/?id=000019439" source="SUSE-SU"/>
		<reference ref_id="TID7022512" ref_url="https://www.suse.com/support/kb/doc/?id=7022512" source="SUSE-SU"/>
		<reference ref_id="TID7022937" ref_url="https://www.suse.com/support/kb/doc/?id=7022937" source="SUSE-SU"/>
		<reference ref_id="TID7023836" ref_url="https://www.suse.com/support/kb/doc/?id=7023836" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1380-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00090.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1418-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00099.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1420-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00101.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1487-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1621-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1623-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1628-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1773-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1904-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2306-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2399-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2402-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3103-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3709-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0042-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1438-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1439-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1325-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.html" source="SUSE-SU"/>
    <description>
    Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-09-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-3639/">CVE-2018-3639</cve>
	<bugzilla href="https://bugzilla.suse.com/1074701">SUSE bug 1074701</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1085235">SUSE bug 1085235</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1085308">SUSE bug 1085308</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087078">SUSE bug 1087078</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1092631">SUSE bug 1092631</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1092885">SUSE bug 1092885</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1094912">SUSE bug 1094912</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1098813">SUSE bug 1098813</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1100394">SUSE bug 1100394</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1102640">SUSE bug 1102640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105412">SUSE bug 1105412</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1111963">SUSE bug 1111963</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172781">SUSE bug 1172781</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172782">SUSE bug 1172782</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172783">SUSE bug 1172783</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173489">SUSE bug 1173489</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1215674">SUSE bug 1215674</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20183640" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-3640</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-3640" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3640" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-3640" ref_url="https://www.suse.com/security/cve/CVE-2018-3640" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1926-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1935-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004322.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004416.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2331-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004716.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2335-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004419.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004422.html" source="SUSE-SU"/>
		<reference ref_id="TID000019198" ref_url="https://www.suse.com/support/kb/doc/?id=000019198" source="SUSE-SU"/>
		<reference ref_id="TID7022512" ref_url="https://www.suse.com/support/kb/doc/?id=7022512" source="SUSE-SU"/>
		<reference ref_id="TID7022950" ref_url="https://www.suse.com/support/kb/doc/?id=7022950" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1904-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2399-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00058.html" source="SUSE-SU"/>
    <description>
    Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-3640/">CVE-2018-3640</cve>
	<bugzilla href="https://bugzilla.suse.com/1074701">SUSE bug 1074701</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087078">SUSE bug 1087078</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087083">SUSE bug 1087083</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1094912">SUSE bug 1094912</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1098813">SUSE bug 1098813</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1100394">SUSE bug 1100394</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1175912">SUSE bug 1175912</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20183646" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-3646</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-3646" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3646" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-3646" ref_url="https://www.suse.com/security/cve/CVE-2018-3646" source="SUSE CVE"/>
		<reference ref_id="L1TF-BLOG-SUSE" ref_url="https://www.suse.com/c/suse-addresses-the-l1-terminal-fault-issue/" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004416.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2331-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004716.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004417.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2335-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004419.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2341-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004426.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2344-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004428.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004430.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004433.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004435.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2363-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004444.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2366-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2368-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2369-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2384-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2391-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2401-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2409-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004464.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2410-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2410-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004468.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2414-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2472-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004485.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2473-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004487.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2483-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2963-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20182963-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:4300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-December/005008.html" source="SUSE-SU"/>
		<reference ref_id="TID000019216" ref_url="https://www.suse.com/support/kb/doc/?id=000019216" source="SUSE-SU"/>
		<reference ref_id="TID000019230" ref_url="https://www.suse.com/support/kb/doc/?id=000019230" source="SUSE-SU"/>
		<reference ref_id="TID000019335" ref_url="https://www.suse.com/support/kb/doc/?id=000019335" source="SUSE-SU"/>
		<reference ref_id="TID000019439" ref_url="https://www.suse.com/support/kb/doc/?id=000019439" source="SUSE-SU"/>
		<reference ref_id="TID7023077" ref_url="https://www.suse.com/support/kb/doc/?id=7023077" source="SUSE-SU"/>
		<reference ref_id="TID7023078" ref_url="https://www.suse.com/support/kb/doc/?id=7023078" source="SUSE-SU"/>
		<reference ref_id="TID7023312" ref_url="https://www.suse.com/support/kb/doc/?id=7023312" source="SUSE-SU"/>
		<reference ref_id="TID7023497" ref_url="https://www.suse.com/support/kb/doc/?id=7023497" source="SUSE-SU"/>
		<reference ref_id="TID7023836" ref_url="https://www.suse.com/support/kb/doc/?id=7023836" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2399-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2404-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2434-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2436-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:4304-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00073.html" source="SUSE-SU"/>
    <description>
    Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.6/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-3646/">CVE-2018-3646</cve>
	<bugzilla href="https://bugzilla.suse.com/1087078">SUSE bug 1087078</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087081">SUSE bug 1087081</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1089343">SUSE bug 1089343</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1091107">SUSE bug 1091107</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1099306">SUSE bug 1099306</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1104365">SUSE bug 1104365</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1104894">SUSE bug 1104894</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1106548">SUSE bug 1106548</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1113534">SUSE bug 1113534</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136865">SUSE bug 1136865</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20183665" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-3665</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-3665" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3665" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-3665" ref_url="https://www.suse.com/security/cve/CVE-2018-3665" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1855-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1855-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1940-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004261.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004263.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004265.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1944-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1945-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1946-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004268.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1981-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004304.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2069-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004315.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2081-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004328.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004330.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004332.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004333.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004336.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004338.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2099-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20182099-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2100-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2101-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004347.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004348.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004349.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004350.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004351.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004355.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2250-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004391.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004396.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004499.html" source="SUSE-SU"/>
		<reference ref_id="TID000019231" ref_url="https://www.suse.com/support/kb/doc/?id=000019231" source="SUSE-SU"/>
		<reference ref_id="TID000019261" ref_url="https://www.suse.com/support/kb/doc/?id=000019261" source="SUSE-SU"/>
		<reference ref_id="TID000019439" ref_url="https://www.suse.com/support/kb/doc/?id=000019439" source="SUSE-SU"/>
		<reference ref_id="TID7022512" ref_url="https://www.suse.com/support/kb/doc/?id=7022512" source="SUSE-SU"/>
		<reference ref_id="TID7023076" ref_url="https://www.suse.com/support/kb/doc/?id=7023076" source="SUSE-SU"/>
		<reference ref_id="TID7023167" ref_url="https://www.suse.com/support/kb/doc/?id=7023167" source="SUSE-SU"/>
		<reference ref_id="TID7023836" ref_url="https://www.suse.com/support/kb/doc/?id=7023836" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1773-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-06/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2116-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-07/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2211-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00012.html" source="SUSE-SU"/>
    <description>
    System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-3665/">CVE-2018-3665</cve>
	<bugzilla href="https://bugzilla.suse.com/1087078">SUSE bug 1087078</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087086">SUSE bug 1087086</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1090338">SUSE bug 1090338</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1095241">SUSE bug 1095241</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1095242">SUSE bug 1095242</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1096740">SUSE bug 1096740</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1100091">SUSE bug 1100091</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1100555">SUSE bug 1100555</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20185146" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-5146</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-5146" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5146" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-5146" ref_url="https://www.suse.com/security/cve/CVE-2018-5146" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0907-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003882.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0737-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0805-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-03/msg00095.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0818-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-03/msg00100.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0819-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-03/msg00101.html" source="SUSE-SU"/>
    <description>
    An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox &lt; 59.0.1, Firefox ESR &lt; 52.7.2, and Thunderbird &lt; 52.7.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-5146/">CVE-2018-5146</cve>
	<bugzilla href="https://bugzilla.suse.com/1085671">SUSE bug 1085671</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1085687">SUSE bug 1085687</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180395">SUSE bug 1180395</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481533" comment="libvorbis0-1.3.6-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481534" comment="libvorbisenc2-1.3.6-4.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20185244" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-5244</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-5244" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5244" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-5244" ref_url="https://www.suse.com/security/cve/CVE-2018-5244" source="SUSE CVE"/>
    <description>
    In Xen 4.10, new infrastructure was introduced as part of an overhaul to how MSR emulation happens for guests. Unfortunately, one tracking structure isn't freed when a vcpu is destroyed. This allows guest OS administrators to cause a denial of service (host OS memory consumption) by rebooting many times.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-5244/">CVE-2018-5244</cve>
	<bugzilla href="https://bugzilla.suse.com/1073961">SUSE bug 1073961</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1074966">SUSE bug 1074966</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20185344" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-5344</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-5344" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5344" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-5344" ref_url="https://www.suse.com/security/cve/CVE-2018-5344" source="SUSE CVE"/>
    <description>
    In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release serialization, which allows attackers to cause a denial of service (__lock_acquire use-after-free) or possibly have unspecified other impact.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-5344/">CVE-2018-5344</cve>
	<bugzilla href="https://bugzilla.suse.com/1075825">SUSE bug 1075825</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20185703" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-5703</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-5703" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5703" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-5703" ref_url="https://www.suse.com/security/cve/CVE-2018-5703" source="SUSE CVE"/>
    <description>
    The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.14.11 allows attackers to cause a denial of service (slab out-of-bounds write) or possibly have unspecified other impact via vectors involving TLS.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-5703/">CVE-2018-5703</cve>
	<bugzilla href="https://bugzilla.suse.com/1076200">SUSE bug 1076200</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20185729" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-5729</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-5729" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5729" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-5729" ref_url="https://www.suse.com/security/cve/CVE-2018-5729" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0854-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-03/msg00116.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0139-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00006.html" source="SUSE-SU"/>
    <description>
    MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.2/CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-5729/">CVE-2018-5729</cve>
	<bugzilla href="https://bugzilla.suse.com/1076211">SUSE bug 1076211</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1083926">SUSE bug 1083926</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122468">SUSE bug 1122468</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20185730" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-5730</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-5730" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5730" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-5730" ref_url="https://www.suse.com/security/cve/CVE-2018-5730" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0854-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-03/msg00116.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0139-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00006.html" source="SUSE-SU"/>
    <description>
    MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-5730/">CVE-2018-5730</cve>
	<bugzilla href="https://bugzilla.suse.com/1076211">SUSE bug 1076211</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1083927">SUSE bug 1083927</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122468">SUSE bug 1122468</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20185748" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-5748</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-5748" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5748" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-5748" ref_url="https://www.suse.com/security/cve/CVE-2018-5748" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-February/003713.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0838-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004357.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0322-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00120.html" source="SUSE-SU"/>
    <description>
    qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.8/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-5748/">CVE-2018-5748</cve>
	<bugzilla href="https://bugzilla.suse.com/1076500">SUSE bug 1076500</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1083625">SUSE bug 1083625</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087887">SUSE bug 1087887</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334933" comment="libvirt-daemon is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334936" comment="libvirt-daemon-driver-interface is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334939" comment="libvirt-daemon-driver-network is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334940" comment="libvirt-daemon-driver-nodedev is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334941" comment="libvirt-daemon-driver-nwfilter is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334942" comment="libvirt-daemon-driver-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334943" comment="libvirt-daemon-driver-secret is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334944" comment="libvirt-daemon-driver-storage is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336191" comment="libvirt-daemon-driver-storage-core is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336192" comment="libvirt-daemon-driver-storage-disk is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336193" comment="libvirt-daemon-driver-storage-iscsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336194" comment="libvirt-daemon-driver-storage-logical is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336195" comment="libvirt-daemon-driver-storage-mpath is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336196" comment="libvirt-daemon-driver-storage-rbd is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336197" comment="libvirt-daemon-driver-storage-scsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334946" comment="libvirt-daemon-qemu is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20185764" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-5764</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-5764" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5764" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-5764" ref_url="https://www.suse.com/security/cve/CVE-2018-5764" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003617.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0174-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003619.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0643-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-03/msg00026.html" source="SUSE-SU"/>
    <description>
    The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-5764/">CVE-2018-5764</cve>
	<bugzilla href="https://bugzilla.suse.com/1076503">SUSE bug 1076503</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482539" comment="rsync-3.1.3-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20186003" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-6003</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-6003" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6003" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-6003" ref_url="https://www.suse.com/security/cve/CVE-2018-6003" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-January/003682.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0324-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-01/msg00122.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-6003/">CVE-2018-6003</cve>
	<bugzilla href="https://bugzilla.suse.com/1076832">SUSE bug 1076832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482427" comment="libtasn1-4.13-4.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482428" comment="libtasn1-6-4.13-4.5.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20186485" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-6485</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-6485" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6485" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-6485" ref_url="https://www.suse.com/security/cve/CVE-2018-6485" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0451-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0565-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00039.html" source="SUSE-SU"/>
    <description>
    An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2018-6485/">CVE-2018-6485</cve>
	<bugzilla href="https://bugzilla.suse.com/1079036">SUSE bug 1079036</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123874">SUSE bug 1123874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20186551" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-6551</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-6551" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6551" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-6551" ref_url="https://www.suse.com/security/cve/CVE-2018-6551" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0451-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0565-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00049.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00039.html" source="SUSE-SU"/>
    <description>
    The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls with arguments close to SIZE_MAX and could return a pointer to a heap region that is smaller than requested, eventually leading to heap corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-6551/">CVE-2018-6551</cve>
	<bugzilla href="https://bugzilla.suse.com/1079036">SUSE bug 1079036</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20186829" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-6829</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-6829" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6829" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-6829" ref_url="https://www.suse.com/security/cve/CVE-2018-6829" source="SUSE CVE"/>
    <description>
    cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-6829/">CVE-2018-6829</cve>
	<bugzilla href="https://bugzilla.suse.com/1081684">SUSE bug 1081684</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335465" comment="libgcrypt20 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20186914" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-6914</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-6914" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6914" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-6914" ref_url="https://www.suse.com/security/cve/CVE-2018-6914" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-6914/">CVE-2018-6914</cve>
	<bugzilla href="https://bugzilla.suse.com/1087441">SUSE bug 1087441</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136906">SUSE bug 1136906</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20186942" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-6942</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-6942" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6942" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-6942" ref_url="https://www.suse.com/security/cve/CVE-2018-6942" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006839.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0704-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00054.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-6942/">CVE-2018-6942</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20186954" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-6954</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-6954" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6954" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-6954" ref_url="https://www.suse.com/security/cve/CVE-2018-6954" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005467.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0098-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1450-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html" source="SUSE-SU"/>
    <description>
    systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2018-6954/">CVE-2018-6954</cve>
	<bugzilla href="https://bugzilla.suse.com/1080919">SUSE bug 1080919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20187169" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-7169</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-7169" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7169" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-7169" ref_url="https://www.suse.com/security/cve/CVE-2018-7169" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-March/003805.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0667-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-03/msg00036.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used "group blacklisting" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-7169/">CVE-2018-7169</cve>
	<bugzilla href="https://bugzilla.suse.com/1081294">SUSE bug 1081294</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482541" comment="shadow-4.6-3.5.6 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20187480" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-7480</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-7480" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7480" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-7480" ref_url="https://www.suse.com/security/cve/CVE-2018-7480" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:3003-1" ref_url="https://www.suse.com/support/update/announcement/2018/suse-su-20183003-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3004-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3202-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00033.html" source="SUSE-SU"/>
    <description>
    The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial of service (double free) or possibly have unspecified other impact by triggering a creation failure.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-7480/">CVE-2018-7480</cve>
	<bugzilla href="https://bugzilla.suse.com/1082863">SUSE bug 1082863</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1084536">SUSE bug 1084536</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20187540" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-7540</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-7540" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7540" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-7540" ref_url="https://www.suse.com/security/cve/CVE-2018-7540" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00059.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU hang) via non-preemptable L3/L4 pagetable freeing.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-7540/">CVE-2018-7540</cve>
	<bugzilla href="https://bugzilla.suse.com/1080635">SUSE bug 1080635</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20187541" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-7541</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-7541" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7541" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-7541" ref_url="https://www.suse.com/security/cve/CVE-2018-7541" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0678-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0909-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00059.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service (hypervisor crash) or gain privileges by triggering a grant-table transition from v2 to v1.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2018-7541/">CVE-2018-7541</cve>
	<bugzilla href="https://bugzilla.suse.com/1080662">SUSE bug 1080662</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20187542" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-7542</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-7542" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7542" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-7542" ref_url="https://www.suse.com/security/cve/CVE-2018-7542" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00059.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hypervisor crash) by leveraging the mishandling of configurations that lack a Local APIC.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-7542/">CVE-2018-7542</cve>
	<bugzilla href="https://bugzilla.suse.com/1080634">SUSE bug 1080634</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20187550" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-7550</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-7550" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7550" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-7550" ref_url="https://www.suse.com/security/cve/CVE-2018-7550" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0762-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:0831-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1077-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-04/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1177-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1202-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1308-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-May/004054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2340-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004424.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0780-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-03/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2402-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00060.html" source="SUSE-SU"/>
    <description>
    The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-7550/">CVE-2018-7550</cve>
	<bugzilla href="https://bugzilla.suse.com/1083291">SUSE bug 1083291</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1083292">SUSE bug 1083292</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20187685" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-7685</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-7685" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7685" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-7685" ref_url="https://www.suse.com/security/cve/CVE-2018-7685" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-August/004510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2688-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2690-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2716-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004713.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-September/004582.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2739-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2881-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-09/msg00079.html" source="SUSE-SU"/>
    <description>
    The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malicious warnings only displayed during download.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-7685/">CVE-2018-7685</cve>
	<bugzilla href="https://bugzilla.suse.com/1045735">SUSE bug 1045735</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1088705">SUSE bug 1088705</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1091624">SUSE bug 1091624</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760839" comment="libzypp-17.25.6-3.28.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20187738" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-7738</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-7738" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7738" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-7738" ref_url="https://www.suse.com/security/cve/CVE-2018-7738" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2066-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:2071-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-July/004317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3926-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-November/004898.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0390-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015862.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:2205-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-08/msg00007.html" source="SUSE-SU"/>
    <description>
    In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-08-12"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-7738/">CVE-2018-7738</cve>
	<bugzilla href="https://bugzilla.suse.com/1080740">SUSE bug 1080740</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1084300">SUSE bug 1084300</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1213865">SUSE bug 1213865</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760806" comment="libblkid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760807" comment="libfdisk1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760808" comment="libmount1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760809" comment="libsmartcols1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760810" comment="libuuid1-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760811" comment="util-linux-2.33.1-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760812" comment="util-linux-systemd-2.33.1-4.13.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20187858" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-7858</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-7858" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7858" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-7858" ref_url="https://www.suse.com/security/cve/CVE-2018-7858" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005184.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00042.html" source="SUSE-SU"/>
    <description>
    Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-7858/">CVE-2018-7858</cve>
	<bugzilla href="https://bugzilla.suse.com/1084604">SUSE bug 1084604</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20187995" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-7995</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-7995" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7995" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-7995" ref_url="https://www.suse.com/security/cve/CVE-2018-7995" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (panic) by leveraging root access to write to the check_interval file in a /sys/devices/system/machinecheck/machinecheck&lt;cpu number&gt; directory. NOTE: a third party has indicated that this report is not security relevant.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-7995/">CVE-2018-7995</cve>
	<bugzilla href="https://bugzilla.suse.com/1084755">SUSE bug 1084755</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087082">SUSE bug 1087082</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20187999" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-7999</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-7999" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7999" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-7999" ref_url="https://www.suse.com/security/cve/CVE-2018-7999" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:0858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-April/003860.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:0883-1" ref_url="https://lists.opensuse.org/opensuse-updates/2018-04/msg00002.html" source="SUSE-SU"/>
    <description>
    In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRendering operation, which may allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ttf file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-7999/">CVE-2018-7999</cve>
	<bugzilla href="https://bugzilla.suse.com/1084850">SUSE bug 1084850</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009480302" comment="libgraphite2-3-1.3.11-2.12 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20188740" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-8740</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-8740" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8740" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-8740" ref_url="https://www.suse.com/security/cve/CVE-2018-8740" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14228-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005569.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1426-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00050.html" source="SUSE-SU"/>
    <description>
    In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, related to build.c and prepare.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-8740/">CVE-2018-8740</cve>
	<bugzilla href="https://bugzilla.suse.com/1085790">SUSE bug 1085790</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131919">SUSE bug 1131919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482404" comment="libsqlite3-0-3.28.0-3.9.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20188769" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-8769</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-8769" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8769" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-8769" ref_url="https://www.suse.com/security/cve/CVE-2018-8769" source="SUSE CVE"/>
    <description>
    elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-23"/>
	<updated date="2023-09-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-8769/">CVE-2018-8769</cve>
	<bugzilla href="https://bugzilla.suse.com/1085809">SUSE bug 1085809</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334073" comment="elfutils is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335871" comment="libasm1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335872" comment="libdw1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009659704" comment="libebl-plugins is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335876" comment="libelf1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20188777" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-8777</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-8777" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8777" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-8777" ref_url="https://www.suse.com/security/cve/CVE-2018-8777" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server/handler and cause a denial of service (memory consumption).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-8777/">CVE-2018-8777</cve>
	<bugzilla href="https://bugzilla.suse.com/1087436">SUSE bug 1087436</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136906">SUSE bug 1136906</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20188778" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-8778</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-8778" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8778" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-8778" ref_url="https://www.suse.com/security/cve/CVE-2018-8778" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#unpack method, resulting in a massive and controlled information disclosure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2018-8778/">CVE-2018-8778</cve>
	<bugzilla href="https://bugzilla.suse.com/1087433">SUSE bug 1087433</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136906">SUSE bug 1136906</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20188779" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-8779</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-8779" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8779" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-8779" ref_url="https://www.suse.com/security/cve/CVE-2018-8779" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-8779/">CVE-2018-8779</cve>
	<bugzilla href="https://bugzilla.suse.com/1087440">SUSE bug 1087440</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136906">SUSE bug 1136906</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20188780" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-8780</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-8780" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8780" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-8780" ref_url="https://www.suse.com/security/cve/CVE-2018-8780" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2018-8780/">CVE-2018-8780</cve>
	<bugzilla href="https://bugzilla.suse.com/1087437">SUSE bug 1087437</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136906">SUSE bug 1136906</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20188897" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-8897</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-8897" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8897" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-8897" ref_url="https://www.suse.com/security/cve/CVE-2018-8897" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2018:1171-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1172-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1173-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1173-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1177-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1202-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1203-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1216-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1220-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1221-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004122.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004123.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004124.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1517-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004125.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1518-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004126.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1519-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1523-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1529-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1533-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1537-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1539-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1636-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004170.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1639-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1644-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1645-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:1648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-June/004180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004740.html" source="SUSE-SU"/>
		<reference ref_id="TID000019188" ref_url="https://www.suse.com/support/kb/doc/?id=000019188" source="SUSE-SU"/>
		<reference ref_id="TID7022916" ref_url="https://www.suse.com/support/kb/doc/?id=7022916" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:1274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-05/msg00059.html" source="SUSE-SU"/>
    <description>
    A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen configurations, or FreeBSD, or a Linux kernel crash. The MOV to SS and POP SS instructions inhibit interrupts (including NMIs), data breakpoints, and single step trap exceptions until the instruction boundary following the next instruction (SDM Vol. 3A; section 6.8.3). (The inhibited data breakpoints are those on memory accessed by the MOV to SS or POP to SS instruction itself.) Note that debug exceptions are not inhibited by the interrupt enable (EFLAGS.IF) system flag (SDM Vol. 3A; section 2.3). If the instruction following the MOV to SS or POP to SS instruction is an instruction like SYSCALL, SYSENTER, INT 3, etc. that transfers control to the operating system at CPL &lt; 3, the debug exception is delivered after the transfer to CPL &lt; 3 is complete. OS kernels may not expect this order of events and may therefore experience unexpected behavior when it occurs.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2018-8897/">CVE-2018-8897</cve>
	<bugzilla href="https://bugzilla.suse.com/1087078">SUSE bug 1087078</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1087088">SUSE bug 1087088</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1090368">SUSE bug 1090368</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1090820">SUSE bug 1090820</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1090869">SUSE bug 1090869</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1092497">SUSE bug 1092497</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1093522">SUSE bug 1093522</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1093524">SUSE bug 1093524</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1098813">SUSE bug 1098813</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1100835">SUSE bug 1100835</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1115893">SUSE bug 1115893</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20189056" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-9056</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-9056" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9056" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-9056" ref_url="https://www.suse.com/security/cve/CVE-2018-9056" source="SUSE CVE"/>
    <description>
    Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-25"/>
	<updated date="2022-08-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-9056/">CVE-2018-9056</cve>
	<bugzilla href="https://bugzilla.suse.com/1087110">SUSE bug 1087110</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20189234" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-9234</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-9234" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9234" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-9234" ref_url="https://www.suse.com/security/cve/CVE-2018-9234" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:3214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3857-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031800.html" source="SUSE-SU"/>
    <description>
    GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-10-01"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2018-9234/">CVE-2018-9234</cve>
	<bugzilla href="https://bugzilla.suse.com/1088255">SUSE bug 1088255</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1090647">SUSE bug 1090647</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482000" comment="gpg2-2.2.5-4.14.4 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20189251" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2018-9251</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2018-9251" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9251" source="CVE"/>
    <reference ref_id="SUSE CVE-2018-9251" ref_url="https://www.suse.com/security/cve/CVE-2018-9251" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2018:3081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2018-October/004657.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3107-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2018:3110-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2018-10/msg00029.html" source="SUSE-SU"/>
    <description>
    The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2018-9251/">CVE-2018-9251</cve>
	<bugzilla href="https://bugzilla.suse.com/1088279">SUSE bug 1088279</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1088601">SUSE bug 1088601</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1105166">SUSE bug 1105166</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20190154" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-0154</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-0154" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0154" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-0154" ref_url="https://www.suse.com/security/cve/CVE-2019-0154" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2946-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192946-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2503-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00039.html" source="SUSE-SU"/>
    <description>
    Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families may allow an authenticated user to potentially enable denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-0154/">CVE-2019-0154</cve>
	<bugzilla href="https://bugzilla.suse.com/1135966">SUSE bug 1135966</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181720">SUSE bug 1181720</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20190155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-0155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-0155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0155" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-0155" ref_url="https://www.suse.com/security/cve/CVE-2019-0155" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2946-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192946-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007365.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2503-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00039.html" source="SUSE-SU"/>
    <description>
    Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or 26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154, 4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation of privilege via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-0155/">CVE-2019-0155</cve>
	<bugzilla href="https://bugzilla.suse.com/1135966">SUSE bug 1135966</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135967">SUSE bug 1135967</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173663">SUSE bug 1173663</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20191010305" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-1010305</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-1010305" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010305" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-1010305" ref_url="https://www.suse.com/security/cve/CVE-2019-1010305" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:1493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2711-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007450.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0746-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00068.html" source="SUSE-SU"/>
    <description>
    libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm file. The fixed version is: after commit 2f084136cfe0d05e5bf5703f3e83c6d955234b4d.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-1010305/">CVE-2019-1010305</cve>
	<bugzilla href="https://bugzilla.suse.com/1141680">SUSE bug 1141680</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482310" comment="libmspack0-0.6-3.8.19 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910125" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10125</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10125" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10125" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10125" ref_url="https://www.suse.com/security/cve/CVE-2019-10125" source="SUSE CVE"/>
    <description>
    An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is triggered immediately (e.g., by the close of a pair of pipes) after the return of vfs_poll(), and this will cause a use-after-free.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-10125/">CVE-2019-10125</cve>
	<bugzilla href="https://bugzilla.suse.com/1130695">SUSE bug 1130695</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910132" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10132</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10132" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10132" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10132" ref_url="https://www.suse.com/security/cve/CVE-2019-10132" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005555.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in libvirt &gt;= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-10132/">CVE-2019-10132</cve>
	<bugzilla href="https://bugzilla.suse.com/1134348">SUSE bug 1134348</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910140" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10140</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10140" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10140" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10140" ref_url="https://www.suse.com/security/cve/CVE-2019-10140" source="SUSE CVE"/>
    <description>
    A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-10140/">CVE-2019-10140</cve>
	<bugzilla href="https://bugzilla.suse.com/1145701">SUSE bug 1145701</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910142" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10142</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10142" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10142" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10142" ref_url="https://www.suse.com/security/cve/CVE-2019-10142" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parameter passed to an ioctl was incorrectly validated and used in size calculations for the page size calculation. An attacker can use this flaw to crash the system, corrupt memory, or create other adverse security affects.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-10142/">CVE-2019-10142</cve>
	<bugzilla href="https://bugzilla.suse.com/1135955">SUSE bug 1135955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910152" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10152</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10152" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10152" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10152" ref_url="https://www.suse.com/security/cve/CVE-2019-10152" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005844.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00001.html" source="SUSE-SU"/>
    <description>
    A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.2/CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-10152/">CVE-2019-10152</cve>
	<bugzilla href="https://bugzilla.suse.com/1136974">SUSE bug 1136974</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628652" comment="libcontainers-common-20200727-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629073" comment="podman-2.1.1-4.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629074" comment="podman-cni-config-2.1.1-4.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910160" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10160</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10160" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10160" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10160" ref_url="https://www.suse.com/security/cve/CVE-2019-10160" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2053-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2064-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005783.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005803.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006445.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1906-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-10160/">CVE-2019-10160</cve>
	<bugzilla href="https://bugzilla.suse.com/1138459">SUSE bug 1138459</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910161" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10161</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10161" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10161" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10161" ref_url="https://www.suse.com/security/cve/CVE-2019-10161" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14100-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005613.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005612.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1686-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005628.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1690-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005629.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2227-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2227-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005908.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00091.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1753-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00019.html" source="SUSE-SU"/>
    <description>
    It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-10161/">CVE-2019-10161</cve>
	<bugzilla href="https://bugzilla.suse.com/1138301">SUSE bug 1138301</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910166" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10166</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10166" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10166" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10166" ref_url="https://www.suse.com/security/cve/CVE-2019-10166" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005612.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005615.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00091.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1753-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00019.html" source="SUSE-SU"/>
    <description>
    It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-10166/">CVE-2019-10166</cve>
	<bugzilla href="https://bugzilla.suse.com/1138302">SUSE bug 1138302</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910167" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10167</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10167" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10167" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10167" ref_url="https://www.suse.com/security/cve/CVE-2019-10167" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005612.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1686-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005628.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2227-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2227-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005908.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00091.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1753-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00019.html" source="SUSE-SU"/>
    <description>
    The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-10167/">CVE-2019-10167</cve>
	<bugzilla href="https://bugzilla.suse.com/1138303">SUSE bug 1138303</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910168" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10168</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10168" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10168" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10168" ref_url="https://www.suse.com/security/cve/CVE-2019-10168" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005615.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1753-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00019.html" source="SUSE-SU"/>
    <description>
    The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-10168/">CVE-2019-10168</cve>
	<bugzilla href="https://bugzilla.suse.com/1138305">SUSE bug 1138305</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138582">SUSE bug 1138582</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910214" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10214</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10214" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10214" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10214" ref_url="https://www.suse.com/security/cve/CVE-2019-10214" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2340-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2341-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005898.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2368-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192368-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2369-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192369-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3423-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010404.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2137-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2138-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2143-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2159-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0377-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0554-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2106-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q7YYGMTZ4T4RLHDVCMQD3K6CDIAXO3O3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0310-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/P4DQSPUPKAZCPS5MQYTAYGS7YM76UIHZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0770-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WFIDXN6UAK2I4PPVFPBE4STNQH2FZQ4A/" source="SUSE-SU"/>
    <description>
    The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-10214/">CVE-2019-10214</cve>
	<bugzilla href="https://bugzilla.suse.com/1144065">SUSE bug 1144065</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629073" comment="podman-2.1.1-4.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629074" comment="podman-cni-config-2.1.1-4.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910220" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10220</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10220" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10220" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10220" ref_url="https://www.suse.com/security/cve/CVE-2019-10220" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2829-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192829-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2859-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192859-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2864-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2946-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192946-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2947-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192947-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2951-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2952-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2953-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192953-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3019-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193019-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006226.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006225.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3224-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3225-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006223.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3228-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3247-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006240.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006242.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006245.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3252-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006241.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3258-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006244.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3260-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006247.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006243.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006399.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2503-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00039.html" source="SUSE-SU"/>
    <description>
    Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-10220/">CVE-2019-10220</cve>
	<bugzilla href="https://bugzilla.suse.com/1144903">SUSE bug 1144903</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1153108">SUSE bug 1153108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910557" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10557</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10557" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10557" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10557" ref_url="https://www.suse.com/security/cve/CVE-2019-10557" source="SUSE CVE"/>
    <description>
    Out-of-bound read in the wireless driver in the Linux kernel due to lack of check of buffer length. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &amp; Music in APQ8009, APQ8017, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCN7605, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDX20, SDX55, SXR1130
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-10557/">CVE-2019-10557</cve>
	<bugzilla href="https://bugzilla.suse.com/1159621">SUSE bug 1159621</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201910906" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-10906</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-10906" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10906" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-10906" ref_url="https://www.suse.com/security/cve/CVE-2019-10906" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007672.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3896-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008099.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1614-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L" href="https://www.suse.com/security/cve/CVE-2019-10906/">CVE-2019-10906</cve>
	<bugzilla href="https://bugzilla.suse.com/1132323">SUSE bug 1132323</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481633" comment="python3-Jinja2-2.10.1-3.5.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911068" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11068</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11068" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11068" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11068" ref_url="https://www.suse.com/security/cve/CVE-2019-11068" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1221-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1862-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005722.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2046-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005772.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1428-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1430-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1433-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1527-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1824-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00001.html" source="SUSE-SU"/>
    <description>
    libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-11068/">CVE-2019-11068</cve>
	<bugzilla href="https://bugzilla.suse.com/1132160">SUSE bug 1132160</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154212">SUSE bug 1154212</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482467" comment="libxslt1-1.1.32-3.8.24 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911091" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11091</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11091" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11091" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11091" ref_url="https://www.suse.com/security/cve/CVE-2019-11091" source="SUSE CVE"/>
		<reference ref_id="MDS-BLOG-SUSE" ref_url="https://www.suse.com/c/suse-addresses-microarchitectural-data-sampling-vulnerabilities/" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005464.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14052-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1423-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005540.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1909-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="TID000019406" ref_url="https://www.suse.com/support/kb/doc/?id=000019406" source="SUSE-SU"/>
		<reference ref_id="TID000019455" ref_url="https://www.suse.com/support/kb/doc/?id=000019455" source="SUSE-SU"/>
		<reference ref_id="TID7023736" ref_url="https://www.suse.com/support/kb/doc/?id=7023736" source="SUSE-SU"/>
		<reference ref_id="TID7023881" ref_url="https://www.suse.com/support/kb/doc/?id=7023881" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1402-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1403-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1404-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1405-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1407-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1408-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1419-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1420-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1505-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1805-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1806-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00052.html" source="SUSE-SU"/>
    <description>
    Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-09-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-11091/">CVE-2019-11091</cve>
	<bugzilla href="https://bugzilla.suse.com/1103186">SUSE bug 1103186</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1111331">SUSE bug 1111331</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1132686">SUSE bug 1132686</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1133319">SUSE bug 1133319</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135394">SUSE bug 1135394</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138043">SUSE bug 1138043</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138534">SUSE bug 1138534</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1141977">SUSE bug 1141977</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911135" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11135</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11135" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11135" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11135" ref_url="https://www.suse.com/security/cve/CVE-2019-11135" source="SUSE CVE"/>
		<reference ref_id="SUSE-BLOG-TAA-IFU" ref_url="https://www.suse.com/c/suse-addresses-transactional-asynchronous-abort-and-machine-check-error-on-page-size-changes-issues/" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2946-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192946-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2947-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192947-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2951-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2952-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2953-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192953-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2955-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192955-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2956-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006122.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2958-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192958-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2959-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192959-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2961-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192961-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2986-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2987-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2988-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006253.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3340-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0334-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007221.html" source="SUSE-SU"/>
		<reference ref_id="TID000019563" ref_url="https://www.suse.com/support/kb/doc/?id=000019563" source="SUSE-SU"/>
		<reference ref_id="TID7024251" ref_url="https://www.suse.com/support/kb/doc/?id=7024251" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2503-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2504-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2505-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2506-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2509-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2527-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00045.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2710-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00042.html" source="SUSE-SU"/>
    <description>
    TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-09-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-11135/">CVE-2019-11135</cve>
	<bugzilla href="https://bugzilla.suse.com/1139073">SUSE bug 1139073</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1152497">SUSE bug 1152497</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1152505">SUSE bug 1152505</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1152506">SUSE bug 1152506</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1160120">SUSE bug 1160120</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911139" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11139</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11139" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11139" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11139" ref_url="https://www.suse.com/security/cve/CVE-2019-11139" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006122.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2958-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192958-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2959-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192959-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2986-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2987-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2988-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006195.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2504-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2509-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2527-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00046.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2528-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00045.html" source="SUSE-SU"/>
    <description>
    Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-11139/">CVE-2019-11139</cve>
	<bugzilla href="https://bugzilla.suse.com/1141035">SUSE bug 1141035</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911236" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11236</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11236" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11236" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11236" ref_url="https://www.suse.com/security/cve/CVE-2019-11236" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005893.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2370-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192370-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2391-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2399-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005931.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2131-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2133-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-11236/">CVE-2019-11236</cve>
	<bugzilla href="https://bugzilla.suse.com/1129071">SUSE bug 1129071</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1132663">SUSE bug 1132663</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760851" comment="python3-urllib3-1.24-9.10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911324" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11324</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11324" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11324" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11324" ref_url="https://www.suse.com/security/cve/CVE-2019-11324" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005893.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2370-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192370-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2391-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005927.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2131-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2133-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-11324/">CVE-2019-11324</cve>
	<bugzilla href="https://bugzilla.suse.com/1132900">SUSE bug 1132900</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760851" comment="python3-urllib3-1.24-9.10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911477" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11477</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11477" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11477" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11477" ref_url="https://www.suse.com/security/cve/CVE-2019-11477" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1527-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1529-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1533-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005578.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1581-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1588-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1668-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005617.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1674-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1692-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1882-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005730.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005744.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005958.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2658-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192658-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="TID000019472" ref_url="https://www.suse.com/support/kb/doc/?id=000019472" source="SUSE-SU"/>
		<reference ref_id="TID7023928" ref_url="https://www.suse.com/support/kb/doc/?id=7023928" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1571-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1579-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html" source="SUSE-SU"/>
    <description>
    Jonathan Looney discovered that the TCP_SKB_CB(skb)-&gt;tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2019-11477/">CVE-2019-11477</cve>
	<bugzilla href="https://bugzilla.suse.com/1132686">SUSE bug 1132686</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1137586">SUSE bug 1137586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1142129">SUSE bug 1142129</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1153242">SUSE bug 1153242</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911478" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11478</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11478" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11478" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11478" ref_url="https://www.suse.com/security/cve/CVE-2019-11478" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1527-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1529-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1533-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005578.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1581-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1588-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1668-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005617.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1674-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1692-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1851-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20191851-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1855-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005713.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1882-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005730.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005744.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2069-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005958.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006072.html" source="SUSE-SU"/>
		<reference ref_id="TID000019472" ref_url="https://www.suse.com/support/kb/doc/?id=000019472" source="SUSE-SU"/>
		<reference ref_id="TID7023928" ref_url="https://www.suse.com/support/kb/doc/?id=7023928" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1571-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1579-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html" source="SUSE-SU"/>
    <description>
    Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-11478/">CVE-2019-11478</cve>
	<bugzilla href="https://bugzilla.suse.com/1132686">SUSE bug 1132686</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1137586">SUSE bug 1137586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1142129">SUSE bug 1142129</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1143542">SUSE bug 1143542</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911479" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11479</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11479" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11479" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11479" ref_url="https://www.suse.com/security/cve/CVE-2019-11479" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1527-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1529-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1533-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005578.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1692-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006049.html" source="SUSE-SU"/>
		<reference ref_id="TID000019472" ref_url="https://www.suse.com/support/kb/doc/?id=000019472" source="SUSE-SU"/>
		<reference ref_id="TID7023928" ref_url="https://www.suse.com/support/kb/doc/?id=7023928" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1570-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1571-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1579-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00048.html" source="SUSE-SU"/>
    <description>
    Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-11479/">CVE-2019-11479</cve>
	<bugzilla href="https://bugzilla.suse.com/1132686">SUSE bug 1132686</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1137586">SUSE bug 1137586</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1142129">SUSE bug 1142129</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1143542">SUSE bug 1143542</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911555" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11555</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11555" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11555" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11555" ref_url="https://www.suse.com/security/cve/CVE-2019-11555" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-11555/">CVE-2019-11555</cve>
	<bugzilla href="https://bugzilla.suse.com/1133640">SUSE bug 1133640</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911683" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11683</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11683" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11683" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11683" ref_url="https://www.suse.com/security/cve/CVE-2019-11683" source="SUSE CVE"/>
    <description>
    udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-11683/">CVE-2019-11683</cve>
	<bugzilla href="https://bugzilla.suse.com/1134021">SUSE bug 1134021</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911745" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11745</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11745" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11745" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11745" ref_url="https://www.suse.com/security/cve/CVE-2019-11745" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14260-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3337-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3395-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0088-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200088-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14418-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007079.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0002-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00006.html" source="SUSE-SU"/>
    <description>
    When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird &lt; 68.3, Firefox ESR &lt; 68.3, and Firefox &lt; 71.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-11745/">CVE-2019-11745</cve>
	<bugzilla href="https://bugzilla.suse.com/1158328">SUSE bug 1158328</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158527">SUSE bug 1158527</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201911922" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-11922</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-11922" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11922" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-11922" ref_url="https://www.suse.com/security/cve/CVE-2019-11922" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2019:1845-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1952-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00078.html" source="SUSE-SU"/>
    <description>
    A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="0/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-11922/">CVE-2019-11922</cve>
	<bugzilla href="https://bugzilla.suse.com/1142941">SUSE bug 1142941</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482471" comment="libzstd1-1.4.4-1.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912067" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12067</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12067" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12067" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12067" ref_url="https://www.suse.com/security/cve/CVE-2019-12067" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
    <description>
    The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad-&gt;cur_cmd' is null.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-12067/">CVE-2019-12067</cve>
	<bugzilla href="https://bugzilla.suse.com/1145642">SUSE bug 1145642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1145652">SUSE bug 1145652</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912068" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12068</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12068" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12068" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12068" ref_url="https://www.suse.com/security/cve/CVE-2019-12068" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2955-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192955-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2956-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006934.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2505-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00038.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.html" source="SUSE-SU"/>
    <description>
    In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's-&gt;dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-12068/">CVE-2019-12068</cve>
	<bugzilla href="https://bugzilla.suse.com/1146873">SUSE bug 1146873</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146874">SUSE bug 1146874</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12155" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12155" ref_url="https://www.suse.com/security/cve/CVE-2019-12155" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2157-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005888.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005878.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005906.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2041-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2059-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00008.html" source="SUSE-SU"/>
    <description>
    interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-12155/">CVE-2019-12155</cve>
	<bugzilla href="https://bugzilla.suse.com/1135902">SUSE bug 1135902</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135905">SUSE bug 1135905</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912290" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12290</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12290" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12290" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12290" ref_url="https://www.suse.com/security/cve/CVE-2019-12290" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006193.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2613-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00008.html" source="SUSE-SU"/>
    <description>
    GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-12290/">CVE-2019-12290</cve>
	<bugzilla href="https://bugzilla.suse.com/1154884">SUSE bug 1154884</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628747" comment="libidn2-0-2.2.0-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912378" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12378</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12378" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12378" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12378" ref_url="https://www.suse.com/security/cve/CVE-2019-12378" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** An issue was discovered in ip6_ra_control in net/ipv6/ipv6_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This has been disputed as not an issue.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-12378/">CVE-2019-12378</cve>
	<bugzilla href="https://bugzilla.suse.com/1136588">SUSE bug 1136588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912379" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12379</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12379" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12379" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12379" ref_url="https://www.suse.com/security/cve/CVE-2019-12379" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** An issue was discovered in con_insert_unipair in drivers/tty/vt/consolemap.c in the Linux kernel through 5.1.5. There is a memory leak in a certain case of an ENOMEM outcome of kmalloc. NOTE: This id is disputed as not being an issue.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-12379/">CVE-2019-12379</cve>
	<bugzilla href="https://bugzilla.suse.com/1136602">SUSE bug 1136602</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912381" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12381</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12381" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12381" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12381" ref_url="https://www.suse.com/security/cve/CVE-2019-12381" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** An issue was discovered in ip_ra_control in net/ipv4/ip_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: this is disputed because new_ra is never used if it is NULL.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-12381/">CVE-2019-12381</cve>
	<bugzilla href="https://bugzilla.suse.com/1136593">SUSE bug 1136593</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912450" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12450</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12450" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12450" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12450" ref_url="https://www.suse.com/security/cve/CVE-2019-12450" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1594-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1722-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005644.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1650-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00076.html" source="SUSE-SU"/>
    <description>
    file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-12450/">CVE-2019-12450</cve>
	<bugzilla href="https://bugzilla.suse.com/1137001">SUSE bug 1137001</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1139959">SUSE bug 1139959</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1142126">SUSE bug 1142126</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760781" comment="glib2-tools-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760782" comment="libgio-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760783" comment="libglib-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760784" comment="libgmodule-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760785" comment="libgobject-2_0-0-2.62.6-3.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912454" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12454</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12454" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12454" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12454" ref_url="https://www.suse.com/security/cve/CVE-2019-12454" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** An issue was discovered in wcd9335_codec_enable_dec in sound/soc/codecs/wcd9335.c in the Linux kernel through 5.1.5. It uses kstrndup instead of kmemdup_nul, which allows attackers to have an unspecified impact via unknown vectors. NOTE: The vendor disputes this issues as not being a vulnerability because switching to kmemdup_nul() would only fix a security issue if the source string wasn't NUL-terminated, which is not the case.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-12454/">CVE-2019-12454</cve>
	<bugzilla href="https://bugzilla.suse.com/1136963">SUSE bug 1136963</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912455" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12455</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12455" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12455" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12455" ref_url="https://www.suse.com/security/cve/CVE-2019-12455" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** An issue was discovered in sunxi_divs_clk_setup in drivers/clk/sunxi/clk-sunxi.c in the Linux kernel through 5.1.5. There is an unchecked kstrndup of derived_name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This id is disputed as not being an issue because “The memory allocation that was not checked is part of a code that only runs at boot time, before user processes are started. Therefore, there is no possibility for an unprivileged user to control it, and no denial of service.”.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-12455/">CVE-2019-12455</cve>
	<bugzilla href="https://bugzilla.suse.com/1136946">SUSE bug 1136946</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912615" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12615</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12615" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12615" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12615" ref_url="https://www.suse.com/security/cve/CVE-2019-12615" source="SUSE CVE"/>
    <description>
    An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup_const of node_info-&gt;vdev_port.name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-12615/">CVE-2019-12615</cve>
	<bugzilla href="https://bugzilla.suse.com/1137195">SUSE bug 1137195</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912735" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12735</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12735" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12735" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12735" ref_url="https://www.suse.com/security/cve/CVE-2019-12735" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14078-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1456-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005543.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1457-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005545.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1551-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1561-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1562-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1759-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1796-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1997-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00075.html" source="SUSE-SU"/>
    <description>
    getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-12735/">CVE-2019-12735</cve>
	<bugzilla href="https://bugzilla.suse.com/1137443">SUSE bug 1137443</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760864" comment="vim-data-common-8.0.1568-5.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760865" comment="vim-small-8.0.1568-5.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912749" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12749</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12749" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12749" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12749" ref_url="https://www.suse.com/security/cve/CVE-2019-12749" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:616-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005601.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005596.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2820-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006487.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1672-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006978.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1604-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1671-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00092.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1750-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00026.html" source="SUSE-SU"/>
    <description>
    dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-12749/">CVE-2019-12749</cve>
	<bugzilla href="https://bugzilla.suse.com/1137832">SUSE bug 1137832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481908" comment="dbus-1-1.12.2-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481911" comment="libdbus-1-3-1.12.2-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912900" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12900</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12900" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12900" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12900" ref_url="https://www.suse.com/security/cve/CVE-2019-12900" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005707.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2004-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192004-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2013-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2013-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3066-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008064.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008110.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1781-1" ref_url="https://lists.opensuse.org/opensuse-updates/2019-07/msg00106.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1918-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2595-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00078.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2597-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2268-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GAR55SQV75RXSJVDKQWD4CZNKDOYFY5P/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2276-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DHFME6EFDMW6BQBIYMTU3MBXQLVR7QTK/" source="SUSE-SU"/>
    <description>
    BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-12900/">CVE-2019-12900</cve>
	<bugzilla href="https://bugzilla.suse.com/1139083">SUSE bug 1139083</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1141513">SUSE bug 1141513</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1149458">SUSE bug 1149458</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481775" comment="libbz2-1-1.0.6-5.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201912904" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-12904</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-12904" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12904" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-12904" ref_url="https://www.suse.com/security/cve/CVE-2019-12904" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005720.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005751.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1792-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00049.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-12904/">CVE-2019-12904</cve>
	<bugzilla href="https://bugzilla.suse.com/1138939">SUSE bug 1138939</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482233" comment="libgcrypt20-1.8.2-8.36.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201913050" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-13050</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-13050" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13050" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-13050" ref_url="https://www.suse.com/security/cve/CVE-2019-13050" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2006-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192006-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1917-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00039.html" source="SUSE-SU"/>
    <description>
    Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-13050/">CVE-2019-13050</cve>
	<bugzilla href="https://bugzilla.suse.com/1141093">SUSE bug 1141093</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482000" comment="gpg2-2.2.5-4.14.4 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201913057" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-13057</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-13057" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13057" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-13057" ref_url="https://www.suse.com/security/cve/CVE-2019-13057" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2390-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2395-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1210-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006767.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2157-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2176-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-13057/">CVE-2019-13057</cve>
	<bugzilla href="https://bugzilla.suse.com/1143273">SUSE bug 1143273</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201913115" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-13115</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-13115" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13115" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-13115" ref_url="https://www.suse.com/security/cve/CVE-2019-13115" source="SUSE CVE"/>
    <description>
    In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server. This is related to an _libssh2_check_length mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-13115/">CVE-2019-13115</cve>
	<bugzilla href="https://bugzilla.suse.com/1141850">SUSE bug 1141850</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335952" comment="libssh2-1 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201913117" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-13117</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-13117" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13117" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-13117" ref_url="https://www.suse.com/security/cve/CVE-2019-13117" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1867-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006330.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006595.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1409-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006855.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0731-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html" source="SUSE-SU"/>
    <description>
    In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-13117/">CVE-2019-13117</cve>
	<bugzilla href="https://bugzilla.suse.com/1140095">SUSE bug 1140095</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157028">SUSE bug 1157028</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1160968">SUSE bug 1160968</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482467" comment="libxslt1-1.1.32-3.8.24 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201913118" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-13118</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-13118" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13118" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-13118" ref_url="https://www.suse.com/security/cve/CVE-2019-13118" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1867-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1409-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006855.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0731-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html" source="SUSE-SU"/>
    <description>
    In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-13118/">CVE-2019-13118</cve>
	<bugzilla href="https://bugzilla.suse.com/1140101">SUSE bug 1140101</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157028">SUSE bug 1157028</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1160968">SUSE bug 1160968</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482467" comment="libxslt1-1.1.32-3.8.24 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201913132" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-13132</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-13132" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13132" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-13132" ref_url="https://www.suse.com/security/cve/CVE-2019-13132" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005673.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005675.html" source="SUSE-SU"/>
		<reference ref_id="TID000019475" ref_url="https://www.suse.com/support/kb/doc/?id=000019475" source="SUSE-SU"/>
		<reference ref_id="TID7023929" ref_url="https://www.suse.com/support/kb/doc/?id=7023929" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1767-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public servers with the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="9.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-13132/">CVE-2019-13132</cve>
	<bugzilla href="https://bugzilla.suse.com/1140255">SUSE bug 1140255</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628931" comment="libzmq5-4.2.3-3.15.4 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201913164" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-13164</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-13164" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13164" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-13164" ref_url="https://www.suse.com/security/cve/CVE-2019-13164" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2157-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005888.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005878.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005906.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2041-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2059-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00008.html" source="SUSE-SU"/>
    <description>
    qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-13164/">CVE-2019-13164</cve>
	<bugzilla href="https://bugzilla.suse.com/1140402">SUSE bug 1140402</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201913377" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-13377</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-13377" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13377" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-13377" ref_url="https://www.suse.com/security/cve/CVE-2019-13377" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-13377/">CVE-2019-13377</cve>
	<bugzilla href="https://bugzilla.suse.com/1144443">SUSE bug 1144443</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201913509" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-13509</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-13509" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13509" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-13509" ref_url="https://www.suse.com/security/cve/CVE-2019-13509" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005814.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html" source="SUSE-SU"/>
    <description>
    In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-13509/">CVE-2019-13509</cve>
	<bugzilla href="https://bugzilla.suse.com/1142160">SUSE bug 1142160</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201913565" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-13565</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-13565" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13565" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-13565" ref_url="https://www.suse.com/security/cve/CVE-2019-13565" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2390-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2395-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1210-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006767.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2157-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2176-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL bind is completed, the sasl_ssf value is retained for all new non-SASL connections. Depending on the ACL configuration, this can affect different types of operations (searches, modifications, etc.). In other words, a successful authorization step completed by one user affects the authorization requirement for a different user.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-13565/">CVE-2019-13565</cve>
	<bugzilla href="https://bugzilla.suse.com/1143194">SUSE bug 1143194</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201913627" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-13627</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-13627" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13627" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-13627" ref_url="https://www.suse.com/security/cve/CVE-2019-13627" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005976.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3392-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006291.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2161-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0022-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00018.html" source="SUSE-SU"/>
    <description>
    It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-13627/">CVE-2019-13627</cve>
	<bugzilla href="https://bugzilla.suse.com/1148987">SUSE bug 1148987</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482233" comment="libgcrypt20-1.8.2-8.36.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914271" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14271</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14271" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14271" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14271" ref_url="https://www.suse.com/security/cve/CVE-2019-14271" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005814.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html" source="SUSE-SU"/>
    <description>
    In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.3/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14271/">CVE-2019-14271</cve>
	<bugzilla href="https://bugzilla.suse.com/1143409">SUSE bug 1143409</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914287" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14287</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14287" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14287" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14287" ref_url="https://www.suse.com/security/cve/CVE-2019-14287" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2656-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192656-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2666-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2667-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2668-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2316-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2333-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00047.html" source="SUSE-SU"/>
    <description>
    In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14287/">CVE-2019-14287</cve>
	<bugzilla href="https://bugzilla.suse.com/1153674">SUSE bug 1153674</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1156093">SUSE bug 1156093</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760863" comment="sudo-1.8.22-4.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914378" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14378</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14378" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14378" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14378" ref_url="https://www.suse.com/security/cve/CVE-2019-14378" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2157-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005888.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005878.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005906.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2955-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192955-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2041-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2059-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.html" source="SUSE-SU"/>
    <description>
    ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14378/">CVE-2019-14378</cve>
	<bugzilla href="https://bugzilla.suse.com/1143794">SUSE bug 1143794</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1143797">SUSE bug 1143797</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914513" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14513</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14513" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14513" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14513" ref_url="https://www.suse.com/security/cve/CVE-2019-14513" source="SUSE CVE"/>
    <description>
    Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-14513/">CVE-2019-14513</cve>
	<bugzilla href="https://bugzilla.suse.com/1143944">SUSE bug 1143944</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338972" comment="dnsmasq is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914615" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14615</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14615" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14615" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14615" ref_url="https://www.suse.com/security/cve/CVE-2019-14615" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-14615/">CVE-2019-14615</cve>
	<bugzilla href="https://bugzilla.suse.com/1160195">SUSE bug 1160195</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1165881">SUSE bug 1165881</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914763" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14763</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14763" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14763" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14763" ref_url="https://www.suse.com/security/cve/CVE-2019-14763" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c may potentially cause a deadlock with f_hid.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-14763/">CVE-2019-14763</cve>
	<bugzilla href="https://bugzilla.suse.com/1144918">SUSE bug 1144918</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914814" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14814</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14814" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14814" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14814" ref_url="https://www.suse.com/security/cve/CVE-2019-14814" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2414-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2651-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192651-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2658-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192658-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2738-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192738-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007367.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2173-1" ref_url="https://lists.opensuse.org/opensuse-updates/2019-09/msg00133.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html" source="SUSE-SU"/>
    <description>
    There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14814/">CVE-2019-14814</cve>
	<bugzilla href="https://bugzilla.suse.com/1146512">SUSE bug 1146512</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173664">SUSE bug 1173664</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173665">SUSE bug 1173665</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914815" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14815</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14815" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14815" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14815" ref_url="https://www.suse.com/security/cve/CVE-2019-14815" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2414-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2651-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192651-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2658-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192658-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2738-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192738-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007367.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2173-1" ref_url="https://lists.opensuse.org/opensuse-updates/2019-09/msg00133.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14815/">CVE-2019-14815</cve>
	<bugzilla href="https://bugzilla.suse.com/1146514">SUSE bug 1146514</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173665">SUSE bug 1173665</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914816" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14816</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14816" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14816" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14816" ref_url="https://www.suse.com/security/cve/CVE-2019-14816" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2414-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2651-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192651-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2658-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192658-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2738-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192738-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007367.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2173-1" ref_url="https://lists.opensuse.org/opensuse-updates/2019-09/msg00133.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html" source="SUSE-SU"/>
    <description>
    There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14816/">CVE-2019-14816</cve>
	<bugzilla href="https://bugzilla.suse.com/1146516">SUSE bug 1146516</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173666">SUSE bug 1173666</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914866" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14866</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14866" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14866" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14866" ref_url="https://www.suse.com/security/cve/CVE-2019-14866" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3064-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006178.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2593-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2596-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00076.html" source="SUSE-SU"/>
    <description>
    In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-14866/">CVE-2019-14866</cve>
	<bugzilla href="https://bugzilla.suse.com/1155199">SUSE bug 1155199</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481843" comment="cpio-2.12-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914889" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14889</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14889" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14889" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14889" ref_url="https://www.suse.com/security/cve/CVE-2019-14889" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:20-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:21-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:22-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:23-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006254.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3307-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006261.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3308-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006263.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006385.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2689-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0102-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00047.html" source="SUSE-SU"/>
    <description>
    A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14889/">CVE-2019-14889</cve>
	<bugzilla href="https://bugzilla.suse.com/1158095">SUSE bug 1158095</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482409" comment="libssh4-0.8.7-10.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914895" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14895</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14895" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14895" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14895" ref_url="https://www.suse.com/security/cve/CVE-2019-14895" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0667-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007355.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007359.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007365.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash) or possibly execute arbitrary code.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14895/">CVE-2019-14895</cve>
	<bugzilla href="https://bugzilla.suse.com/1157042">SUSE bug 1157042</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157158">SUSE bug 1157158</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173100">SUSE bug 1173100</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173660">SUSE bug 1173660</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914896" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14896</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14896" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14896" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14896" ref_url="https://www.suse.com/security/cve/CVE-2019-14896" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14896/">CVE-2019-14896</cve>
	<bugzilla href="https://bugzilla.suse.com/1157157">SUSE bug 1157157</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1160468">SUSE bug 1160468</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914897" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14897</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14897" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14897" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14897" ref_url="https://www.suse.com/security/cve/CVE-2019-14897" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14897/">CVE-2019-14897</cve>
	<bugzilla href="https://bugzilla.suse.com/1157155">SUSE bug 1157155</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1160467">SUSE bug 1160467</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1160468">SUSE bug 1160468</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914898" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14898</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14898" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14898" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14898" ref_url="https://www.suse.com/security/cve/CVE-2019-14898" source="SUSE CVE"/>
    <description>
    The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with mmget_not_zero or get_task_mm calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14898/">CVE-2019-14898</cve>
	<bugzilla href="https://bugzilla.suse.com/1157905">SUSE bug 1157905</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201914901" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-14901</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-14901" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14901" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-14901" ref_url="https://www.suse.com/security/cve/CVE-2019-14901" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007355.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007365.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the code will run with the permissions of root. This will affect both confidentiality and integrity of files on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-14901/">CVE-2019-14901</cve>
	<bugzilla href="https://bugzilla.suse.com/1157042">SUSE bug 1157042</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173661">SUSE bug 1173661</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915030" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15030</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15030" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15030" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15030" ref_url="https://www.suse.com/security/cve/CVE-2019-15030" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2414-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2651-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192651-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2658-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192658-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2738-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192738-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2173-1" ref_url="https://lists.opensuse.org/opensuse-updates/2019-09/msg00133.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbegin) and then accesses vector registers. At some point, the vector registers will be corrupted with the values from a different local Linux process because of a missing arch/powerpc/kernel/process.c check.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-15030/">CVE-2019-15030</cve>
	<bugzilla href="https://bugzilla.suse.com/1149713">SUSE bug 1149713</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915031" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15031</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15031" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15031" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15031" ref_url="https://www.suse.com/security/cve/CVE-2019-15031" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2414-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2651-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192651-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2658-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192658-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2738-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192738-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2173-1" ref_url="https://lists.opensuse.org/opensuse-updates/2019-09/msg00133.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbegin) and then accesses vector registers. At some point, the vector registers will be corrupted with the values from a different local Linux process, because MSR_TM_ACTIVE is misused in arch/powerpc/kernel/process.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-15031/">CVE-2019-15031</cve>
	<bugzilla href="https://bugzilla.suse.com/1149713">SUSE bug 1149713</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915098" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15098</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15098" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15098" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15098" ref_url="https://www.suse.com/security/cve/CVE-2019-15098" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2414-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2651-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192651-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2658-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192658-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2738-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192738-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2173-1" ref_url="https://lists.opensuse.org/opensuse-updates/2019-09/msg00133.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html" source="SUSE-SU"/>
    <description>
    drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.2/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-15098/">CVE-2019-15098</cve>
	<bugzilla href="https://bugzilla.suse.com/1146378">SUSE bug 1146378</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146543">SUSE bug 1146543</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915099" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15099</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15099" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15099" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15099" ref_url="https://www.suse.com/security/cve/CVE-2019-15099" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2658-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192658-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2738-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192738-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html" source="SUSE-SU"/>
    <description>
    drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-15099/">CVE-2019-15099</cve>
	<bugzilla href="https://bugzilla.suse.com/1146368">SUSE bug 1146368</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915126" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15126</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15126" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15126" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15126" ref_url="https://www.suse.com/security/cve/CVE-2019-15126" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1648-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KZGJOQCY3UVCSZY3XFCDUYHPVWB2IH7T/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-27"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="3.1/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-15126/">CVE-2019-15126</cve>
	<bugzilla href="https://bugzilla.suse.com/1167162">SUSE bug 1167162</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009658281" comment="kernel-firmware-20200107-3.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658282" comment="ucode-amd-20200107-3.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915223" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15223</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15223" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15223" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15223" ref_url="https://www.suse.com/security/cve/CVE-2019-15223" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/driver.c driver.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-15223/">CVE-2019-15223</cve>
	<bugzilla href="https://bugzilla.suse.com/1146519">SUSE bug 1146519</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146535">SUSE bug 1146535</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915290" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15290</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15290" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15290" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15290" ref_url="https://www.suse.com/security/cve/CVE-2019-15290" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2414-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2651-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192651-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2658-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192658-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2738-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192738-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2173-1" ref_url="https://lists.opensuse.org/opensuse-updates/2019-09/msg00133.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2181-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00066.html" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15098. Reason: This candidate is a duplicate of CVE-2019-15098. Notes: All CVE users should reference CVE-2019-15098 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.2/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-15290/">CVE-2019-15290</cve>
	<bugzilla href="https://bugzilla.suse.com/1146378">SUSE bug 1146378</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146519">SUSE bug 1146519</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146543">SUSE bug 1146543</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915291" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15291</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15291" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15291" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15291" ref_url="https://www.suse.com/security/cve/CVE-2019-15291" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2651-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192651-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2658-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192658-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2706-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192706-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2307-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2308-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00036.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-15291/">CVE-2019-15291</cve>
	<bugzilla href="https://bugzilla.suse.com/1146519">SUSE bug 1146519</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146540">SUSE bug 1146540</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20191543" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-1543</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-1543" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1543" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-1543" ref_url="https://www.suse.com/security/cve/CVE-2019-1543" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005214.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005259.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1147-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1814-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html" source="SUSE-SU"/>
    <description>
    ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and front pads the nonce with 0 bytes if it is less than 12 bytes. However it also incorrectly allows a nonce to be set of up to 16 bytes. In this case only the last 12 bytes are significant and any additional leading bytes are ignored. It is a requirement of using this cipher that nonce values are unique. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks. If an application changes the default nonce length to be longer than 12 bytes and then makes a change to the leading bytes of the nonce expecting the new value to be a new unique nonce then such an application could inadvertently encrypt messages with a reused nonce. Additionally the ignored bytes in a long nonce are not covered by the integrity guarantee of this cipher. Any application that relies on the integrity of these ignored leading bytes of a long nonce may be further affected. Any OpenSSL internal use of this cipher, including in SSL/TLS, is safe because no such use sets such a long nonce value. However user applications that use this cipher directly and set a non-default nonce length to be longer than 12 bytes may be vulnerable. OpenSSL versions 1.1.1 and 1.1.0 are affected by this issue. Due to the limited scope of affected deployments this has been assessed as low severity and therefore we are not creating new releases at this time. Fixed in OpenSSL 1.1.1c (Affected 1.1.1-1.1.1b). Fixed in OpenSSL 1.1.0k (Affected 1.1.0-1.1.0j).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-1543/">CVE-2019-1543</cve>
	<bugzilla href="https://bugzilla.suse.com/1128189">SUSE bug 1128189</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1141801">SUSE bug 1141801</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154162">SUSE bug 1154162</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20191547" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-1547</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-1547" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1547" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-1547" ref_url="https://www.suse.com/security/cve/CVE-2019-1547" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14171-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14174-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2397-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2403-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2410-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005939.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005943.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2561-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0099-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006349.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2158-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2189-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2268-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2269-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00016.html" source="SUSE-SU"/>
    <description>
    Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters match a known named curve. If such a curve is used then OpenSSL falls back to non-side channel resistant code paths which may result in full key recovery during an ECDSA signature operation. In order to be vulnerable an attacker would have to have the ability to time the creation of a large number of signatures where explicit parameters with no co-factor present are in use by an application using libcrypto. For the avoidance of doubt libssl is not vulnerable because explicit parameters are never used. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-1547/">CVE-2019-1547</cve>
	<bugzilla href="https://bugzilla.suse.com/1150003">SUSE bug 1150003</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154162">SUSE bug 1154162</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154166">SUSE bug 1154166</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1156430">SUSE bug 1156430</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1161085">SUSE bug 1161085</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205621">SUSE bug 1205621</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20191549" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-1549</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-1549" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1549" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-1549" ref_url="https://www.suse.com/security/cve/CVE-2019-1549" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0099-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006349.html" source="SUSE-SU"/>
    <description>
    OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-1549/">CVE-2019-1549</cve>
	<bugzilla href="https://bugzilla.suse.com/1150247">SUSE bug 1150247</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154162">SUSE bug 1154162</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205621">SUSE bug 1205621</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915504" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15504</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15504" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15504" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15504" ref_url="https://www.suse.com/security/cve/CVE-2019-15504" source="SUSE CVE"/>
    <description>
    drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-15504/">CVE-2019-15504</cve>
	<bugzilla href="https://bugzilla.suse.com/1147116">SUSE bug 1147116</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1185852">SUSE bug 1185852</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20191551" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-1551</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-1551" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1551" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-1551" ref_url="https://www.suse.com/security/cve/CVE-2019-1551" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006328.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006540.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0002-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006297.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0028-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0064-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0069-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0099-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006349.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006529.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0062-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00030.html" source="SUSE-SU"/>
    <description>
    There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-1551/">CVE-2019-1551</cve>
	<bugzilla href="https://bugzilla.suse.com/1158809">SUSE bug 1158809</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205621">SUSE bug 1205621</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20191563" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-1563</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-1563" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1563" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-1563" ref_url="https://www.suse.com/security/cve/CVE-2019-1563" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14171-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14174-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006250.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2397-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2403-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2410-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005939.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005943.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2561-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0099-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006349.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2634-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007427.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2158-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2189-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2268-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2269-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00016.html" source="SUSE-SU"/>
    <description>
    In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-1563/">CVE-2019-1563</cve>
	<bugzilla href="https://bugzilla.suse.com/1150250">SUSE bug 1150250</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154162">SUSE bug 1154162</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1156430">SUSE bug 1156430</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205621">SUSE bug 1205621</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915791" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15791</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15791" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15791" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15791" ref_url="https://www.suse.com/security/cve/CVE-2019-15791" source="SUSE CVE"/>
    <description>
    In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additional reference to that file. After the btrfs ioctl completes this fd is closed, which then puts a reference to that file, leading to a refcount underflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-15791/">CVE-2019-15791</cve>
	<bugzilla href="https://bugzilla.suse.com/1156640">SUSE bug 1156640</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915794" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15794</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15794" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15794" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15794" ref_url="https://www.suse.com/security/cve/CVE-2019-15794" source="SUSE CVE"/>
    <description>
    Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma-&gt;vm_file in their mmap handlers. On error the original value is not restored, and the reference is put for the file to which vm_file points. On upstream kernels this is not an issue, as no callers dereference vm_file following after call_mmap() returns an error. However, the aufs patchs change mmap_region() to replace the fput() using a local variable with vma_fput(), which will fput() vm_file, leading to a refcount underflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-15794/">CVE-2019-15794</cve>
	<bugzilla href="https://bugzilla.suse.com/1158156">SUSE bug 1158156</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915845" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15845</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15845" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15845" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15845" ref_url="https://www.suse.com/security/cve/CVE-2019-15845" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html" source="SUSE-SU"/>
    <description>
    Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-15845/">CVE-2019-15845</cve>
	<bugzilla href="https://bugzilla.suse.com/1152994">SUSE bug 1152994</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915890" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15890</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15890" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15890" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15890" ref_url="https://www.suse.com/security/cve/CVE-2019-15890" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2955-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192955-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006934.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008910.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1895-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008990.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
    <description>
    libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.8/CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-15890/">CVE-2019-15890</cve>
	<bugzilla href="https://bugzilla.suse.com/1149811">SUSE bug 1149811</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1149813">SUSE bug 1149813</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704898" comment="qemu-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499897" comment="qemu-arm-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499905" comment="qemu-ipxe-1.0.0+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499911" comment="qemu-seabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499912" comment="qemu-sgabios-8-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704899" comment="qemu-tools-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499916" comment="qemu-vgabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499917" comment="qemu-x86-4.2.1-11.19.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915903" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15903</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15903" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15903" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15903" ref_url="https://www.suse.com/security/cve/CVE-2019-15903" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:616-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2871-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192871-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2872-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192872-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006445.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2204-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00080.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2205-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00081.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2420-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00000.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2424-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2425-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2447-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2451-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2452-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2464-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0010-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-15903/">CVE-2019-15903</cve>
	<bugzilla href="https://bugzilla.suse.com/1149429">SUSE bug 1149429</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154738">SUSE bug 1154738</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154806">SUSE bug 1154806</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481944" comment="libexpat1-2.2.5-3.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915922" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15922</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15922" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15922" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15922" ref_url="https://www.suse.com/security/cve/CVE-2019-15922" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a pf data structure if alloc_disk fails in drivers/block/paride/pf.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-15922/">CVE-2019-15922</cve>
	<bugzilla href="https://bugzilla.suse.com/1149607">SUSE bug 1149607</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915923" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15923</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15923" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15923" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15923" ref_url="https://www.suse.com/security/cve/CVE-2019-15923" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a cd data structure if alloc_disk fails in drivers/block/paride/pf.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-15923/">CVE-2019-15923</cve>
	<bugzilla href="https://bugzilla.suse.com/1149609">SUSE bug 1149609</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201915925" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-15925</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-15925" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15925" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-15925" ref_url="https://www.suse.com/security/cve/CVE-2019-15925" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-18"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-15925/">CVE-2019-15925</cve>
	<bugzilla href="https://bugzilla.suse.com/1149532">SUSE bug 1149532</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916056" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16056</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16056" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16056" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16056" ref_url="https://www.suse.com/security/cve/CVE-2019-16056" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2748-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006125.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006064.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008150.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2393-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2438-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2453-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-16056/">CVE-2019-16056</cve>
	<bugzilla href="https://bugzilla.suse.com/1149955">SUSE bug 1149955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916168" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16168</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16168" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16168" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16168" ref_url="https://www.suse.com/security/cve/CVE-2019-16168" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006426.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006433.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2533-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2298-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2300-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00033.html" source="SUSE-SU"/>
    <description>
    In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-16168/">CVE-2019-16168</cve>
	<bugzilla href="https://bugzilla.suse.com/1150137">SUSE bug 1150137</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1160968">SUSE bug 1160968</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482404" comment="libsqlite3-0-3.28.0-3.9.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916201" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16201</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16201" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16201" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16201" ref_url="https://www.suse.com/security/cve/CVE-2019-16201" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html" source="SUSE-SU"/>
    <description>
    WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the Internet or a untrusted network.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-16201/">CVE-2019-16201</cve>
	<bugzilla href="https://bugzilla.suse.com/1152995">SUSE bug 1152995</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916229" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16229</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16229" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16229" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16229" ref_url="https://www.suse.com/security/cve/CVE-2019-16229" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: The security community disputes this issues as not being serious enough to be deserving a CVE id.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-16229/">CVE-2019-16229</cve>
	<bugzilla href="https://bugzilla.suse.com/1150469">SUSE bug 1150469</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916231" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16231</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16231" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16231" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16231" ref_url="https://www.suse.com/security/cve/CVE-2019-16231" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2503-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00039.html" source="SUSE-SU"/>
    <description>
    drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-16231/">CVE-2019-16231</cve>
	<bugzilla href="https://bugzilla.suse.com/1150466">SUSE bug 1150466</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916232" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16232</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16232" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16232" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16232" ref_url="https://www.suse.com/security/cve/CVE-2019-16232" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2946-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192946-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2947-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192947-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2951-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2952-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2953-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192953-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2392-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2444-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html" source="SUSE-SU"/>
    <description>
    drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-16232/">CVE-2019-16232</cve>
	<bugzilla href="https://bugzilla.suse.com/1150465">SUSE bug 1150465</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916233" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16233</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16233" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16233" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16233" ref_url="https://www.suse.com/security/cve/CVE-2019-16233" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2946-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192946-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2947-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192947-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2951-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2952-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2953-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192953-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2444-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2503-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00035.html" source="SUSE-SU"/>
    <description>
    drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-16233/">CVE-2019-16233</cve>
	<bugzilla href="https://bugzilla.suse.com/1150457">SUSE bug 1150457</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916234" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16234</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16234" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16234" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16234" ref_url="https://www.suse.com/security/cve/CVE-2019-16234" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2946-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192946-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2947-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192947-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2951-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2952-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2953-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192953-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2392-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2444-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html" source="SUSE-SU"/>
    <description>
    drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-16234/">CVE-2019-16234</cve>
	<bugzilla href="https://bugzilla.suse.com/1150452">SUSE bug 1150452</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916254" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16254</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16254" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16254" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16254" ref_url="https://www.suse.com/security/cve/CVE-2019-16254" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html" source="SUSE-SU"/>
    <description>
    Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. NOTE: this issue exists because of an incomplete fix for CVE-2017-17742, which addressed the CRLF vector, but did not address an isolated CR or an isolated LF.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-16254/">CVE-2019-16254</cve>
	<bugzilla href="https://bugzilla.suse.com/1152992">SUSE bug 1152992</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1165402">SUSE bug 1165402</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916255" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16255</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16255" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16255" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16255" ref_url="https://www.suse.com/security/cve/CVE-2019-16255" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html" source="SUSE-SU"/>
    <description>
    Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-16255/">CVE-2019-16255</cve>
	<bugzilla href="https://bugzilla.suse.com/1152990">SUSE bug 1152990</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916275" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16275</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16275" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16275" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16275" ref_url="https://www.suse.com/security/cve/CVE-2019-16275" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008327.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0519-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EXT3Y5NEGCCPGZ7FTYURPUBTHNNJA6MF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0545-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7GHTARPJSUMITH7M3ESWRIZUIYW5UAM6/" source="SUSE-SU"/>
    <description>
    hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-16275/">CVE-2019-16275</cve>
	<bugzilla href="https://bugzilla.suse.com/1150934">SUSE bug 1150934</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916714" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16714</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16714" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16714" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16714" ref_url="https://www.suse.com/security/cve/CVE-2019-16714" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-16714/">CVE-2019-16714</cve>
	<bugzilla href="https://bugzilla.suse.com/1151791">SUSE bug 1151791</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916884" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16884</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16884" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16884" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16884" ref_url="https://www.suse.com/security/cve/CVE-2019-16884" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2786-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192786-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006310.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008717.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2418-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2434-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0045-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00010.html" source="SUSE-SU"/>
    <description>
    runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-16884/">CVE-2019-16884</cve>
	<bugzilla href="https://bugzilla.suse.com/1152308">SUSE bug 1152308</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629072" comment="docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-6.45.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482602" comment="runc-1.0.0~rc10-1.9.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916921" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16921</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16921" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16921" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16921" ref_url="https://www.suse.com/security/cve/CVE-2019-16921" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initialize the resp data structure, which might allow attackers to obtain sensitive information from kernel stack memory, aka CID-df7e40425813.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-16921/">CVE-2019-16921</cve>
	<bugzilla href="https://bugzilla.suse.com/1152516">SUSE bug 1152516</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201916935" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-16935</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-16935" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16935" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-16935" ref_url="https://www.suse.com/security/cve/CVE-2019-16935" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2748-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006125.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008118.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2393-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2438-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2453-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2332-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S3JTHM6LLDKL7VPNRJUSRPNZAD2FZ25H/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2333-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FLGERALYYFTBIX3ZKPM6EQ2WJVUXLOXY/" source="SUSE-SU"/>
    <description>
    The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-16935/">CVE-2019-16935</cve>
	<bugzilla href="https://bugzilla.suse.com/1153238">SUSE bug 1153238</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917006" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17006</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17006" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17006" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17006" ref_url="https://www.suse.com/security/cve/CVE-2019-17006" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:299-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3395-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0088-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200088-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14418-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007069.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0008-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0854-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00047.html" source="SUSE-SU"/>
    <description>
    In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-17006/">CVE-2019-17006</cve>
	<bugzilla href="https://bugzilla.suse.com/1159819">SUSE bug 1159819</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917052" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17052</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17052" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17052" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17052" ref_url="https://www.suse.com/security/cve/CVE-2019-17052" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006135.html" source="SUSE-SU"/>
    <description>
    ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-0614e2b73768.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-17052/">CVE-2019-17052</cve>
	<bugzilla href="https://bugzilla.suse.com/1152779">SUSE bug 1152779</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917053" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17053</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17053" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17053" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17053" ref_url="https://www.suse.com/security/cve/CVE-2019-17053" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006135.html" source="SUSE-SU"/>
    <description>
    ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154 network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-e69dbd4619e7.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-03"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-17053/">CVE-2019-17053</cve>
	<bugzilla href="https://bugzilla.suse.com/1152789">SUSE bug 1152789</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917054" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17054</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17054" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17054" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17054" ref_url="https://www.suse.com/security/cve/CVE-2019-17054" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006135.html" source="SUSE-SU"/>
    <description>
    atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-17054/">CVE-2019-17054</cve>
	<bugzilla href="https://bugzilla.suse.com/1152786">SUSE bug 1152786</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917133" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17133</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17133" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17133" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17133" ref_url="https://www.suse.com/security/cve/CVE-2019-17133" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2829-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192829-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2859-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192859-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2864-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2946-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192946-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2947-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192947-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2951-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2952-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2953-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192953-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006228.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006399.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2392-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2444-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-17133/">CVE-2019-17133</cve>
	<bugzilla href="https://bugzilla.suse.com/1153158">SUSE bug 1153158</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1153161">SUSE bug 1153161</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917346" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17346</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17346" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17346" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17346" ref_url="https://www.suse.com/security/cve/CVE-2019-17346" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006058.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-17346/">CVE-2019-17346</cve>
	<bugzilla href="https://bugzilla.suse.com/1126198">SUSE bug 1126198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917347" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17347</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17347" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17347" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17347" ref_url="https://www.suse.com/security/cve/CVE-2019-17347" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-17347/">CVE-2019-17347</cve>
	<bugzilla href="https://bugzilla.suse.com/1126201">SUSE bug 1126201</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917348" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17348</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17348" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17348" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17348" ref_url="https://www.suse.com/security/cve/CVE-2019-17348" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006058.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service because of an incompatibility between Process Context Identifiers (PCID) and shadow-pagetable switching.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-17348/">CVE-2019-17348</cve>
	<bugzilla href="https://bugzilla.suse.com/1127400">SUSE bug 1127400</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917349" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17349</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17349" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17349" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17349" ref_url="https://www.suse.com/security/cve/CVE-2019-17349" source="SUSE CVE"/>
    <description>
    An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreExcl operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-17349/">CVE-2019-17349</cve>
	<bugzilla href="https://bugzilla.suse.com/1138294">SUSE bug 1138294</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917361" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17361</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17361" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17361" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17361" ref_url="https://www.suse.com/security/cve/CVE-2019-17361" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008325.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0357-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00026.html" source="SUSE-SU"/>
    <description>
    In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-17361/">CVE-2019-17361</cve>
	<bugzilla href="https://bugzilla.suse.com/1162504">SUSE bug 1162504</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917498" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17498</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17498" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17498" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17498" ref_url="https://www.suse.com/security/cve/CVE-2019-17498" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14226-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201914226-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2900-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2900-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2936-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192936-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2483-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00026.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2126-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZ5CXNJKJVQFPMHVDXDS6F67TKZ3TJ7E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2129-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HAQH2P56QS5PVJGYRATVMCCAWSF5JABQ/" source="SUSE-SU"/>
    <description>
    In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-17498/">CVE-2019-17498</cve>
	<bugzilla href="https://bugzilla.suse.com/1154862">SUSE bug 1154862</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1171566">SUSE bug 1171566</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917543" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17543</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17543" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17543" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17543" ref_url="https://www.suse.com/security/cve/CVE-2019-17543" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008776.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2398-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00069.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2399-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00070.html" source="SUSE-SU"/>
    <description>
    LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-17543/">CVE-2019-17543</cve>
	<bugzilla href="https://bugzilla.suse.com/1153936">SUSE bug 1153936</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188549">SUSE bug 1188549</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482293" comment="liblz4-1-1.8.0-3.5.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917594" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17594</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17594" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17594" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17594" ref_url="https://www.suse.com/security/cve/CVE-2019-17594" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:746-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006428.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006435.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006199.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2550-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2551-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00059.html" source="SUSE-SU"/>
    <description>
    There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-17594/">CVE-2019-17594</cve>
	<bugzilla href="https://bugzilla.suse.com/1154036">SUSE bug 1154036</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482311" comment="libncurses6-6.1-5.6.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482314" comment="ncurses-utils-6.1-5.6.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482316" comment="terminfo-6.1-5.6.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482317" comment="terminfo-base-6.1-5.6.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917595" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17595</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17595" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17595" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17595" ref_url="https://www.suse.com/security/cve/CVE-2019-17595" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:746-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006428.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006435.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006199.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2550-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2551-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00059.html" source="SUSE-SU"/>
    <description>
    There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-17595/">CVE-2019-17595</cve>
	<bugzilla href="https://bugzilla.suse.com/1154037">SUSE bug 1154037</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482311" comment="libncurses6-6.1-5.6.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482314" comment="ncurses-utils-6.1-5.6.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482316" comment="terminfo-6.1-5.6.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482317" comment="terminfo-base-6.1-5.6.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201917666" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-17666</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-17666" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17666" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-17666" ref_url="https://www.suse.com/security/cve/CVE-2019-17666" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2946-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192946-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2947-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192947-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2949-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2951-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2952-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2953-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192953-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2392-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2444-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00010.html" source="SUSE-SU"/>
    <description>
    rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-17666/">CVE-2019-17666</cve>
	<bugzilla href="https://bugzilla.suse.com/1154372">SUSE bug 1154372</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918197" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18197</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18197" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18197" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18197" ref_url="https://www.suse.com/security/cve/CVE-2019-18197" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0920-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006675.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0920-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007307.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1409-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006855.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0189-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0210-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0731-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html" source="SUSE-SU"/>
    <description>
    In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18197/">CVE-2019-18197</cve>
	<bugzilla href="https://bugzilla.suse.com/1154609">SUSE bug 1154609</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157028">SUSE bug 1157028</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1162833">SUSE bug 1162833</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1169511">SUSE bug 1169511</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190108">SUSE bug 1190108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482467" comment="libxslt1-1.1.32-3.8.24 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918198" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18198</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18198" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18198" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18198" ref_url="https://www.suse.com/security/cve/CVE-2019-18198" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18198/">CVE-2019-18198</cve>
	<bugzilla href="https://bugzilla.suse.com/1154617">SUSE bug 1154617</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918218" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18218</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18218" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18218" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18218" ref_url="https://www.suse.com/security/cve/CVE-2019-18218" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009407.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009408.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009409.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009396.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0677-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00044.html" source="SUSE-SU"/>
    <description>
    cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18218/">CVE-2019-18218</cve>
	<bugzilla href="https://bugzilla.suse.com/1154661">SUSE bug 1154661</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190368">SUSE bug 1190368</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191838">SUSE bug 1191838</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628435" comment="file-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628437" comment="file-magic-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628438" comment="libmagic1-5.32-7.11.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918224" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18224</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18224" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18224" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18224" ref_url="https://www.suse.com/security/cve/CVE-2019-18224" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006193.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2611-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2613-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00008.html" source="SUSE-SU"/>
    <description>
    idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-18224/">CVE-2019-18224</cve>
	<bugzilla href="https://bugzilla.suse.com/1154887">SUSE bug 1154887</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628747" comment="libidn2-0-2.2.0-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918348" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18348</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18348" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18348" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18348" ref_url="https://www.suse.com/security/cve/CVE-2019-18348" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3228-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013165.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3259-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013170.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013231.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3378-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:500-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1144-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1145-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013286.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0854-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006666.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006878.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3865-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008081.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013149.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2332-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S3JTHM6LLDKL7VPNRJUSRPNZAD2FZ25H/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2333-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FLGERALYYFTBIX3ZKPM6EQ2WJVUXLOXY/" source="SUSE-SU"/>
    <description>
    An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1; v3.6.11, v3.6.11rc1, v3.6.12; v3.7.8, v3.7.8rc1, v3.7.9; v3.8.3, v3.8.3rc1, v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-18348/">CVE-2019-18348</cve>
	<bugzilla href="https://bugzilla.suse.com/1155094">SUSE bug 1155094</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918388" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18388</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18388" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18388" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18388" ref_url="https://www.suse.com/security/cve/CVE-2019-18388" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0016-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0017-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006300.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00028.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-18388/">CVE-2019-18388</cve>
	<bugzilla href="https://bugzilla.suse.com/1159479">SUSE bug 1159479</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009488549" comment="libvirglrenderer0-0.6.0-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918389" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18389</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18389" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18389" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18389" ref_url="https://www.suse.com/security/cve/CVE-2019-18389" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0016-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0017-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006300.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00028.html" source="SUSE-SU"/>
    <description>
    A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18389/">CVE-2019-18389</cve>
	<bugzilla href="https://bugzilla.suse.com/1159482">SUSE bug 1159482</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009488549" comment="libvirglrenderer0-0.6.0-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918390" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18390</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18390" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18390" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18390" ref_url="https://www.suse.com/security/cve/CVE-2019-18390" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0016-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0017-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006300.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00028.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-18390/">CVE-2019-18390</cve>
	<bugzilla href="https://bugzilla.suse.com/1159478">SUSE bug 1159478</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009488549" comment="libvirglrenderer0-0.6.0-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918391" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18391</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18391" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18391" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18391" ref_url="https://www.suse.com/security/cve/CVE-2019-18391" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0016-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0017-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006300.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0058-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00028.html" source="SUSE-SU"/>
    <description>
    A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18391/">CVE-2019-18391</cve>
	<bugzilla href="https://bugzilla.suse.com/1159486">SUSE bug 1159486</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009488549" comment="libvirglrenderer0-0.6.0-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918397" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18397</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18397" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18397" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18397" ref_url="https://www.suse.com/security/cve/CVE-2019-18397" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008796.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0763-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GPZ3M35XR5IQLIBDLZFFWGW6Z6SM7YNW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NAPU2NE5KWWCW4NS2FW7DLCSMM442VDM/" source="SUSE-SU"/>
    <description>
    A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses FriBidi for text layout calculations. Examples include any GNOME or GTK+ based application that uses Pango for text layout, as this internally uses FriBidi for bidirectional text layout. For example, the attacker can construct a crafted text file to be opened in GEdit, or a crafted IRC message to be viewed in HexChat.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18397/">CVE-2019-18397</cve>
	<bugzilla href="https://bugzilla.suse.com/1156260">SUSE bug 1156260</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704876" comment="libfribidi0-1.0.5-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918424" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18424</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18424" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18424" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18424" ref_url="https://www.suse.com/security/cve/CVE-2019-18424" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2961-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192961-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006253.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0334-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007221.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2506-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00037.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI device is assigned to an untrusted domain, it is possible for that domain to program the device to DMA to an arbitrary address. The IOMMU is used to protect the host from malicious DMA by making sure that the device addresses can only target memory assigned to the guest. However, when the guest domain is torn down, or the device is deassigned, the device is assigned back to dom0, thus allowing any in-flight DMA to potentially target critical host data. An untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation. Only systems where guests are given direct access to physical devices capable of DMA (PCI pass-through) are vulnerable. Systems which do not use PCI pass-through are not vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.6/CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18424/">CVE-2019-18424</cve>
	<bugzilla href="https://bugzilla.suse.com/1154461">SUSE bug 1154461</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918634" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18634</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18634" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18634" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18634" ref_url="https://www.suse.com/security/cve/CVE-2019-18634" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0390-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0409-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006492.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0244-1" ref_url="https://lists.opensuse.org/opensuse-updates/2020-02/msg00091.html" source="SUSE-SU"/>
    <description>
    In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an administrator.) The attacker needs to deliver a long string to the stdin of getln() in tgetpass.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18634/">CVE-2019-18634</cve>
	<bugzilla href="https://bugzilla.suse.com/1162202">SUSE bug 1162202</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760863" comment="sudo-1.8.22-4.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918660" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18660</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18660" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18660" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18660" ref_url="https://www.suse.com/security/cve/CVE-2019-18660" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-18660/">CVE-2019-18660</cve>
	<bugzilla href="https://bugzilla.suse.com/1157038">SUSE bug 1157038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157923">SUSE bug 1157923</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918675" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18675</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18675" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18675" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18675" ref_url="https://www.suse.com/security/cve/CVE-2019-18675" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
    <description>
    The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18675/">CVE-2019-18675</cve>
	<bugzilla href="https://bugzilla.suse.com/1157804">SUSE bug 1157804</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918680" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18680</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18680" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18680" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18680" ref_url="https://www.suse.com/security/cve/CVE-2019-18680" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007364.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_sock() in net/rds/tcp.c that will cause denial of service, aka CID-91573ae4aed0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-18680/">CVE-2019-18680</cve>
	<bugzilla href="https://bugzilla.suse.com/1155898">SUSE bug 1155898</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173867">SUSE bug 1173867</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918683" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18683</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18683" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18683" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18683" ref_url="https://www.suse.com/security/cve/CVE-2019-18683" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem). These issues are caused by wrong mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(), sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these race conditions leads to a use-after-free.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18683/">CVE-2019-18683</cve>
	<bugzilla href="https://bugzilla.suse.com/1155897">SUSE bug 1155897</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173868">SUSE bug 1173868</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918786" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18786</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18786" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18786" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18786" ref_url="https://www.suse.com/security/cve/CVE-2019-18786" source="SUSE CVE"/>
    <description>
    In the Linux kernel through 5.3.8, f-&gt;fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could cause a memory disclosure problem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-18786/">CVE-2019-18786</cve>
	<bugzilla href="https://bugzilla.suse.com/1156043">SUSE bug 1156043</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918802" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18802</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18802" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18802" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18802" ref_url="https://www.suse.com/security/cve/CVE-2019-18802" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006631.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0722-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006902.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0379-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0341-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XIUODYDMMPC4VZZIR4DRKRPVXGPEDZRO/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18802/">CVE-2019-18802</cve>
	<bugzilla href="https://bugzilla.suse.com/1159003">SUSE bug 1159003</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482322" comment="libnghttp2-14-1.40.0-1.15 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918807" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18807</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18807" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18807" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18807" ref_url="https://www.suse.com/security/cve/CVE-2019-18807" source="SUSE CVE"/>
    <description>
    Two memory leaks in the sja1105_static_config_upload() function in drivers/net/dsa/sja1105/sja1105_spi.c in the Linux kernel before 5.3.5 allow attackers to cause a denial of service (memory consumption) by triggering static_config_buf_prepare_for_upload() or sja1105_inhibit_tx() failures, aka CID-68501df92d11.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-18807/">CVE-2019-18807</cve>
	<bugzilla href="https://bugzilla.suse.com/1160881">SUSE bug 1160881</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918808" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18808</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18808" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18808" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18808" ref_url="https://www.suse.com/security/cve/CVE-2019-18808" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-18808/">CVE-2019-18808</cve>
	<bugzilla href="https://bugzilla.suse.com/1156259">SUSE bug 1156259</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189884">SUSE bug 1189884</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190534">SUSE bug 1190534</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918809" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18809</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18809" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18809" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18809" ref_url="https://www.suse.com/security/cve/CVE-2019-18809" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-18809/">CVE-2019-18809</cve>
	<bugzilla href="https://bugzilla.suse.com/1156258">SUSE bug 1156258</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918810" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18810</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18810" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18810" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18810" ref_url="https://www.suse.com/security/cve/CVE-2019-18810" source="SUSE CVE"/>
    <description>
    A memory leak in the komeda_wb_connector_add() function in drivers/gpu/drm/arm/display/komeda/komeda_wb_connector.c in the Linux kernel before 5.3.8 allows attackers to cause a denial of service (memory consumption) by triggering drm_writeback_connector_init() failures, aka CID-a0ecd6fdbf5d.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-18810/">CVE-2019-18810</cve>
	<bugzilla href="https://bugzilla.suse.com/1156257">SUSE bug 1156257</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918811" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18811</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18811" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18811" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18811" ref_url="https://www.suse.com/security/cve/CVE-2019-18811" source="SUSE CVE"/>
    <description>
    A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-18811/">CVE-2019-18811</cve>
	<bugzilla href="https://bugzilla.suse.com/1159374">SUSE bug 1159374</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918812" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18812</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18812" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18812" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18812" ref_url="https://www.suse.com/security/cve/CVE-2019-18812" source="SUSE CVE"/>
    <description>
    A memory leak in the sof_dfsentry_write() function in sound/soc/sof/debug.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-c0a333d842ef.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-18812/">CVE-2019-18812</cve>
	<bugzilla href="https://bugzilla.suse.com/1156277">SUSE bug 1156277</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918813" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18813</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18813" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18813" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18813" ref_url="https://www.suse.com/security/cve/CVE-2019-18813" source="SUSE CVE"/>
    <description>
    A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering platform_device_add_properties() failures, aka CID-9bbfceea12a8.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-18813/">CVE-2019-18813</cve>
	<bugzilla href="https://bugzilla.suse.com/1156278">SUSE bug 1156278</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918814" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18814</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18814" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18814" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18814" ref_url="https://www.suse.com/security/cve/CVE-2019-18814" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/apparmor/audit.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-18814/">CVE-2019-18814</cve>
	<bugzilla href="https://bugzilla.suse.com/1156256">SUSE bug 1156256</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918874" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18874</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18874" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18874" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18874" ref_url="https://www.suse.com/security/cve/CVE-2019-18874" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1901-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007124.html" source="SUSE-SU"/>
    <description>
    psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-10-05"/>
	<updated date="2023-10-05"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-18874/">CVE-2019-18874</cve>
	<bugzilla href="https://bugzilla.suse.com/1156525">SUSE bug 1156525</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655560" comment="python3-psutil is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918885" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18885</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18885" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18885" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18885" ref_url="https://www.suse.com/security/cve/CVE-2019-18885" source="SUSE CVE"/>
    <description>
    fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents NULL pointer dereference via a crafted btrfs image because fs_devices-&gt;devices is mishandled within find_device, aka CID-09ba3bc9dd15.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-18885/">CVE-2019-18885</cve>
	<bugzilla href="https://bugzilla.suse.com/1156901">SUSE bug 1156901</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918897" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18897</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18897" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18897" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18897" ref_url="https://www.suse.com/security/cve/CVE-2019-18897" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007158.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0357-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00026.html" source="SUSE-SU"/>
    <description>
    A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 2019.2.0-6.21.1 and prior versions. openSUSE Factory salt-master version 2019.2.2-3.1 and prior versions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-18897/">CVE-2019-18897</cve>
	<bugzilla href="https://bugzilla.suse.com/1157465">SUSE bug 1157465</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918900" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18900</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18900" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18900" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18900" ref_url="https://www.suse.com/security/cve/CVE-2019-18900" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:62-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006336.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006338.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0023-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0079-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006333.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0432-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007791.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0255-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00036.html" source="SUSE-SU"/>
    <description>
    : Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1. SUSE Linux Enterprise Server 15 17.19.0-3.34.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-07-29"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-18900/">CVE-2019-18900</cve>
	<bugzilla href="https://bugzilla.suse.com/1158763">SUSE bug 1158763</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760839" comment="libzypp-17.25.6-3.28.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009373564" comment="zypper is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009654588" comment="zypper-needs-restarting is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918902" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18902</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18902" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18902" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18902" ref_url="https://www.suse.com/security/cve/CVE-2019-18902" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006416.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0369-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0410-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006499.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0165-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00005.html" source="SUSE-SU"/>
    <description>
    A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-3.21.1. openSUSE Leap 15.1 wicked versions prior to 0.6.60-lp151.2.6.1. openSUSE Factory wicked versions prior to 0.6.62.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-18902/">CVE-2019-18902</cve>
	<bugzilla href="https://bugzilla.suse.com/1160903">SUSE bug 1160903</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760866" comment="wicked-0.6.64-3.3.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760867" comment="wicked-service-0.6.64-3.3.4 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201918903" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-18903</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-18903" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18903" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-18903" ref_url="https://www.suse.com/security/cve/CVE-2019-18903" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0369-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0410-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006499.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0207-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00011.html" source="SUSE-SU"/>
    <description>
    A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-28.26.1. openSUSE Leap 15.1 wicked versions prior to 0.6.60-lp151.2.9.1. openSUSE Factory wicked versions prior to 0.6.62.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-18903/">CVE-2019-18903</cve>
	<bugzilla href="https://bugzilla.suse.com/1160904">SUSE bug 1160904</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760866" comment="wicked-0.6.64-3.3.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760867" comment="wicked-service-0.6.64-3.3.4 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919037" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19037</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19037" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19037" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19037" ref_url="https://www.suse.com/security/cve/CVE-2019-19037" source="SUSE CVE"/>
    <description>
    ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can be zero.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19037/">CVE-2019-19037</cve>
	<bugzilla href="https://bugzilla.suse.com/1157717">SUSE bug 1157717</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919039" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19039</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19039" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19039" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19039" ref_url="https://www.suse.com/security/cve/CVE-2019-19039" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS development team disputes this issues as not being a vulnerability because “1) The kernel provide facilities to restrict access to dmesg - dmesg_restrict=1 sysctl option. So it's really up to the system administrator to judge whether dmesg access shall be disallowed or not. 2) WARN/WARN_ON are widely used macros in the linux kernel. If this CVE is considered valid this would mean there are literally thousands CVE lurking in the kernel - something which clearly is not the case.”
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-19039/">CVE-2019-19039</cve>
	<bugzilla href="https://bugzilla.suse.com/1157719">SUSE bug 1157719</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919043" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19043</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19043" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19043" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19043" ref_url="https://www.suse.com/security/cve/CVE-2019-19043" source="SUSE CVE"/>
    <description>
    A memory leak in the i40e_setup_macvlans() function in drivers/net/ethernet/intel/i40e/i40e_main.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering i40e_setup_channel() failures, aka CID-27d461333459.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19043/">CVE-2019-19043</cve>
	<bugzilla href="https://bugzilla.suse.com/1159375">SUSE bug 1159375</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919044" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19044</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19044" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19044" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19044" ref_url="https://www.suse.com/security/cve/CVE-2019-19044" source="SUSE CVE"/>
    <description>
    Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering kcalloc() or v3d_job_init() failures, aka CID-29cd13cfd762.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19044/">CVE-2019-19044</cve>
	<bugzilla href="https://bugzilla.suse.com/1159370">SUSE bug 1159370</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919045" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19045</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19045" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19045" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19045" ref_url="https://www.suse.com/security/cve/CVE-2019-19045" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19045/">CVE-2019-19045</cve>
	<bugzilla href="https://bugzilla.suse.com/1161522">SUSE bug 1161522</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919046" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19046</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19046" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19046" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19046" ref_url="https://www.suse.com/security/cve/CVE-2019-19046" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20. NOTE: third parties dispute the relevance of this because an attacker cannot realistically control this failure at probe time.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19046/">CVE-2019-19046</cve>
	<bugzilla href="https://bugzilla.suse.com/1157304">SUSE bug 1157304</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919047" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19047</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19047" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19047" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19047" ref_url="https://www.suse.com/security/cve/CVE-2019-19047" source="SUSE CVE"/>
    <description>
    A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_crdump_collect() failures, aka CID-c7ed6d0183d5.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="1.9/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19047/">CVE-2019-19047</cve>
	<bugzilla href="https://bugzilla.suse.com/1157715">SUSE bug 1157715</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919048" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19048</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19048" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19048" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19048" ref_url="https://www.suse.com/security/cve/CVE-2019-19048" source="SUSE CVE"/>
    <description>
    A memory leak in the crypto_reportstat() function in drivers/virt/vboxguest/vboxguest_utils.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering copy_form_user() failures, aka CID-e0b0cb938864.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19048/">CVE-2019-19048</cve>
	<bugzilla href="https://bugzilla.suse.com/1157720">SUSE bug 1157720</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919049" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19049</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19049" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19049" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19049" ref_url="https://www.suse.com/security/cve/CVE-2019-19049" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a. NOTE: third parties dispute the relevance of this because unittest.c can only be reached during boot.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="1.6/CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19049/">CVE-2019-19049</cve>
	<bugzilla href="https://bugzilla.suse.com/1157173">SUSE bug 1157173</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919050" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19050</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19050" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19050" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19050" ref_url="https://www.suse.com/security/cve/CVE-2019-19050" source="SUSE CVE"/>
    <description>
    A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19050/">CVE-2019-19050</cve>
	<bugzilla href="https://bugzilla.suse.com/1157336">SUSE bug 1157336</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919051" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19051</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19051" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19051" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19051" ref_url="https://www.suse.com/security/cve/CVE-2019-19051" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc7.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19051/">CVE-2019-19051</cve>
	<bugzilla href="https://bugzilla.suse.com/1159024">SUSE bug 1159024</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919052" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19052</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19052" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19052" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19052" ref_url="https://www.suse.com/security/cve/CVE-2019-19052" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19052/">CVE-2019-19052</cve>
	<bugzilla href="https://bugzilla.suse.com/1157324">SUSE bug 1157324</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919053" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19053</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19053" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19053" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19053" ref_url="https://www.suse.com/security/cve/CVE-2019-19053" source="SUSE CVE"/>
    <description>
    A memory leak in the rpmsg_eptdev_write_iter() function in drivers/rpmsg/rpmsg_char.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering copy_from_iter_full() failures, aka CID-bbe692e349e2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19053/">CVE-2019-19053</cve>
	<bugzilla href="https://bugzilla.suse.com/1161520">SUSE bug 1161520</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919054" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19054</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19054" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19054" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19054" ref_url="https://www.suse.com/security/cve/CVE-2019-19054" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42b.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="2.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19054/">CVE-2019-19054</cve>
	<bugzilla href="https://bugzilla.suse.com/1161518">SUSE bug 1161518</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919055" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19055</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19055" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19055" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19055" ref_url="https://www.suse.com/security/cve/CVE-2019-19055" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering nl80211hdr_put() failures, aka CID-1399c59fa929. NOTE: third parties dispute the relevance of this because it occurs on a code path where a successful allocation has already occurred.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19055/">CVE-2019-19055</cve>
	<bugzilla href="https://bugzilla.suse.com/1157319">SUSE bug 1157319</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919056" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19056</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19056" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19056" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19056" ref_url="https://www.suse.com/security/cve/CVE-2019-19056" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19056/">CVE-2019-19056</cve>
	<bugzilla href="https://bugzilla.suse.com/1157197">SUSE bug 1157197</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919057" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19057</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19057" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19057" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19057" ref_url="https://www.suse.com/security/cve/CVE-2019-19057" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19057/">CVE-2019-19057</cve>
	<bugzilla href="https://bugzilla.suse.com/1157193">SUSE bug 1157193</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157197">SUSE bug 1157197</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919058" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19058</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19058" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19058" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19058" ref_url="https://www.suse.com/security/cve/CVE-2019-19058" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19058/">CVE-2019-19058</cve>
	<bugzilla href="https://bugzilla.suse.com/1157145">SUSE bug 1157145</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919059" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19059</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19059" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19059" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19059" ref_url="https://www.suse.com/security/cve/CVE-2019-19059" source="SUSE CVE"/>
    <description>
    Multiple memory leaks in the iwl_pcie_ctxt_info_gen3_init() function in drivers/net/wireless/intel/iwlwifi/pcie/ctxt-info-gen3.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering iwl_pcie_init_fw_sec() or dma_alloc_coherent() failures, aka CID-0f4f199443fa.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-04"/>
	<updated date="2023-08-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19059/">CVE-2019-19059</cve>
	<bugzilla href="https://bugzilla.suse.com/1157296">SUSE bug 1157296</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919060" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19060</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19060" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19060" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19060" ref_url="https://www.suse.com/security/cve/CVE-2019-19060" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-ab612b1daf41.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19060/">CVE-2019-19060</cve>
	<bugzilla href="https://bugzilla.suse.com/1157178">SUSE bug 1157178</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919061" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19061</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19061" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19061" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19061" ref_url="https://www.suse.com/security/cve/CVE-2019-19061" source="SUSE CVE"/>
    <description>
    A memory leak in the adis_update_scan_mode_burst() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-9c0530e898f3.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19061/">CVE-2019-19061</cve>
	<bugzilla href="https://bugzilla.suse.com/1157192">SUSE bug 1157192</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919062" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19062</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19062" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19062" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19062" ref_url="https://www.suse.com/security/cve/CVE-2019-19062" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19062/">CVE-2019-19062</cve>
	<bugzilla href="https://bugzilla.suse.com/1157333">SUSE bug 1157333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919063" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19063</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19063" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19063" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19063" ref_url="https://www.suse.com/security/cve/CVE-2019-19063" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption), aka CID-3f9361695113.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19063/">CVE-2019-19063</cve>
	<bugzilla href="https://bugzilla.suse.com/1157298">SUSE bug 1157298</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919064" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19064</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19064" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19064" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19064" ref_url="https://www.suse.com/security/cve/CVE-2019-19064" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** A memory leak in the fsl_lpspi_probe() function in drivers/spi/spi-fsl-lpspi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering pm_runtime_get_sync() failures, aka CID-057b8945f78f. NOTE: third parties dispute the relevance of this because an attacker cannot realistically control these failures at probe time.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="1.6/CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19064/">CVE-2019-19064</cve>
	<bugzilla href="https://bugzilla.suse.com/1157300">SUSE bug 1157300</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919065" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19065</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19065" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19065" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19065" ref_url="https://www.suse.com/security/cve/CVE-2019-19065" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering rhashtable_init() failures, aka CID-34b3be18a04e. NOTE: This has been disputed as not a vulnerability because "rhashtable_init() can only fail if it is passed invalid values in the second parameter's struct, but when invoked from sdma_init() that is a pointer to a static const struct, so an attacker could only trigger failure if they could corrupt kernel memory (in which case a small memory leak is not a significant problem)."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19065/">CVE-2019-19065</cve>
	<bugzilla href="https://bugzilla.suse.com/1157191">SUSE bug 1157191</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173961">SUSE bug 1173961</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919066" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19066</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19066" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19066" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19066" ref_url="https://www.suse.com/security/cve/CVE-2019-19066" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19066/">CVE-2019-19066</cve>
	<bugzilla href="https://bugzilla.suse.com/1157303">SUSE bug 1157303</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919067" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19067</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19067" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19067" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19067" ref_url="https://www.suse.com/security/cve/CVE-2019-19067" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices() or pm_genpd_add_device() failures, aka CID-57be09c6e874. NOTE: third parties dispute the relevance of this because the attacker must already have privileges for module loading.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19067/">CVE-2019-19067</cve>
	<bugzilla href="https://bugzilla.suse.com/1157180">SUSE bug 1157180</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919068" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19068</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19068" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19068" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19068" ref_url="https://www.suse.com/security/cve/CVE-2019-19068" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19068/">CVE-2019-19068</cve>
	<bugzilla href="https://bugzilla.suse.com/1157307">SUSE bug 1157307</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919069" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19069</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19069" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19069" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19069" ref_url="https://www.suse.com/security/cve/CVE-2019-19069" source="SUSE CVE"/>
    <description>
    A memory leak in the fastrpc_dma_buf_attach() function in drivers/misc/fastrpc.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering dma_get_sgtable() failures, aka CID-fc739a058d99.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19069/">CVE-2019-19069</cve>
	<bugzilla href="https://bugzilla.suse.com/1157064">SUSE bug 1157064</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919070" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19070</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19070" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19070" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19070" ref_url="https://www.suse.com/security/cve/CVE-2019-19070" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** A memory leak in the spi_gpio_probe() function in drivers/spi/spi-gpio.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering devm_add_action_or_reset() failures, aka CID-d3b0ffa1d75d. NOTE: third parties dispute the relevance of this because the system must have already been out of memory before the probe began.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19070/">CVE-2019-19070</cve>
	<bugzilla href="https://bugzilla.suse.com/1157294">SUSE bug 1157294</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919071" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19071</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19071" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19071" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19071" ref_url="https://www.suse.com/security/cve/CVE-2019-19071" source="SUSE CVE"/>
    <description>
    A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19071/">CVE-2019-19071</cve>
	<bugzilla href="https://bugzilla.suse.com/1157067">SUSE bug 1157067</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919072" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19072</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19072" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19072" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19072" ref_url="https://www.suse.com/security/cve/CVE-2019-19072" source="SUSE CVE"/>
    <description>
    A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19072/">CVE-2019-19072</cve>
	<bugzilla href="https://bugzilla.suse.com/1157069">SUSE bug 1157069</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919073" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19073</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19073" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19073" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19073" ref_url="https://www.suse.com/security/cve/CVE-2019-19073" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This affects the htc_config_pipe_credits() function, the htc_setup_complete() function, and the htc_connect_service() function, aka CID-853acf7caf10.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19073/">CVE-2019-19073</cve>
	<bugzilla href="https://bugzilla.suse.com/1157070">SUSE bug 1157070</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919074" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19074</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19074" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19074" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19074" ref_url="https://www.suse.com/security/cve/CVE-2019-19074" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19074/">CVE-2019-19074</cve>
	<bugzilla href="https://bugzilla.suse.com/1157143">SUSE bug 1157143</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919075" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19075</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19075" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19075" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19075" ref_url="https://www.suse.com/security/cve/CVE-2019-19075" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c in the Linux kernel before 5.3.8 allows attackers to cause a denial of service (memory consumption) by triggering ca8210_get_platform_data() failures, aka CID-6402939ec86e.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19075/">CVE-2019-19075</cve>
	<bugzilla href="https://bugzilla.suse.com/1157162">SUSE bug 1157162</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173958">SUSE bug 1173958</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919076" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19076</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19076" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19076" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19076" ref_url="https://www.suse.com/security/cve/CVE-2019-19076" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption), aka CID-78beef629fd9. NOTE: This has been argued as not a valid vulnerability. The upstream commit 78beef629fd9 was reverted.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-08-05"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19076/">CVE-2019-19076</cve>
	<bugzilla href="https://bugzilla.suse.com/1157164">SUSE bug 1157164</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919077" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19077</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19077" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19077" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19077" ref_url="https://www.suse.com/security/cve/CVE-2019-19077" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering copy to udata failures, aka CID-4a9d46a9fe14.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19077/">CVE-2019-19077</cve>
	<bugzilla href="https://bugzilla.suse.com/1157171">SUSE bug 1157171</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919078" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19078</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19078" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19078" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19078" ref_url="https://www.suse.com/security/cve/CVE-2019-19078" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19078/">CVE-2019-19078</cve>
	<bugzilla href="https://bugzilla.suse.com/1157032">SUSE bug 1157032</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919079" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19079</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19079" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19079" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19079" ref_url="https://www.suse.com/security/cve/CVE-2019-19079" source="SUSE CVE"/>
    <description>
    A memory leak in the qrtr_tun_write_iter() function in net/qrtr/tun.c in the Linux kernel before 5.3 allows attackers to cause a denial of service (memory consumption), aka CID-a21b7f0cff19.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19079/">CVE-2019-19079</cve>
	<bugzilla href="https://bugzilla.suse.com/1157039">SUSE bug 1157039</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919080" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19080</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19080" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19080" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19080" ref_url="https://www.suse.com/security/cve/CVE-2019-19080" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    Four memory leaks in the nfp_flower_spawn_phy_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in the Linux kernel before 5.3.4 allow attackers to cause a denial of service (memory consumption), aka CID-8572cea1461a.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19080/">CVE-2019-19080</cve>
	<bugzilla href="https://bugzilla.suse.com/1157044">SUSE bug 1157044</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919081" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19081</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19081" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19081" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19081" ref_url="https://www.suse.com/security/cve/CVE-2019-19081" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    A memory leak in the nfp_flower_spawn_vnic_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in the Linux kernel before 5.3.4 allows attackers to cause a denial of service (memory consumption), aka CID-8ce39eb5a67a.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19081/">CVE-2019-19081</cve>
	<bugzilla href="https://bugzilla.suse.com/1157045">SUSE bug 1157045</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919082" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19082</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19082" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19082" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19082" ref_url="https://www.suse.com/security/cve/CVE-2019-19082" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption). This affects the dce120_create_resource_pool() function in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_create_resource_pool() function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, the dce100_create_resource_pool() function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_create_resource_pool() function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, and the dce112_create_resource_pool() function in drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, aka CID-104c307147ad.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19082/">CVE-2019-19082</cve>
	<bugzilla href="https://bugzilla.suse.com/1157046">SUSE bug 1157046</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919083" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19083</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19083" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19083" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19083" ref_url="https://www.suse.com/security/cve/CVE-2019-19083" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013530.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption). This affects the dce112_clock_source_create() function in drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, the dce100_clock_source_create() function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_clock_source_create() function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, the dcn20_clock_source_create() function in drivers/gpu/drm/amd/display/dc/dcn20/dcn20_resource.c, the dce120_clock_source_create() function in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_clock_source_create() function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, and the dce80_clock_source_create() function in drivers/gpu/drm/amd/display/dc/dce80/dce80_resource.c, aka CID-055e547478a1.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19083/">CVE-2019-19083</cve>
	<bugzilla href="https://bugzilla.suse.com/1157049">SUSE bug 1157049</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919126" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19126</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19126" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19126" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19126" ref_url="https://www.suse.com/security/cve/CVE-2019-19126" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006420.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006421.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:33-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006430.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:35-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:39-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006444.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006413.html" source="SUSE-SU"/>
    <description>
    On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-19126/">CVE-2019-19126</cve>
	<bugzilla href="https://bugzilla.suse.com/1157292">SUSE bug 1157292</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919234" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19234</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19234" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19234" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19234" ref_url="https://www.suse.com/security/cve/CVE-2019-19234" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** In Sudo through 1.8.29, the fact that a user has been blocked (e.g., by using the ! character in the shadow file instead of a password hash) is not considered, allowing an attacker (who has access to a Runas ALL sudoer account) to impersonate any blocked user. NOTE: The software maintainer believes that this CVE is not valid. Disabling local password authentication for a user is not the same as disabling all access to that user--the user may still be able to login via other means (ssh key, kerberos, etc). Both the Linux shadow(5) and passwd(1) manuals are clear on this. Indeed it is a valid use case to have local accounts that are _only_ accessible via sudo and that cannot be logged into with a password. Sudo 1.8.30 added an optional setting to check the _shell_ of the target user (not the encrypted password!) against the contents of /etc/shells but that is not the same thing as preventing access to users with an invalid password hash.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-19234/">CVE-2019-19234</cve>
	<bugzilla href="https://bugzilla.suse.com/1159616">SUSE bug 1159616</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334290" comment="sudo is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919241" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19241</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19241" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19241" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19241" ref_url="https://www.suse.com/security/cve/CVE-2019-19241" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabilities, aka CID-181e448d8709. This is related to fs/io-wq.c, fs/io_uring.c, and net/socket.c. For example, an attacker can bypass intended restrictions on adding an IPv4 address to the loopback interface. This occurs because IORING_OP_SENDMSG operations, although requested in the context of an unprivileged user, are sometimes performed by a kernel worker thread without considering that context.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-19241/">CVE-2019-19241</cve>
	<bugzilla href="https://bugzilla.suse.com/1159441">SUSE bug 1159441</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919244" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19244</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19244" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19244" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19244" ref_url="https://www.suse.com/security/cve/CVE-2019-19244" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19244/">CVE-2019-19244</cve>
	<bugzilla href="https://bugzilla.suse.com/1157817">SUSE bug 1157817</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157818">SUSE bug 1157818</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919252" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19252</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19252" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19252" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19252" ref_url="https://www.suse.com/security/cve/CVE-2019-19252" source="SUSE CVE"/>
    <description>
    vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through 5.3.13 does not prevent write access to vcsu devices, aka CID-0c9acb1af77a.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19252/">CVE-2019-19252</cve>
	<bugzilla href="https://bugzilla.suse.com/1157813">SUSE bug 1157813</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919317" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19317</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19317" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19317" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19317" ref_url="https://www.suse.com/security/cve/CVE-2019-19317" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-19317/">CVE-2019-19317</cve>
	<bugzilla href="https://bugzilla.suse.com/1158812">SUSE bug 1158812</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196773">SUSE bug 1196773</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196775">SUSE bug 1196775</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919332" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19332</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19332" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19332" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19332" ref_url="https://www.suse.com/security/cve/CVE-2019-19332" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or process able to access the '/dev/kvm' device could use this flaw to crash the system, resulting in a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-19332/">CVE-2019-19332</cve>
	<bugzilla href="https://bugzilla.suse.com/1158827">SUSE bug 1158827</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919338" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19338</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19338" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19338" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19338" ref_url="https://www.suse.com/security/cve/CVE-2019-19338" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (TAA) error occurs. When a guest is running on a host CPU affected by the TAA flaw (TAA_NO=0), but is not affected by the MDS issue (MDS_NO=1), the guest was to clear the affected buffers by using a VERW instruction mechanism. But when the MDS_NO=1 bit was exported to the guests, the guests did not use the VERW mechanism to clear the affected buffers. This issue affects guests running on Cascade Lake CPUs and requires that host has 'TSX' enabled. Confidentiality of data is the highest threat associated with this vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-19338/">CVE-2019-19338</cve>
	<bugzilla href="https://bugzilla.suse.com/1158954">SUSE bug 1158954</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919378" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19378</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19378" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19378" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19378" ref_url="https://www.suse.com/security/cve/CVE-2019-19378" source="SUSE CVE"/>
    <description>
    In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-19378/">CVE-2019-19378</cve>
	<bugzilla href="https://bugzilla.suse.com/1158270">SUSE bug 1158270</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1185853">SUSE bug 1185853</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919447" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19447</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19447" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19447" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19447" ref_url="https://www.suse.com/security/cve/CVE-2019-19447" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007355.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007359.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007365.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-19447/">CVE-2019-19447</cve>
	<bugzilla href="https://bugzilla.suse.com/1158819">SUSE bug 1158819</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173869">SUSE bug 1173869</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919448" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19448</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19448" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19448" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19448" ref_url="https://www.suse.com/security/cve/CVE-2019-19448" source="SUSE CVE"/>
    <description>
    In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-19448/">CVE-2019-19448</cve>
	<bugzilla href="https://bugzilla.suse.com/1158820">SUSE bug 1158820</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1162369">SUSE bug 1162369</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173871">SUSE bug 1173871</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919449" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19449</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19449" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19449" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19449" ref_url="https://www.suse.com/security/cve/CVE-2019-19449" source="SUSE CVE"/>
    <description>
    In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2019-19449/">CVE-2019-19449</cve>
	<bugzilla href="https://bugzilla.suse.com/1158821">SUSE bug 1158821</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919462" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19462</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19462" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19462" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19462" ref_url="https://www.suse.com/security/cve/CVE-2019-19462" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19462/">CVE-2019-19462</cve>
	<bugzilla href="https://bugzilla.suse.com/1158265">SUSE bug 1158265</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919523" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19523</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19523" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19523" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19523" ref_url="https://www.suse.com/security/cve/CVE-2019-19523" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2019-19523/">CVE-2019-19523</cve>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158823">SUSE bug 1158823</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919524" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19524</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19524" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19524" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19524" ref_url="https://www.suse.com/security/cve/CVE-2019-19524" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.3.12, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/input/ff-memless.c driver, aka CID-fa3a5a1880c9.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.4/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19524/">CVE-2019-19524</cve>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158413">SUSE bug 1158413</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919525" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19525</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19525" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19525" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19525" ref_url="https://www.suse.com/security/cve/CVE-2019-19525" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.3.6, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/ieee802154/atusb.c driver, aka CID-7fd25e6fc035.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-19525/">CVE-2019-19525</cve>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158417">SUSE bug 1158417</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919526" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19526</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19526" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19526" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19526" ref_url="https://www.suse.com/security/cve/CVE-2019-19526" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.3.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/nfc/pn533/usb.c driver, aka CID-6af3aa57a098.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19526/">CVE-2019-19526</cve>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158893">SUSE bug 1158893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919528" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19528</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19528" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19528" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19528" ref_url="https://www.suse.com/security/cve/CVE-2019-19528" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver, aka CID-edc4746f253d.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-19528/">CVE-2019-19528</cve>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158407">SUSE bug 1158407</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919529" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19529</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19529" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19529" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19529" ref_url="https://www.suse.com/security/cve/CVE-2019-19529" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.3.11, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c driver, aka CID-4d6636498c41.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19529/">CVE-2019-19529</cve>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919532" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19532</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19532" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19532" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19532" ref_url="https://www.suse.com/security/cve/CVE-2019-19532" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.3.9, there are multiple out-of-bounds write bugs that can be caused by a malicious USB device in the Linux kernel HID drivers, aka CID-d9d4b1e46d95. This affects drivers/hid/hid-axff.c, drivers/hid/hid-dr.c, drivers/hid/hid-emsff.c, drivers/hid/hid-gaff.c, drivers/hid/hid-holtekff.c, drivers/hid/hid-lg2ff.c, drivers/hid/hid-lg3ff.c, drivers/hid/hid-lg4ff.c, drivers/hid/hid-lgff.c, drivers/hid/hid-logitech-hidpp.c, drivers/hid/hid-microsoft.c, drivers/hid/hid-sony.c, drivers/hid/hid-tmff.c, and drivers/hid/hid-zpff.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-19532/">CVE-2019-19532</cve>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158823">SUSE bug 1158823</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158824">SUSE bug 1158824</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919533" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19533</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19533" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19533" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19533" ref_url="https://www.suse.com/security/cve/CVE-2019-19533" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c driver, aka CID-a10feaf8c464.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.4/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-19533/">CVE-2019-19533</cve>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919534" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19534</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19534" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19534" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19534" ref_url="https://www.suse.com/security/cve/CVE-2019-19534" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3372-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20193372-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2675-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00029.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c driver, aka CID-f7a1337f0d29.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.4/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-19534/">CVE-2019-19534</cve>
	<bugzilla href="https://bugzilla.suse.com/1158381">SUSE bug 1158381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158398">SUSE bug 1158398</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1158834">SUSE bug 1158834</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919579" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19579</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19579" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19579" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19579" ref_url="https://www.suse.com/security/cve/CVE-2019-19579" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006253.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006260.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0334-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006956.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these "alternate" methods are used will still leave the system in a vulnerable state after the device comes back from a guest. An untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation. Only systems where guests are given direct access to physical devices capable of DMA (PCI pass-through) are vulnerable. Systems which do not use PCI pass-through are not vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.9/CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-19579/">CVE-2019-19579</cve>
	<bugzilla href="https://bugzilla.suse.com/1157888">SUSE bug 1157888</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919581" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19581</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19581" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19581" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19581" ref_url="https://www.suse.com/security/cve/CVE-2019-19581" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006253.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006260.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0334-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006485.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006956.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bounds access) because certain bit iteration is mishandled. In a number of places bitmaps are being used by the hypervisor to track certain state. Iteration over all bits involves functions which may misbehave in certain corner cases: On 32-bit Arm accesses to bitmaps with bit a count which is a multiple of 32, an out of bounds access may occur. A malicious guest may cause a hypervisor crash or hang, resulting in a Denial of Service (DoS). All versions of Xen are vulnerable. 32-bit Arm systems are vulnerable. 64-bit Arm systems are not vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19581/">CVE-2019-19581</cve>
	<bugzilla href="https://bugzilla.suse.com/1158003">SUSE bug 1158003</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919582" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19582</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19582" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19582" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19582" ref_url="https://www.suse.com/security/cve/CVE-2019-19582" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006253.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006260.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006271.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) because certain bit iteration is mishandled. In a number of places bitmaps are being used by the hypervisor to track certain state. Iteration over all bits involves functions which may misbehave in certain corner cases: On x86 accesses to bitmaps with a compile time known size of 64 may incur undefined behavior, which may in particular result in infinite loops. A malicious guest may cause a hypervisor crash or hang, resulting in a Denial of Service (DoS). All versions of Xen are vulnerable. x86 systems with 64 or more nodes are vulnerable (there might not be any such systems that Xen would run on). x86 systems with less than 64 nodes are not vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19582/">CVE-2019-19582</cve>
	<bugzilla href="https://bugzilla.suse.com/1158003">SUSE bug 1158003</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919602" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19602</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19602" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19602" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19602" ref_url="https://www.suse.com/security/cve/CVE-2019-19602" source="SUSE CVE"/>
    <description>
    fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated by mishandling of signal-based non-cooperative preemption in Go 1.14 prereleases on amd64, aka CID-59c4bd853abc.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-19602/">CVE-2019-19602</cve>
	<bugzilla href="https://bugzilla.suse.com/1158887">SUSE bug 1158887</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919603" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19603</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19603" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19603" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19603" ref_url="https://www.suse.com/security/cve/CVE-2019-19603" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19603/">CVE-2019-19603</cve>
	<bugzilla href="https://bugzilla.suse.com/1158960">SUSE bug 1158960</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193078">SUSE bug 1193078</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919645" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19645</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19645" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19645" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19645" ref_url="https://www.suse.com/security/cve/CVE-2019-19645" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19645/">CVE-2019-19645</cve>
	<bugzilla href="https://bugzilla.suse.com/1158958">SUSE bug 1158958</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919646" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19646</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19646" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19646" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19646" ref_url="https://www.suse.com/security/cve/CVE-2019-19646" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-19646/">CVE-2019-19646</cve>
	<bugzilla href="https://bugzilla.suse.com/1158959">SUSE bug 1158959</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919767" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19767</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19767" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19767" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19767" ref_url="https://www.suse.com/security/cve/CVE-2019-19767" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:3381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0093-1" ref_url="https://www.suse.com/support/update/announcement/2020/suse-su-20200093-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-19767/">CVE-2019-19767</cve>
	<bugzilla href="https://bugzilla.suse.com/1159297">SUSE bug 1159297</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919768" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19768</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19768" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19768" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19768" ref_url="https://www.suse.com/security/cve/CVE-2019-19768" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1085-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006727.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0388-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cpu sub-buffer).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-19768/">CVE-2019-19768</cve>
	<bugzilla href="https://bugzilla.suse.com/1159285">SUSE bug 1159285</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919769" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19769</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19769" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19769" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19769" ref_url="https://www.suse.com/security/cve/CVE-2019-19769" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2019-19769/">CVE-2019-19769</cve>
	<bugzilla href="https://bugzilla.suse.com/1159280">SUSE bug 1159280</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919770" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19770</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19770" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19770" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19770" ref_url="https://www.suse.com/security/cve/CVE-2019-19770" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1085-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006727.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0543-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00035.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_create_file). NOTE: Linux kernel developers dispute this issue as not being an issue with debugfs, instead this is an issue with misuse of debugfs within blktrace.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2019-19770/">CVE-2019-19770</cve>
	<bugzilla href="https://bugzilla.suse.com/1159198">SUSE bug 1159198</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1171295">SUSE bug 1171295</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919807" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19807</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19807" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19807" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19807" ref_url="https://www.suse.com/security/cve/CVE-2019-19807" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for a different purpose after refactoring.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-19807/">CVE-2019-19807</cve>
	<bugzilla href="https://bugzilla.suse.com/1159281">SUSE bug 1159281</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919814" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19814</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19814" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19814" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19814" ref_url="https://www.suse.com/security/cve/CVE-2019-19814" source="SUSE CVE"/>
    <description>
    In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-19814/">CVE-2019-19814</cve>
	<bugzilla href="https://bugzilla.suse.com/1159437">SUSE bug 1159437</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919815" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19815</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19815" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19815" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19815" ref_url="https://www.suse.com/security/cve/CVE-2019-19815" source="SUSE CVE"/>
    <description>
    In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2fs.h.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19815/">CVE-2019-19815</cve>
	<bugzilla href="https://bugzilla.suse.com/1159438">SUSE bug 1159438</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919880" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19880</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19880" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19880" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19880" ref_url="https://www.suse.com/security/cve/CVE-2019-19880" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0189-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0210-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19880/">CVE-2019-19880</cve>
	<bugzilla href="https://bugzilla.suse.com/1159491">SUSE bug 1159491</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1159715">SUSE bug 1159715</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1162833">SUSE bug 1162833</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919921" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19921</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19921" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19921" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19921" ref_url="https://www.suse.com/security/cve/CVE-2019-19921" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2958-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0944-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006685.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008717.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0219-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00018.html" source="SUSE-SU"/>
    <description>
    runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-19921/">CVE-2019-19921</cve>
	<bugzilla href="https://bugzilla.suse.com/1160452">SUSE bug 1160452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208962">SUSE bug 1208962</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629072" comment="docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-6.45.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482602" comment="runc-1.0.0~rc10-1.9.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919922" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19922</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19922" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19922" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19922" ref_url="https://www.suse.com/security/cve/CVE-2019-19922" source="SUSE CVE"/>
    <description>
    kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19922/">CVE-2019-19922</cve>
	<bugzilla href="https://bugzilla.suse.com/1159717">SUSE bug 1159717</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919923" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19923</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19923" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19923" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19923" ref_url="https://www.suse.com/security/cve/CVE-2019-19923" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0189-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0210-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-19923/">CVE-2019-19923</cve>
	<bugzilla href="https://bugzilla.suse.com/1160309">SUSE bug 1160309</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1162833">SUSE bug 1162833</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919924" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19924</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19924" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19924" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19924" ref_url="https://www.suse.com/security/cve/CVE-2019-19924" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-19924/">CVE-2019-19924</cve>
	<bugzilla href="https://bugzilla.suse.com/1159850">SUSE bug 1159850</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919925" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19925</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19925" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19925" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19925" ref_url="https://www.suse.com/security/cve/CVE-2019-19925" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0189-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0210-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19925/">CVE-2019-19925</cve>
	<bugzilla href="https://bugzilla.suse.com/1159847">SUSE bug 1159847</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1162833">SUSE bug 1162833</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919926" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19926</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19926" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19926" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19926" ref_url="https://www.suse.com/security/cve/CVE-2019-19926" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0189-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0210-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0233-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19926/">CVE-2019-19926</cve>
	<bugzilla href="https://bugzilla.suse.com/1159491">SUSE bug 1159491</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1159715">SUSE bug 1159715</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1162833">SUSE bug 1162833</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919947" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19947</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19947" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19947" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19947" ref_url="https://www.suse.com/security/cve/CVE-2019-19947" source="SUSE CVE"/>
    <description>
    In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-19947/">CVE-2019-19947</cve>
	<bugzilla href="https://bugzilla.suse.com/1159929">SUSE bug 1159929</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919956" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19956</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19956" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19956" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19956" ref_url="https://www.suse.com/security/cve/CVE-2019-19956" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006890.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006891.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007413.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007415.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1299-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1532-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007409.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008797.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0681-1" ref_url="https://lists.opensuse.org/opensuse-updates/2020-05/msg00124.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0781-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00005.html" source="SUSE-SU"/>
    <description>
    xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc-&gt;oldNs.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19956/">CVE-2019-19956</cve>
	<bugzilla href="https://bugzilla.suse.com/1159928">SUSE bug 1159928</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191860">SUSE bug 1191860</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919959" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19959</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19959" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19959" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19959" ref_url="https://www.suse.com/security/cve/CVE-2019-19959" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19959/">CVE-2019-19959</cve>
	<bugzilla href="https://bugzilla.suse.com/1160438">SUSE bug 1160438</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919965" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19965</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19965" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19965" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19965" ref_url="https://www.suse.com/security/cve/CVE-2019-19965" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-19965/">CVE-2019-19965</cve>
	<bugzilla href="https://bugzilla.suse.com/1159911">SUSE bug 1159911</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201919977" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-19977</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-19977" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19977" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-19977" ref_url="https://www.suse.com/security/cve/CVE-2019-19977" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009358.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2917-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2937-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2937-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009471.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1235-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HXOIPTG34E6FHFZ5MRT6B4BEC5ETU6ML/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2937-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TGZ4L5IPYNOJTWC7WZTAMPSFHIGKXQAE/" source="SUSE-SU"/>
    <description>
    libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-19977/">CVE-2019-19977</cve>
	<bugzilla href="https://bugzilla.suse.com/1160462">SUSE bug 1160462</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189097">SUSE bug 1189097</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190329">SUSE bug 1190329</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191840">SUSE bug 1191840</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192365">SUSE bug 1192365</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193380">SUSE bug 1193380</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193381">SUSE bug 1193381</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629441" comment="libesmtp-1.0.6-150.4.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920218" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20218</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20218" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20218" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20218" ref_url="https://www.suse.com/security/cve/CVE-2019-20218" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009231.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-20218/">CVE-2019-20218</cve>
	<bugzilla href="https://bugzilla.suse.com/1160439">SUSE bug 1160439</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189840">SUSE bug 1189840</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190372">SUSE bug 1190372</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192495">SUSE bug 1192495</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193078">SUSE bug 1193078</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920367" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20367</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20367" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20367" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20367" ref_url="https://www.suse.com/security/cve/CVE-2019-20367" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:1298-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006825.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0679-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00043.html" source="SUSE-SU"/>
    <description>
    nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-20367/">CVE-2019-20367</cve>
	<bugzilla href="https://bugzilla.suse.com/1160551">SUSE bug 1160551</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482145" comment="libbsd0-0.8.7-3.3.17 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920386" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20386</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20386" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20386" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20386" ref_url="https://www.suse.com/security/cve/CVE-2019-20386" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:361-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:48-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0335-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007072.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0208-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00014.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.4/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-20386/">CVE-2019-20386</cve>
	<bugzilla href="https://bugzilla.suse.com/1161436">SUSE bug 1161436</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920388" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20388</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20388" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20388" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20388" ref_url="https://www.suse.com/security/cve/CVE-2019-20388" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007413.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007415.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1299-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007409.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008797.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0681-1" ref_url="https://lists.opensuse.org/opensuse-updates/2020-05/msg00124.html" source="SUSE-SU"/>
    <description>
    xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-20388/">CVE-2019-20388</cve>
	<bugzilla href="https://bugzilla.suse.com/1161521">SUSE bug 1161521</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191860">SUSE bug 1191860</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920422" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20422</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20422" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20422" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20422" ref_url="https://www.suse.com/security/cve/CVE-2019-20422" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 5.3.4, fib6_rule_lookup in net/ipv6/ip6_fib.c mishandles the RT6_LOOKUP_F_DST_NOREF flag in a reference-count decision, leading to (for example) a crash that was identified by syzkaller, aka CID-7b09c2d052db.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-20422/">CVE-2019-20422</cve>
	<bugzilla href="https://bugzilla.suse.com/1161897">SUSE bug 1161897</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20192054" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-2054</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-2054" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2054" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-2054" ref_url="https://www.suse.com/security/cve/CVE-2019-2054" source="SUSE CVE"/>
    <description>
    In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-119769499
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-2054/">CVE-2019-2054</cve>
	<bugzilla href="https://bugzilla.suse.com/1134561">SUSE bug 1134561</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181039">SUSE bug 1181039</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920794" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20794</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20794" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20794" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20794" ref_url="https://www.suse.com/security/cve/CVE-2019-20794" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-20794/">CVE-2019-20794</cve>
	<bugzilla href="https://bugzilla.suse.com/1171737">SUSE bug 1171737</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920795" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20795</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20795" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20795" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20795" ref_url="https://www.suse.com/security/cve/CVE-2019-20795" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:3452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009603.html" source="SUSE-SU"/>
    <description>
    iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-20795/">CVE-2019-20795</cve>
	<bugzilla href="https://bugzilla.suse.com/1171452">SUSE bug 1171452</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009339120" comment="iproute2 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920807" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20807</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20807" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20807" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20807" ref_url="https://www.suse.com/security/cve/CVE-2019-20807" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006887.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006895.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006896.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0794-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00018.html" source="SUSE-SU"/>
    <description>
    In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-20807/">CVE-2019-20807</cve>
	<bugzilla href="https://bugzilla.suse.com/1172225">SUSE bug 1172225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760864" comment="vim-data-common-8.0.1568-5.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760865" comment="vim-small-8.0.1568-5.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920810" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20810</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20810" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20810" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20810" ref_url="https://www.suse.com/security/cve/CVE-2019-20810" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1693-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-20810/">CVE-2019-20810</cve>
	<bugzilla href="https://bugzilla.suse.com/1172458">SUSE bug 1172458</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920812" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20812</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20812" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20812" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20812" ref_url="https://www.suse.com/security/cve/CVE-2019-20812" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.4.7. The prb_calc_retire_blk_tmo() function in net/packet/af_packet.c can result in a denial of service (CPU consumption and soft lockup) in a certain failure case involving TPACKET_V3, aka CID-b43d1f9f7067.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-20812/">CVE-2019-20812</cve>
	<bugzilla href="https://bugzilla.suse.com/1172453">SUSE bug 1172453</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920838" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20838</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20838" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20838" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20838" ref_url="https://www.suse.com/security/cve/CVE-2019-20838" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:472-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009675.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:473-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009676.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:476-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-October/020654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009722.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009725.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009758.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:571-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:572-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3529-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-October/020617.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3652-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009715.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1441-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ANBRV4PU5AWEEYUWZYBLJCQBG3AHEGD/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3529-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DOG6FED4Y3TBAFL2V2XUUC43MKZLFGH3/" source="SUSE-SU"/>
    <description>
    libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-24"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-20838/">CVE-2019-20838</cve>
	<bugzilla href="https://bugzilla.suse.com/1172973">SUSE bug 1172973</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189526">SUSE bug 1189526</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193384">SUSE bug 1193384</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704972" comment="libpcre1-8.45-20.10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920907" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20907</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20907" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20907" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20907" ref_url="https://www.suse.com/security/cve/CVE-2019-20907" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007260.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007282.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008118.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1254-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1257-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1258-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1265-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2332-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S3JTHM6LLDKL7VPNRJUSRPNZAD2FZ25H/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2333-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FLGERALYYFTBIX3ZKPM6EQ2WJVUXLOXY/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-20907/">CVE-2019-20907</cve>
	<bugzilla href="https://bugzilla.suse.com/1174091">SUSE bug 1174091</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201920916" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-20916</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-20916" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20916" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-20916" ref_url="https://www.suse.com/security/cve/CVE-2019-20916" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007932.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007933.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007934.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:917-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2698-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2726-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3016-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007614.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3565-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007889.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3566-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007890.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3593-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007908.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3594-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007907.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007904.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007909.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007975.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3865-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008081.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008282.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008291.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0428-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008303.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0432-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008310.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0529-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008350.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1454-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0516-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013882.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1598-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1613-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2143-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LG3I7MSGZF7WN3YNM7ML4QMO6MXYUU73/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2152-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4KXU352TPOYPGUNSKDJRXFXWPD5NF32K/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7DKY5FFZVXAPBL5ATB6LJG4VYEF3GOLN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2184-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/G3AA6BSUJEGBBKUCQO6J25OSG7PA6ZKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2185-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KOMPFK5R4IK4IFOQTL5NIJK6DKSYRSXT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2189-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/E2GBJR7SZL3UIJETOGQDYOPIODBESJYI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2190-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/623Y5GJHFGANTQ36ECKXIXY3QVKGYSCE/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2211-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EUMJS3WWV7Y2IVJFRMZNDUXZBSPWORBP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0270-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WUT6BSX5663NCXU3Y4KR3RA3RQHJMCFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0331-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3AKEBUCTPHZWXJGF6EWK7HBTO726SP2Y/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-20916/">CVE-2019-20916</cve>
	<bugzilla href="https://bugzilla.suse.com/1176262">SUSE bug 1176262</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629000" comment="python3-setuptools-40.5.0-6.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20192182" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-2182</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-2182" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2182" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-2182" ref_url="https://www.suse.com/security/cve/CVE-2019-2182" source="SUSE CVE"/>
    <description>
    In the Android kernel in the kernel MMU code there is a possible execution path leaving some kernel text and rodata pages writable. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-2182/">CVE-2019-2182</cve>
	<bugzilla href="https://bugzilla.suse.com/1150022">SUSE bug 1150022</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20192201" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-2201</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-2201" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2201" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-2201" ref_url="https://www.suse.com/security/cve/CVE-2019-2201" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2971-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006137.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2529-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2530-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00048.html" source="SUSE-SU"/>
    <description>
    In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-2201/">CVE-2019-2201</cve>
	<bugzilla href="https://bugzilla.suse.com/1156402">SUSE bug 1156402</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628779" comment="libjpeg8-8.1.2-5.15.7 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20192213" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-2213</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-2213" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2213" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-2213" ref_url="https://www.suse.com/security/cve/CVE-2019-2213" source="SUSE CVE"/>
    <description>
    In binder_free_transaction of binder.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-133758011References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-2213/">CVE-2019-2213</cve>
	<bugzilla href="https://bugzilla.suse.com/1156185">SUSE bug 1156185</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20192214" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-2214</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-2214" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2214" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-2214" ref_url="https://www.suse.com/security/cve/CVE-2019-2214" source="SUSE CVE"/>
    <description>
    In binder_transaction of binder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-136210786References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-2214/">CVE-2019-2214</cve>
	<bugzilla href="https://bugzilla.suse.com/1156186">SUSE bug 1156186</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20192215" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-2215</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-2215" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2215" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-2215" ref_url="https://www.suse.com/security/cve/CVE-2019-2215" source="SUSE CVE"/>
    <description>
    A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2019-2215/">CVE-2019-2215</cve>
	<bugzilla href="https://bugzilla.suse.com/1164867">SUSE bug 1164867</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201925044" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-25044</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-25044" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-25044" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-25044" ref_url="https://www.suse.com/security/cve/CVE-2019-25044" source="SUSE CVE"/>
    <description>
    The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs and blk_cleanup_queue.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-25044/">CVE-2019-25044</cve>
	<bugzilla href="https://bugzilla.suse.com/1186175">SUSE bug 1186175</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:201925045" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-25045</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-25045" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-25045" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-25045" ref_url="https://www.suse.com/security/cve/CVE-2019-25045" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:2321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009133.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-25045/">CVE-2019-25045</cve>
	<bugzilla href="https://bugzilla.suse.com/1187049">SUSE bug 1187049</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009624613" comment="kernel-rt-4.12.14-10.49.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193016" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3016</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3016" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3016" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3016" ref_url="https://www.suse.com/security/cve/CVE-2019-3016" source="SUSE CVE"/>
    <description>
    In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later. The problem mainly affects AMD processors but Intel CPUs cannot be ruled out.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-07-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-3016/">CVE-2019-3016</cve>
	<bugzilla href="https://bugzilla.suse.com/1159281">SUSE bug 1159281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1161154">SUSE bug 1161154</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193687" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3687</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3687" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3687" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3687" ref_url="https://www.suse.com/security/cve/CVE-2019-3687" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006559.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006556.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0302-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1520-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CDE67H3SKCA2N6SED6KU5T3MBX3UVI6N/" source="SUSE-SU"/>
    <description>
    The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to 081d081dcfaf61710bda34bc21c80c66276119aa.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-3687/">CVE-2019-3687</cve>
	<bugzilla href="https://bugzilla.suse.com/1148788">SUSE bug 1148788</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180102">SUSE bug 1180102</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628975" comment="permissions-20181224-23.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193688" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3688</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3688" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3688" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3688" ref_url="https://www.suse.com/security/cve/CVE-2019-3688" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006772.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009118.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2540-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2541-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1520-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CDE67H3SKCA2N6SED6KU5T3MBX3UVI6N/" source="SUSE-SU"/>
    <description>
    The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binary
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-3688/">CVE-2019-3688</cve>
	<bugzilla href="https://bugzilla.suse.com/1093414">SUSE bug 1093414</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1149108">SUSE bug 1149108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628975" comment="permissions-20181224-23.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193689" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3689</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3689" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3689" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3689" ref_url="https://www.suse.com/security/cve/CVE-2019-3689" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2776-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192776-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2781-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192781-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006056.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2408-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2435-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-11/msg00006.html" source="SUSE-SU"/>
    <description>
    The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-3689/">CVE-2019-3689</cve>
	<bugzilla href="https://bugzilla.suse.com/1150733">SUSE bug 1150733</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628947" comment="nfs-client-2.1.1-10.10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193690" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3690</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3690" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3690" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3690" ref_url="https://www.suse.com/security/cve/CVE-2019-3690" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006220.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006772.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009118.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2672-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-12/msg00024.html" source="SUSE-SU"/>
    <description>
    The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that is traversed by chkstat to escalate privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-3690/">CVE-2019-3690</cve>
	<bugzilla href="https://bugzilla.suse.com/1148336">SUSE bug 1148336</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1150734">SUSE bug 1150734</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157880">SUSE bug 1157880</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1157883">SUSE bug 1157883</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1160594">SUSE bug 1160594</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1160764">SUSE bug 1160764</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1163922">SUSE bug 1163922</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628975" comment="permissions-20181224-23.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193813" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3813</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3813" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3813" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3813" ref_url="https://www.suse.com/security/cve/CVE-2019-3813" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0229-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005081.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0231-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005405.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005094.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0167-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0176-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00025.html" source="SUSE-SU"/>
    <description>
    Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8/CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-3813/">CVE-2019-3813</cve>
	<bugzilla href="https://bugzilla.suse.com/1122706">SUSE bug 1122706</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193822" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3822</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3822" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3822" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3822" ref_url="https://www.suse.com/security/cve/CVE-2019-3822" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0249-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005111.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0173-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00023.html" source="SUSE-SU"/>
    <description>
    libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting overflowed is implemented wrongly (using unsigned math) and as such it does not prevent the overflow from happening. This output data can grow larger than the local buffer if very large 'nt response' data is extracted from a previous NTLMv2 header provided by the malicious or broken HTTP server. Such a 'large value' needs to be around 1000 bytes or more. The actual payload data copied to the target buffer comes from the NTLMv2 type-2 response header.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-3822/">CVE-2019-3822</cve>
	<bugzilla href="https://bugzilla.suse.com/1123377">SUSE bug 1123377</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1141798">SUSE bug 1141798</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193823" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3823</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3823" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3823" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3823" ref_url="https://www.suse.com/security/cve/CVE-2019-3823" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0249-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005111.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0173-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0174-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00023.html" source="SUSE-SU"/>
    <description>
    libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-3823/">CVE-2019-3823</cve>
	<bugzilla href="https://bugzilla.suse.com/1123378">SUSE bug 1123378</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1141798">SUSE bug 1141798</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193829" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3829</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3829" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3829" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3829" ref_url="https://www.suse.com/security/cve/CVE-2019-3829" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005414.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1353-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-3829/">CVE-2019-3829</cve>
	<bugzilla href="https://bugzilla.suse.com/1130681">SUSE bug 1130681</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193836" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3836</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3836" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3836" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3836" ref_url="https://www.suse.com/security/cve/CVE-2019-3836" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005414.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1353-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html" source="SUSE-SU"/>
    <description>
    It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-3836/">CVE-2019-3836</cve>
	<bugzilla href="https://bugzilla.suse.com/1130682">SUSE bug 1130682</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193837" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3837</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3837" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3837" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3837" ref_url="https://www.suse.com/security/cve/CVE-2019-3837" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2023:0416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013765.html" source="SUSE-SU"/>
    <description>
    It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same network socket in parallel executed on ioatdma-enabled hardware with net_dma enabled can leak the memory, crash the host leading to a denial-of-service or cause a random memory corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2019-3837/">CVE-2019-3837</cve>
	<bugzilla href="https://bugzilla.suse.com/1131430">SUSE bug 1131430</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193842" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3842</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3842" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3842" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3842" ref_url="https://www.suse.com/security/cve/CVE-2019-3842" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005509.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1364-2" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20191364-2.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1450-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html" source="SUSE-SU"/>
    <description>
    In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather than "allow_any".
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.5/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-3842/">CVE-2019-3842</cve>
	<bugzilla href="https://bugzilla.suse.com/1132348">SUSE bug 1132348</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193843" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3843</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3843" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3843" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3843" ref_url="https://www.suse.com/security/cve/CVE-2019-3843" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005509.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1364-2" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20191364-2.html" source="SUSE-SU"/>
    <description>
    It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.5/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-3843/">CVE-2019-3843</cve>
	<bugzilla href="https://bugzilla.suse.com/1133506">SUSE bug 1133506</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193844" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3844</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3844" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3844" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3844" ref_url="https://www.suse.com/security/cve/CVE-2019-3844" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005509.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1364-2" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20191364-2.html" source="SUSE-SU"/>
    <description>
    It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the GID will be recycled.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.5/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-3844/">CVE-2019-3844</cve>
	<bugzilla href="https://bugzilla.suse.com/1133509">SUSE bug 1133509</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193855" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3855</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3855" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3855" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3855" ref_url="https://www.suse.com/security/cve/CVE-2019-3855" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13982-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913982-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1075-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2126-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZ5CXNJKJVQFPMHVDXDS6F67TKZ3TJ7E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2129-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HAQH2P56QS5PVJGYRATVMCCAWSF5JABQ/" source="SUSE-SU"/>
    <description>
    An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-3855/">CVE-2019-3855</cve>
	<bugzilla href="https://bugzilla.suse.com/1128471">SUSE bug 1128471</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1134329">SUSE bug 1134329</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135434">SUSE bug 1135434</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1141850">SUSE bug 1141850</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193856" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3856</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3856" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3856" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3856" ref_url="https://www.suse.com/security/cve/CVE-2019-3856" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13982-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913982-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1075-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2126-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZ5CXNJKJVQFPMHVDXDS6F67TKZ3TJ7E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2129-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HAQH2P56QS5PVJGYRATVMCCAWSF5JABQ/" source="SUSE-SU"/>
    <description>
    An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-3856/">CVE-2019-3856</cve>
	<bugzilla href="https://bugzilla.suse.com/1128472">SUSE bug 1128472</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135434">SUSE bug 1135434</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193857" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3857</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3857" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3857" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3857" ref_url="https://www.suse.com/security/cve/CVE-2019-3857" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13982-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913982-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1075-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2126-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZ5CXNJKJVQFPMHVDXDS6F67TKZ3TJ7E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2129-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HAQH2P56QS5PVJGYRATVMCCAWSF5JABQ/" source="SUSE-SU"/>
    <description>
    An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-3857/">CVE-2019-3857</cve>
	<bugzilla href="https://bugzilla.suse.com/1128474">SUSE bug 1128474</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135434">SUSE bug 1135434</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193858" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3858</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3858" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3858" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3858" ref_url="https://www.suse.com/security/cve/CVE-2019-3858" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13982-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913982-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1075-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2126-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZ5CXNJKJVQFPMHVDXDS6F67TKZ3TJ7E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2129-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HAQH2P56QS5PVJGYRATVMCCAWSF5JABQ/" source="SUSE-SU"/>
    <description>
    An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-3858/">CVE-2019-3858</cve>
	<bugzilla href="https://bugzilla.suse.com/1128476">SUSE bug 1128476</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135434">SUSE bug 1135434</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193859" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3859</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3859" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3859" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3859" ref_url="https://www.suse.com/security/cve/CVE-2019-3859" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1060-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13982-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913982-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14031-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14032-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1075-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1290-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00102.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1291-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00103.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2126-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZ5CXNJKJVQFPMHVDXDS6F67TKZ3TJ7E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2129-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HAQH2P56QS5PVJGYRATVMCCAWSF5JABQ/" source="SUSE-SU"/>
    <description>
    An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-3859/">CVE-2019-3859</cve>
	<bugzilla href="https://bugzilla.suse.com/1128480">SUSE bug 1128480</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1130103">SUSE bug 1130103</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135434">SUSE bug 1135434</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193860" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3860</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3860" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3860" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3860" ref_url="https://www.suse.com/security/cve/CVE-2019-3860" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13982-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913982-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005609.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14099-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1606-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1075-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1640-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2126-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZ5CXNJKJVQFPMHVDXDS6F67TKZ3TJ7E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2129-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HAQH2P56QS5PVJGYRATVMCCAWSF5JABQ/" source="SUSE-SU"/>
    <description>
    An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-3860/">CVE-2019-3860</cve>
	<bugzilla href="https://bugzilla.suse.com/1128481">SUSE bug 1128481</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135434">SUSE bug 1135434</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136570">SUSE bug 1136570</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193861" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3861</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3861" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3861" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3861" ref_url="https://www.suse.com/security/cve/CVE-2019-3861" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13982-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913982-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1075-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2126-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZ5CXNJKJVQFPMHVDXDS6F67TKZ3TJ7E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2129-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HAQH2P56QS5PVJGYRATVMCCAWSF5JABQ/" source="SUSE-SU"/>
    <description>
    An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-3861/">CVE-2019-3861</cve>
	<bugzilla href="https://bugzilla.suse.com/1128490">SUSE bug 1128490</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135434">SUSE bug 1135434</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193862" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3862</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3862" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3862" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3862" ref_url="https://www.suse.com/security/cve/CVE-2019-3862" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13982-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913982-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1075-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2126-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZ5CXNJKJVQFPMHVDXDS6F67TKZ3TJ7E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2129-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HAQH2P56QS5PVJGYRATVMCCAWSF5JABQ/" source="SUSE-SU"/>
    <description>
    An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-3862/">CVE-2019-3862</cve>
	<bugzilla href="https://bugzilla.suse.com/1128492">SUSE bug 1128492</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135434">SUSE bug 1135434</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193863" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3863</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3863" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3863" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3863" ref_url="https://www.suse.com/security/cve/CVE-2019-3863" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13982-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-201913982-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1075-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1109-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2126-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZ5CXNJKJVQFPMHVDXDS6F67TKZ3TJ7E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2129-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HAQH2P56QS5PVJGYRATVMCCAWSF5JABQ/" source="SUSE-SU"/>
    <description>
    A flaw was found in libssh2 before 1.8.1. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used as an index to copy memory causing in an out of bounds memory write error.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-3863/">CVE-2019-3863</cve>
	<bugzilla href="https://bugzilla.suse.com/1128493">SUSE bug 1128493</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1130103">SUSE bug 1130103</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135434">SUSE bug 1135434</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628874" comment="libssh2-1-1.9.0-4.13.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193886" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3886</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3886" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3886" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3886" ref_url="https://www.suse.com/security/cve/CVE-2019-3886" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005338.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1042-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005533.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1294-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.html" source="SUSE-SU"/>
    <description>
    An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2019-3886/">CVE-2019-3886</cve>
	<bugzilla href="https://bugzilla.suse.com/1131595">SUSE bug 1131595</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1133150">SUSE bug 1133150</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138301">SUSE bug 1138301</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193896" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3896</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3896" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3896" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3896" ref_url="https://www.suse.com/security/cve/CVE-2019-3896" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14127-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005734.html" source="SUSE-SU"/>
    <description>
    A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-20"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-3896/">CVE-2019-3896</cve>
	<bugzilla href="https://bugzilla.suse.com/1138943">SUSE bug 1138943</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1156434">SUSE bug 1156434</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173987">SUSE bug 1173987</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20193901" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-3901</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-3901" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3901" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-3901" ref_url="https://www.suse.com/security/cve/CVE-2019-3901" source="SUSE CVE"/>
    <description>
    A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target task to perform an execve() syscall with setuid execution before perf_event_alloc() actually attaches to it, allowing an attacker to bypass the ptrace_may_access() check and the perf_event_exit_task(current) call that is performed in install_exec_creds() during privileged execve() calls. This issue affects kernel versions before 4.8.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-3901/">CVE-2019-3901</cve>
	<bugzilla href="https://bugzilla.suse.com/1132374">SUSE bug 1132374</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1133106">SUSE bug 1133106</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20195008" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-5008</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-5008" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5008" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-5008" ref_url="https://www.suse.com/security/cve/CVE-2019-5008" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005833.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2041-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00000.html" source="SUSE-SU"/>
    <description>
    hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-5008/">CVE-2019-5008</cve>
	<bugzilla href="https://bugzilla.suse.com/1133031">SUSE bug 1133031</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20195010" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-5010</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-5010" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5010" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-5010" ref_url="https://www.suse.com/security/cve/CVE-2019-5010" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006375.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005085.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0243-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0482-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008118.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0155-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00012.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0184-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0292-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2332-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S3JTHM6LLDKL7VPNRJUSRPNZAD2FZ25H/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2333-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FLGERALYYFTBIX3ZKPM6EQ2WJVUXLOXY/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-5010/">CVE-2019-5010</cve>
	<bugzilla href="https://bugzilla.suse.com/1122191">SUSE bug 1122191</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126909">SUSE bug 1126909</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20195068" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-5068</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-5068" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5068" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-5068" ref_url="https://www.suse.com/security/cve/CVE-2019-5068" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0111-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0145-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009451.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0084-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00037.html" source="SUSE-SU"/>
    <description>
    An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-5068/">CVE-2019-5068</cve>
	<bugzilla href="https://bugzilla.suse.com/1156015">SUSE bug 1156015</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481717" comment="libgbm1-19.3.4-45.23 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20195094" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-5094</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-5094" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5094" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-5094" ref_url="https://www.suse.com/security/cve/CVE-2019-5094" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006427.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
    <description>
    An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-5094/">CVE-2019-5094</cve>
	<bugzilla href="https://bugzilla.suse.com/1152101">SUSE bug 1152101</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760777" comment="e2fsprogs-1.43.8-4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760778" comment="libcom_err2-1.43.8-4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760779" comment="libext2fs2-1.43.8-4.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20195188" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-5188</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-5188" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5188" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-5188" ref_url="https://www.suse.com/security/cve/CVE-2019-5188" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006420.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006421.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:33-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006430.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:35-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:39-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006444.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:51-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006338.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006332.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006415.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006471.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0166-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00004.html" source="SUSE-SU"/>
    <description>
    A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-5188/">CVE-2019-5188</cve>
	<bugzilla href="https://bugzilla.suse.com/1160571">SUSE bug 1160571</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760777" comment="e2fsprogs-1.43.8-4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760778" comment="libcom_err2-1.43.8-4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760779" comment="libext2fs2-1.43.8-4.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20195435" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-5435</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-5435" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5435" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-5435" ref_url="https://www.suse.com/security/cve/CVE-2019-5435" source="SUSE CVE"/>
    <description>
    An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.7/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-5435/">CVE-2019-5435</cve>
	<bugzilla href="https://bugzilla.suse.com/1135176">SUSE bug 1135176</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154162">SUSE bug 1154162</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20195436" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-5436</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-5436" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5436" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-5436" ref_url="https://www.suse.com/security/cve/CVE-2019-5436" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1357-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1363-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005506.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14064-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2009-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192009-1.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1492-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1508-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00017.html" source="SUSE-SU"/>
    <description>
    A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-5436/">CVE-2019-5436</cve>
	<bugzilla href="https://bugzilla.suse.com/1135170">SUSE bug 1135170</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1149496">SUSE bug 1149496</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154162">SUSE bug 1154162</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1167096">SUSE bug 1167096</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20195481" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-5481</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-5481" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5481" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-5481" ref_url="https://www.suse.com/security/cve/CVE-2019-5481" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2373-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192373-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005919.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2149-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00055.html" source="SUSE-SU"/>
    <description>
    Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-5481/">CVE-2019-5481</cve>
	<bugzilla href="https://bugzilla.suse.com/1149495">SUSE bug 1149495</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20195482" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-5482</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-5482" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5482" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-5482" ref_url="https://www.suse.com/security/cve/CVE-2019-5482" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005897.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2339-2" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192339-2.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2373-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192373-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2381-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005919.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2149-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00055.html" source="SUSE-SU"/>
    <description>
    Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-5482/">CVE-2019-5482</cve>
	<bugzilla href="https://bugzilla.suse.com/1149496">SUSE bug 1149496</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1156634">SUSE bug 1156634</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20195544" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-5544</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-5544" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5544" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-5544" ref_url="https://www.suse.com/security/cve/CVE-2019-5544" source="SUSE CVE"/>
    <description>
    OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-5544/">CVE-2019-5544</cve>
	<bugzilla href="https://bugzilla.suse.com/1157869">SUSE bug 1157869</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334285" comment="openslp is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20195736" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-5736</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-5736" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5736" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-5736" ref_url="https://www.suse.com/security/cve/CVE-2019-5736" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1007-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0337-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1234-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005814.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008717.html" source="SUSE-SU"/>
		<reference ref_id="TID000019404" ref_url="https://www.suse.com/support/kb/doc/?id=000019404" source="SUSE-SU"/>
		<reference ref_id="TID7023708" ref_url="https://www.suse.com/support/kb/doc/?id=7023708" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0170-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0201-1" ref_url="https://lists.opensuse.org/opensuse-updates/2019-02/msg00096.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0208-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00048.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0252-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0295-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1079-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1227-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00074.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1275-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00091.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1444-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00060.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1481-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1499-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1506-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2021-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2245-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2286-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00029.html" source="SUSE-SU"/>
    <description>
    runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-5736/">CVE-2019-5736</cve>
	<bugzilla href="https://bugzilla.suse.com/1121967">SUSE bug 1121967</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122185">SUSE bug 1122185</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173421">SUSE bug 1173421</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629067" comment="containerd-1.3.9-5.29.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629072" comment="docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-6.45.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482602" comment="runc-1.0.0~rc10-1.9.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20196109" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-6109</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-6109" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6109" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-6109" ref_url="https://www.suse.com/security/cve/CVE-2019-6109" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0125-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005404.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0941-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005333.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14016-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005565.html" source="SUSE-SU"/>
		<reference ref_id="TID000019375" ref_url="https://www.suse.com/support/kb/doc/?id=000019375" source="SUSE-SU"/>
		<reference ref_id="TID7023647" ref_url="https://www.suse.com/support/kb/doc/?id=7023647" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0091-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0307-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1602-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00058.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-6109/">CVE-2019-6109</cve>
	<bugzilla href="https://bugzilla.suse.com/1121571">SUSE bug 1121571</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121816">SUSE bug 1121816</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121818">SUSE bug 1121818</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121821">SUSE bug 1121821</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138392">SUSE bug 1138392</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1144902">SUSE bug 1144902</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1144903">SUSE bug 1144903</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1148884">SUSE bug 1148884</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20196110" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-6110</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-6110" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6110" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-6110" ref_url="https://www.suse.com/security/cve/CVE-2019-6110" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0125-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005404.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005049.html" source="SUSE-SU"/>
		<reference ref_id="TID000019375" ref_url="https://www.suse.com/support/kb/doc/?id=000019375" source="SUSE-SU"/>
		<reference ref_id="TID7023647" ref_url="https://www.suse.com/support/kb/doc/?id=7023647" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0091-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00041.html" source="SUSE-SU"/>
    <description>
    In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-6110/">CVE-2019-6110</cve>
	<bugzilla href="https://bugzilla.suse.com/1121571">SUSE bug 1121571</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121816">SUSE bug 1121816</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121818">SUSE bug 1121818</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121821">SUSE bug 1121821</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20196111" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-6111</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-6111" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6111" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-6111" ref_url="https://www.suse.com/security/cve/CVE-2019-6111" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0125-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005404.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0941-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005333.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14016-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005565.html" source="SUSE-SU"/>
		<reference ref_id="TID000019375" ref_url="https://www.suse.com/support/kb/doc/?id=000019375" source="SUSE-SU"/>
		<reference ref_id="TID7023647" ref_url="https://www.suse.com/support/kb/doc/?id=7023647" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0091-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0093-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0307-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00013.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1602-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00058.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.8/CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-6111/">CVE-2019-6111</cve>
	<bugzilla href="https://bugzilla.suse.com/1121571">SUSE bug 1121571</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121816">SUSE bug 1121816</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121818">SUSE bug 1121818</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121821">SUSE bug 1121821</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123028">SUSE bug 1123028</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123220">SUSE bug 1123220</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131109">SUSE bug 1131109</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138392">SUSE bug 1138392</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1144902">SUSE bug 1144902</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1144903">SUSE bug 1144903</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1148884">SUSE bug 1148884</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201840">SUSE bug 1201840</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20196133" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-6133</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-6133" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6133" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-6133" ref_url="https://www.suse.com/security/cve/CVE-2019-6133" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:2018-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2035-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1914-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00049.html" source="SUSE-SU"/>
    <description>
    In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-6133/">CVE-2019-6133</cve>
	<bugzilla href="https://bugzilla.suse.com/1070943">SUSE bug 1070943</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121826">SUSE bug 1121826</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1121872">SUSE bug 1121872</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482356" comment="libpolkit0-0.116-1.51 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482357" comment="polkit-0.116-1.51 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20196250" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-6250</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-6250" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6250" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-6250" ref_url="https://www.suse.com/security/cve/CVE-2019-6250" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-January/005037.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0064-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0087-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow allows an authenticated attacker to overwrite an arbitrary amount of bytes beyond the bounds of a buffer, which can be leveraged to run arbitrary code on the target system. The memory layout allows the attacker to inject OS commands into a data structure located immediately after the problematic buffer (i.e., it is not necessary to use a typical buffer-overflow exploitation technique that changes the flow of control).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.2/CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-6250/">CVE-2019-6250</cve>
	<bugzilla href="https://bugzilla.suse.com/1121717">SUSE bug 1121717</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122012">SUSE bug 1122012</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628931" comment="libzmq5-4.2.3-3.15.4 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20196285" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-6285</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-6285" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6285" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-6285" ref_url="https://www.suse.com/security/cve/CVE-2019-6285" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:481-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:483-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010626.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010628.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:488-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010629.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010631.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:500-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010643.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010644.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:515-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:525-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010658.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010617.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1073-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1740-3" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014346.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1073-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/U5JRSH3JEFDRI2LLKIUVXRRMZJAO5ZPH/" source="SUSE-SU"/>
    <description>
    The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-6285/">CVE-2019-6285</cve>
	<bugzilla href="https://bugzilla.suse.com/1122004">SUSE bug 1122004</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1122021">SUSE bug 1122021</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1129245">SUSE bug 1129245</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705024" comment="libyaml-cpp0_6-0.6.1-4.5.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20196292" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-6292</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-6292" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6292" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-6292" ref_url="https://www.suse.com/security/cve/CVE-2019-6292" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:481-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:483-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010626.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010628.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:488-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010629.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010631.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:500-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010643.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010644.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:515-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:525-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010658.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010617.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1073-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1740-3" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014346.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1073-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/U5JRSH3JEFDRI2LLKIUVXRRMZJAO5ZPH/" source="SUSE-SU"/>
    <description>
    An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::SingleDocParser, and there is a stack consumption problem caused by recursive stack frames: HandleCompactMap, HandleMap, HandleFlowSequence, HandleSequence, HandleNode. Remote attackers could leverage this vulnerability to cause a denial-of-service via a cpp file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-6292/">CVE-2019-6292</cve>
	<bugzilla href="https://bugzilla.suse.com/1122021">SUSE bug 1122021</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705024" comment="libyaml-cpp0_6-0.6.1-4.5.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20196454" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-6454</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-6454" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6454" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-6454" ref_url="https://www.suse.com/security/cve/CVE-2019-6454" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0425-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0425-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005336.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005509.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1364-2" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20191364-2.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0255-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0268-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1450-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-6454/">CVE-2019-6454</cve>
	<bugzilla href="https://bugzilla.suse.com/1125352">SUSE bug 1125352</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20196462" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-6462</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-6462" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6462" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-6462" ref_url="https://www.suse.com/security/cve/CVE-2019-6462" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:3502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009644.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-6462/">CVE-2019-6462</cve>
	<bugzilla href="https://bugzilla.suse.com/1122321">SUSE bug 1122321</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009339036" comment="libcairo2 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20196706" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-6706</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-6706" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6706" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-6706" ref_url="https://www.suse.com/security/cve/CVE-2019-6706" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0247-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005087.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0175-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00024.html" source="SUSE-SU"/>
    <description>
    Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-6706/">CVE-2019-6706</cve>
	<bugzilla href="https://bugzilla.suse.com/1123043">SUSE bug 1123043</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481427" comment="liblua5_3-5-5.3.4-3.3.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20196778" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-6778</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-6778" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6778" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-6778" ref_url="https://www.suse.com/security/cve/CVE-2019-6778" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0423-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0457-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0471-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0471-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0921-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005320.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:13962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-February/005126.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14001-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006662.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006664.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006934.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006868.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1523-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006874.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0254-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-02/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2044-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.html" source="SUSE-SU"/>
    <description>
    In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-6778/">CVE-2019-6778</cve>
	<bugzilla href="https://bugzilla.suse.com/1123156">SUSE bug 1123156</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1123157">SUSE bug 1123157</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629075" comment="slirp4netns-0.4.7-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20197146" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-7146</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-7146" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7146" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-7146" ref_url="https://www.suse.com/security/cve/CVE-2019-7146" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
    <description>
    In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted elf file, as demonstrated by eu-readelf.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-06"/>
	<updated date="2023-09-06"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-7146/">CVE-2019-7146</cve>
	<bugzilla href="https://bugzilla.suse.com/1123545">SUSE bug 1123545</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334073" comment="elfutils is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335871" comment="libasm1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335872" comment="libdw1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009659704" comment="libebl-plugins is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335876" comment="libelf1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20197150" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-7150</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-7150" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7150" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-7150" ref_url="https://www.suse.com/security/cve/CVE-2019-7150" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-7150/">CVE-2019-7150</cve>
	<bugzilla href="https://bugzilla.suse.com/1123685">SUSE bug 1123685</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20197317" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-7317</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-7317" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7317" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-7317" ref_url="https://www.suse.com/security/cve/CVE-2019-7317" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1398-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1398-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005664.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1405-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14160-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2002-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192002-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2021-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2028-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005762.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2036-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005767.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2036-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2291-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192291-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005896.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2371-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192371-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3060-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:3060-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006567.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1484-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1530-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1534-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1664-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1912-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1916-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html" source="SUSE-SU"/>
    <description>
    png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-7317/">CVE-2019-7317</cve>
	<bugzilla href="https://bugzilla.suse.com/1124211">SUSE bug 1124211</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135824">SUSE bug 1135824</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1141780">SUSE bug 1141780</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1147021">SUSE bug 1147021</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1165297">SUSE bug 1165297</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482352" comment="libpng16-16-1.6.34-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20197665" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-7665</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-7665" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7665" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-7665" ref_url="https://www.suse.com/security/cve/CVE-2019-7665" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2614-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012057.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1590-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.html" source="SUSE-SU"/>
    <description>
    In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-7665/">CVE-2019-7665</cve>
	<bugzilla href="https://bugzilla.suse.com/1125007">SUSE bug 1125007</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009481929" comment="elfutils-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481932" comment="libasm1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481934" comment="libdw1-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481937" comment="libebl-plugins-0.168-4.5.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481940" comment="libelf1-0.168-4.5.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198320" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8320</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8320" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8320" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8320" ref_url="https://www.suse.com/security/cve/CVE-2019-8320" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user's machine, presuming the attacker could guess at paths. Given how frequently gem is run as sudo, and how predictable paths are on modern systems (/tmp, /usr, etc.), this could likely lead to data loss or an unusable system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-8320/">CVE-2019-8320</cve>
	<bugzilla href="https://bugzilla.suse.com/1130627">SUSE bug 1130627</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198321" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8321</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8321" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8321" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8321" ref_url="https://www.suse.com/security/cve/CVE-2019-8321" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-8321/">CVE-2019-8321</cve>
	<bugzilla href="https://bugzilla.suse.com/1130623">SUSE bug 1130623</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198322" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8322</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8322" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8322" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8322" ref_url="https://www.suse.com/security/cve/CVE-2019-8322" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-8322/">CVE-2019-8322</cve>
	<bugzilla href="https://bugzilla.suse.com/1130622">SUSE bug 1130622</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198323" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8323</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8323" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8323" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8323" ref_url="https://www.suse.com/security/cve/CVE-2019-8323" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-8323/">CVE-2019-8323</cve>
	<bugzilla href="https://bugzilla.suse.com/1130620">SUSE bug 1130620</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198324" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8324</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8324" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8324" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8324" ref_url="https://www.suse.com/security/cve/CVE-2019-8324" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-8324/">CVE-2019-8324</cve>
	<bugzilla href="https://bugzilla.suse.com/1130617">SUSE bug 1130617</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198325" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8325</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8325" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8325" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8325" ref_url="https://www.suse.com/security/cve/CVE-2019-8325" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1771-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-8325/">CVE-2019-8325</cve>
	<bugzilla href="https://bugzilla.suse.com/1130611">SUSE bug 1130611</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198341" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8341</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8341" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8341" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8341" ref_url="https://www.suse.com/security/cve/CVE-2019-8341" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007672.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3896-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008099.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1614-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxing.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-8341/">CVE-2019-8341</cve>
	<bugzilla href="https://bugzilla.suse.com/1125815">SUSE bug 1125815</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009481633" comment="python3-Jinja2-2.10.1-3.5.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198905" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8905</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8905" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8905" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8905" ref_url="https://www.suse.com/security/cve/CVE-2019-8905" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0571-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190571-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005284.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0345-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1197-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html" source="SUSE-SU"/>
    <description>
    do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-8905/">CVE-2019-8905</cve>
	<bugzilla href="https://bugzilla.suse.com/1126117">SUSE bug 1126117</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126118">SUSE bug 1126118</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628435" comment="file-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628437" comment="file-magic-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628438" comment="libmagic1-5.32-7.11.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198906" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8906</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8906" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8906" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8906" ref_url="https://www.suse.com/security/cve/CVE-2019-8906" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0571-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190571-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005284.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0345-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1197-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html" source="SUSE-SU"/>
    <description>
    do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-8906/">CVE-2019-8906</cve>
	<bugzilla href="https://bugzilla.suse.com/1126119">SUSE bug 1126119</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628435" comment="file-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628437" comment="file-magic-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628438" comment="libmagic1-5.32-7.11.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198907" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8907</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8907" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8907" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8907" ref_url="https://www.suse.com/security/cve/CVE-2019-8907" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0571-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190571-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005284.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:0345-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1197-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html" source="SUSE-SU"/>
    <description>
    do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-8907/">CVE-2019-8907</cve>
	<bugzilla href="https://bugzilla.suse.com/1126117">SUSE bug 1126117</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628435" comment="file-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628437" comment="file-magic-5.32-7.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628438" comment="libmagic1-5.32-7.11.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198912" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8912</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8912" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8912" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8912" ref_url="https://www.suse.com/security/cve/CVE-2019-8912" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0726-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005231.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0745-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005240.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-March/005245.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0784-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190784-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0785-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20190785-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005285.html" source="SUSE-SU"/>
		<reference ref_id="TID000019417" ref_url="https://www.suse.com/support/kb/doc/?id=000019417" source="SUSE-SU"/>
		<reference ref_id="TID7023740" ref_url="https://www.suse.com/support/kb/doc/?id=7023740" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1193-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00052.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-8912/">CVE-2019-8912</cve>
	<bugzilla href="https://bugzilla.suse.com/1125907">SUSE bug 1125907</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126284">SUSE bug 1126284</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198934" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8934</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8934" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8934" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8934" ref_url="https://www.suse.com/security/cve/CVE-2019-8934" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008910.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1405-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00040.html" source="SUSE-SU"/>
    <description>
    hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-26"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-8934/">CVE-2019-8934</cve>
	<bugzilla href="https://bugzilla.suse.com/1118900">SUSE bug 1118900</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1126455">SUSE bug 1126455</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20198956" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-8956</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-8956" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8956" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-8956" ref_url="https://www.suse.com/security/cve/CVE-2019-8956" source="SUSE CVE"/>
    <description>
    In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-8956/">CVE-2019-8956</cve>
	<bugzilla href="https://bugzilla.suse.com/1124136">SUSE bug 1124136</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199162" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9162</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9162" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9162" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9162" ref_url="https://www.suse.com/security/cve/CVE-2019-9162" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This affects snmp_version and snmp_helper.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-9162/">CVE-2019-9162</cve>
	<bugzilla href="https://bugzilla.suse.com/1127324">SUSE bug 1127324</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199169" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9169</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9169" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9169" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9169" ref_url="https://www.suse.com/security/cve/CVE-2019-9169" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005729.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1958-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1958-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005821.html" source="SUSE-SU"/>
    <description>
    In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-9169/">CVE-2019-9169</cve>
	<bugzilla href="https://bugzilla.suse.com/1127308">SUSE bug 1127308</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146392">SUSE bug 1146392</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199445" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9445</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9445" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9445" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9445" ref_url="https://www.suse.com/security/cve/CVE-2019-9445" source="SUSE CVE"/>
    <description>
    In the Android kernel in F2FS driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-9445/">CVE-2019-9445</cve>
	<bugzilla href="https://bugzilla.suse.com/1172196">SUSE bug 1172196</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199446" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9446</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9446" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9446" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9446" ref_url="https://www.suse.com/security/cve/CVE-2019-9446" source="SUSE CVE"/>
    <description>
    In the Android kernel in the FingerTipS touchscreen driver there is a possible out of bounds write due to improper input validation. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-9446/">CVE-2019-9446</cve>
	<bugzilla href="https://bugzilla.suse.com/1168313">SUSE bug 1168313</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199447" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9447</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9447" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9447" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9447" ref_url="https://www.suse.com/security/cve/CVE-2019-9447" source="SUSE CVE"/>
    <description>
    In the Android kernel in the FingerTipS touchscreen driver there is a possible use-after-free due to improper locking. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-9447/">CVE-2019-9447</cve>
	<bugzilla href="https://bugzilla.suse.com/1168311">SUSE bug 1168311</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199448" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9448</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9448" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9448" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9448" ref_url="https://www.suse.com/security/cve/CVE-2019-9448" source="SUSE CVE"/>
    <description>
    In the Android kernel in the FingerTipS touchscreen driver there is a possible out of bounds write due to a missing bounds check. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-9448/">CVE-2019-9448</cve>
	<bugzilla href="https://bugzilla.suse.com/1168315">SUSE bug 1168315</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199449" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9449</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9449" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9449" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9449" ref_url="https://www.suse.com/security/cve/CVE-2019-9449" source="SUSE CVE"/>
    <description>
    In the Android kernel in FingerTipS touchscreen driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-9449/">CVE-2019-9449</cve>
	<bugzilla href="https://bugzilla.suse.com/1168314">SUSE bug 1168314</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199450" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9450</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9450" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9450" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9450" ref_url="https://www.suse.com/security/cve/CVE-2019-9450" source="SUSE CVE"/>
    <description>
    In the Android kernel in the FingerTipS touchscreen driver there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-9450/">CVE-2019-9450</cve>
	<bugzilla href="https://bugzilla.suse.com/1168316">SUSE bug 1168316</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199453" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9453</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9453" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9453" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9453" ref_url="https://www.suse.com/security/cve/CVE-2019-9453" source="SUSE CVE"/>
    <description>
    In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-9453/">CVE-2019-9453</cve>
	<bugzilla href="https://bugzilla.suse.com/1150028">SUSE bug 1150028</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199454" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9454</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9454" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9454" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9454" ref_url="https://www.suse.com/security/cve/CVE-2019-9454" source="SUSE CVE"/>
    <description>
    In the Android kernel in i2c driver there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2019-9454/">CVE-2019-9454</cve>
	<bugzilla href="https://bugzilla.suse.com/1150023">SUSE bug 1150023</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199466" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9466</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9466" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9466" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9466" ref_url="https://www.suse.com/security/cve/CVE-2019-9466" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-9503. Reason: This candidate is a duplicate of CVE-2019-9503. Notes: All CVE users should reference CVE-2019-9503 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-08"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-9466/">CVE-2019-9466</cve>
	<bugzilla href="https://bugzilla.suse.com/1156653">SUSE bug 1156653</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199475" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9475</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9475" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9475" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9475" ref_url="https://www.suse.com/security/cve/CVE-2019-9475" source="SUSE CVE"/>
    <description>
    In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-9496886
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-9475/">CVE-2019-9475</cve>
	<bugzilla href="https://bugzilla.suse.com/1189429">SUSE bug 1189429</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199494" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9494</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9494" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9494" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9494" ref_url="https://www.suse.com/security/cve/CVE-2019-9494" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="TID000019433" ref_url="https://www.suse.com/support/kb/doc/?id=000019433" source="SUSE-SU"/>
		<reference ref_id="TID7023818" ref_url="https://www.suse.com/support/kb/doc/?id=7023818" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0222-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.9/CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-9494/">CVE-2019-9494</cve>
	<bugzilla href="https://bugzilla.suse.com/1131291">SUSE bug 1131291</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131868">SUSE bug 1131868</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194732">SUSE bug 1194732</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199495" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9495</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9495" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9495" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9495" ref_url="https://www.suse.com/security/cve/CVE-2019-9495" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="TID000019433" ref_url="https://www.suse.com/support/kb/doc/?id=000019433" source="SUSE-SU"/>
		<reference ref_id="TID7023818" ref_url="https://www.suse.com/support/kb/doc/?id=7023818" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0222-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2019-9495/">CVE-2019-9495</cve>
	<bugzilla href="https://bugzilla.suse.com/1131291">SUSE bug 1131291</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131870">SUSE bug 1131870</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194733">SUSE bug 1194733</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199497" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9497</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9497" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9497" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9497" ref_url="https://www.suse.com/security/cve/CVE-2019-9497" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="TID000019433" ref_url="https://www.suse.com/support/kb/doc/?id=000019433" source="SUSE-SU"/>
		<reference ref_id="TID7023818" ref_url="https://www.suse.com/support/kb/doc/?id=7023818" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0222-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete EAP-PWD authentication without knowing the password. However, unless the crypto library does not implement additional checks for the EC point, the attacker will not be able to derive the session key or complete the key exchange. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.1/CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-9497/">CVE-2019-9497</cve>
	<bugzilla href="https://bugzilla.suse.com/1131871">SUSE bug 1131871</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131872">SUSE bug 1131872</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131874">SUSE bug 1131874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199498" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9498</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9498" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9498" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9498" ref_url="https://www.suse.com/security/cve/CVE-2019-9498" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="TID000019433" ref_url="https://www.suse.com/support/kb/doc/?id=000019433" source="SUSE-SU"/>
		<reference ref_id="TID7023818" ref_url="https://www.suse.com/support/kb/doc/?id=7023818" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0222-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and network access without needing or learning the password. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.8/CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-9498/">CVE-2019-9498</cve>
	<bugzilla href="https://bugzilla.suse.com/1131871">SUSE bug 1131871</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131872">SUSE bug 1131872</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131874">SUSE bug 1131874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199499" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9499</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9499" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9499" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9499" ref_url="https://www.suse.com/security/cve/CVE-2019-9499" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="TID000019433" ref_url="https://www.suse.com/support/kb/doc/?id=000019433" source="SUSE-SU"/>
		<reference ref_id="TID7023818" ref_url="https://www.suse.com/support/kb/doc/?id=7023818" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0222-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2053-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2R3VXKTYLLUYFBZQ2NNAI5NSZOBXISJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5HDY6AZL2NYOKU57GM74M5JHC5SYA3IY/" source="SUSE-SU"/>
    <description>
    The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.8/CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2019-9499/">CVE-2019-9499</cve>
	<bugzilla href="https://bugzilla.suse.com/1131871">SUSE bug 1131871</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131872">SUSE bug 1131872</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1131874">SUSE bug 1131874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199511" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9511</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9511" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9511" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9511" ref_url="https://www.suse.com/security/cve/CVE-2019-9511" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2259-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2260-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2473-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006320.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008541.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2114-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2120-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2232-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2234-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2264-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html" source="SUSE-SU"/>
    <description>
    Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-9511/">CVE-2019-9511</cve>
	<bugzilla href="https://bugzilla.suse.com/1145579">SUSE bug 1145579</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146091">SUSE bug 1146091</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146182">SUSE bug 1146182</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193427">SUSE bug 1193427</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1202787">SUSE bug 1202787</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482322" comment="libnghttp2-14-1.40.0-1.15 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199513" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9513</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9513" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9513" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9513" ref_url="https://www.suse.com/security/cve/CVE-2019-9513" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-August/005861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2259-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2260-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2473-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006320.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008541.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2114-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2115-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2120-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2232-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2234-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2264-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html" source="SUSE-SU"/>
    <description>
    Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-9513/">CVE-2019-9513</cve>
	<bugzilla href="https://bugzilla.suse.com/1145580">SUSE bug 1145580</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146094">SUSE bug 1146094</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1146184">SUSE bug 1146184</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193427">SUSE bug 1193427</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1202787">SUSE bug 1202787</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482322" comment="libnghttp2-14-1.40.0-1.15 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199636" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9636</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9636" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9636" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9636" ref_url="https://www.suse.com/security/cve/CVE-2019-9636" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0961-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005348.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005347.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14018-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1439-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006445.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1273-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1282-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00097.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1371-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1580-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
    <description>
    Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-9636/">CVE-2019-9636</cve>
	<bugzilla href="https://bugzilla.suse.com/1129346">SUSE bug 1129346</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1135433">SUSE bug 1135433</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1138459">SUSE bug 1138459</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1145004">SUSE bug 1145004</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199674" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9674</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9674" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9674" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9674" ref_url="https://www.suse.com/security/cve/CVE-2019-9674" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0467-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0854-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006666.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006878.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0696-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html" source="SUSE-SU"/>
    <description>
    Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-9674/">CVE-2019-9674</cve>
	<bugzilla href="https://bugzilla.suse.com/1162825">SUSE bug 1162825</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199740" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9740</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9740" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9740" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9740" ref_url="https://www.suse.com/security/cve/CVE-2019-9740" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005893.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2370-1" ref_url="https://www.suse.com/support/update/announcement/2019/suse-su-20192370-1.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2391-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2399-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-September/005931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007763.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008099.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2131-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2133-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the query string after a ? character) followed by an HTTP header or a Redis command. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-9740/">CVE-2019-9740</cve>
	<bugzilla href="https://bugzilla.suse.com/1129071">SUSE bug 1129071</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1130840">SUSE bug 1130840</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1132663">SUSE bug 1132663</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760851" comment="python3-urllib3-1.24-9.10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199824" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9824</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9824" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9824" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9824" ref_url="https://www.suse.com/security/cve/CVE-2019-9824" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:0825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0921-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005320.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14001-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14011-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14052-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005480.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1226-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00094.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1405-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00040.html" source="SUSE-SU"/>
    <description>
    tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.8/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-9824/">CVE-2019-9824</cve>
	<bugzilla href="https://bugzilla.suse.com/1118900">SUSE bug 1118900</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1129622">SUSE bug 1129622</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1129623">SUSE bug 1129623</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199836" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9836</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9836" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9836" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9836" ref_url="https://www.suse.com/security/cve/CVE-2019-9836" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:1792-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005686.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005683.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1770-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00032.html" source="SUSE-SU"/>
    <description>
    Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-9836/">CVE-2019-9836</cve>
	<bugzilla href="https://bugzilla.suse.com/1139383">SUSE bug 1139383</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760799" comment="kernel-firmware-20200107-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199857" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9857</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9857" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9857" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9857" ref_url="https://www.suse.com/security/cve/CVE-2019-9857" source="SUSE CVE"/>
    <description>
    In the Linux kernel through 5.0.2, the function inotify_update_existing_watch() in fs/notify/inotify/inotify_user.c neglects to call fsnotify_put_mark() with IN_MASK_CREATE after fsnotify_find_mark(), which will cause a memory leak (aka refcount leak). Finally, this will cause a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2019-9857/">CVE-2019-9857</cve>
	<bugzilla href="https://bugzilla.suse.com/1129896">SUSE bug 1129896</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199893" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9893</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9893" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9893" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9893" ref_url="https://www.suse.com/security/cve/CVE-2019-9893" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006426.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006433.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:616-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2517-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/005978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2941-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006108.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2280-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2283-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00022.html" source="SUSE-SU"/>
    <description>
    libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and potential privilege escalations.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-9893/">CVE-2019-9893</cve>
	<bugzilla href="https://bugzilla.suse.com/1128828">SUSE bug 1128828</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482393" comment="libseccomp2-2.4.1-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199923" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9923</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9923" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9923" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9923" ref_url="https://www.suse.com/security/cve/CVE-2019-9923" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1101-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:917-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:919-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:680-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:683-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:689-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:0926-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-April/005322.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-November/006107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007506.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010950.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1237-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-04/msg00077.html" source="SUSE-SU"/>
    <description>
    pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-9923/">CVE-2019-9923</cve>
	<bugzilla href="https://bugzilla.suse.com/1130496">SUSE bug 1130496</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705032" comment="tar-1.34-150000.3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199928" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9928</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9928" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9928" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9928" ref_url="https://www.suse.com/security/cve/CVE-2019-9928" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2019:14076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005559.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005560.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-June/005598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1300-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007089.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1638-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-06/msg00082.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1639-1" ref_url="https://lists.opensuse.org/opensuse-updates/2019-06/msg00171.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0678-1" ref_url="https://lists.opensuse.org/opensuse-updates/2020-05/msg00129.html" source="SUSE-SU"/>
    <description>
    GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2019-9928/">CVE-2019-9928</cve>
	<bugzilla href="https://bugzilla.suse.com/1133375">SUSE bug 1133375</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482020" comment="gstreamer-plugins-base-1.16.2-2.12 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482022" comment="libgstallocators-1_0-0-1.16.2-2.12 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482023" comment="libgstapp-1_0-0-1.16.2-2.12 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482024" comment="libgstaudio-1_0-0-1.16.2-2.12 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482026" comment="libgstgl-1_0-0-1.16.2-2.12 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482027" comment="libgstpbutils-1_0-0-1.16.2-2.12 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482028" comment="libgstriff-1_0-0-1.16.2-2.12 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482032" comment="libgsttag-1_0-0-1.16.2-2.12 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482033" comment="libgstvideo-1_0-0-1.16.2-2.12 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199936" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9936</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9936" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9936" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9936" ref_url="https://www.suse.com/security/cve/CVE-2019-9936" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1127-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1372-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html" source="SUSE-SU"/>
    <description>
    In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2019-9936/">CVE-2019-9936</cve>
	<bugzilla href="https://bugzilla.suse.com/1130326">SUSE bug 1130326</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154162">SUSE bug 1154162</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482404" comment="libsqlite3-0-3.28.0-3.9.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199937" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9937</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9937" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9937" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9937" ref_url="https://www.suse.com/security/cve/CVE-2019-9937" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:697-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1127-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:1372-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html" source="SUSE-SU"/>
    <description>
    In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2019-9937/">CVE-2019-9937</cve>
	<bugzilla href="https://bugzilla.suse.com/1130325">SUSE bug 1130325</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1154162">SUSE bug 1154162</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482404" comment="libsqlite3-0-3.28.0-3.9.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20199947" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2019-9947</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2019-9947" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9947" source="CVE"/>
    <reference ref_id="SUSE CVE-2019-9947" ref_url="https://www.suse.com/security/cve/CVE-2019-9947" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2019:740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006431.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2019:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-May/005497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:1352-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-July/005696.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:14246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-December/006249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2019:2743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2019-October/006041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007449.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2389-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2019:2393-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0086-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the path component of a URL that lacks a ? character) followed by an HTTP header or a Redis command. This is similar to the CVE-2019-9740 query string issue. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2019-9947/">CVE-2019-9947</cve>
	<bugzilla href="https://bugzilla.suse.com/1130840">SUSE bug 1130840</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1136184">SUSE bug 1136184</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1155094">SUSE bug 1155094</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201559">SUSE bug 1201559</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200030" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0030</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0030" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0030" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0030" ref_url="https://www.suse.com/security/cve/CVE-2020-0030" source="SUSE CVE"/>
    <description>
    In binder_thread_release of binder.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-145286050References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-0030/">CVE-2020-0030</cve>
	<bugzilla href="https://bugzilla.suse.com/1164096">SUSE bug 1164096</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200067" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0067</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0067" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0067" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0067" ref_url="https://www.suse.com/security/cve/CVE-2020-0067" source="SUSE CVE"/>
    <description>
    In f2fs_xattr_generic_list of xattr.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not required for exploitation.Product: Android. Versions: Android kernel. Android ID: A-120551147.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-0067/">CVE-2020-0067</cve>
	<bugzilla href="https://bugzilla.suse.com/1169391">SUSE bug 1169391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200110" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0110</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0110" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0110" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0110" ref_url="https://www.suse.com/security/cve/CVE-2020-0110" source="SUSE CVE"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In psi_write of psi.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-148159562References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-0110/">CVE-2020-0110</cve>
	<bugzilla href="https://bugzilla.suse.com/1171374">SUSE bug 1171374</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1174874">SUSE bug 1174874</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200305" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0305</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0305" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0305" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0305" ref_url="https://www.suse.com/security/cve/CVE-2020-0305" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007405.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-153467744
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-0305/">CVE-2020-0305</cve>
	<bugzilla href="https://bugzilla.suse.com/1174462">SUSE bug 1174462</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200404" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0404</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0404" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0404" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0404" ref_url="https://www.suse.com/security/cve/CVE-2020-0404" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2907-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1586-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1655-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111893654References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-0404/">CVE-2020-0404</cve>
	<bugzilla href="https://bugzilla.suse.com/1176423">SUSE bug 1176423</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200423" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0423</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0423" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0423" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0423" ref_url="https://www.suse.com/security/cve/CVE-2020-0423" source="SUSE CVE"/>
    <description>
    In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-161151868References: N/A
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-0423/">CVE-2020-0423</cve>
	<bugzilla href="https://bugzilla.suse.com/1178200">SUSE bug 1178200</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200427" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0427</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0427" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0427" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0427" ref_url="https://www.suse.com/security/cve/CVE-2020-0427" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2907-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1586-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1655-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-0427/">CVE-2020-0427</cve>
	<bugzilla href="https://bugzilla.suse.com/1176725">SUSE bug 1176725</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200431" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0431</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0431" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0431" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0431" ref_url="https://www.suse.com/security/cve/CVE-2020-0431" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2907-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007706.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007712.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007722.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3225-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-November/016787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1586-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1655-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-144161459
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-0431/">CVE-2020-0431</cve>
	<bugzilla href="https://bugzilla.suse.com/1176722">SUSE bug 1176722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1176896">SUSE bug 1176896</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200432" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0432</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0432" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0432" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0432" ref_url="https://www.suse.com/security/cve/CVE-2020-0432" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2907-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1586-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1655-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-143560807
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-0432/">CVE-2020-0432</cve>
	<bugzilla href="https://bugzilla.suse.com/1176721">SUSE bug 1176721</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177165">SUSE bug 1177165</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200435" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0435</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0435" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0435" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0435" ref_url="https://www.suse.com/security/cve/CVE-2020-0435" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-14615. Reason: This candidate is a duplicate of CVE-2018-14615. Notes: All CVE users should reference CVE-2018-14615 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-0435/">CVE-2020-0435</cve>
	<bugzilla href="https://bugzilla.suse.com/1176719">SUSE bug 1176719</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196027">SUSE bug 1196027</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200444" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0444</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0444" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0444" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0444" ref_url="https://www.suse.com/security/cve/CVE-2020-0444" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In audit_free_lsm_field of auditfilter.c, there is a possible bad kfree due to a logic error in audit_data_to_entry. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-150693166References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-0444/">CVE-2020-0444</cve>
	<bugzilla href="https://bugzilla.suse.com/1180027">SUSE bug 1180027</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180028">SUSE bug 1180028</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200465" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0465</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0465" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0465" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0465" ref_url="https://www.suse.com/security/cve/CVE-2020-0465" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0377-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-February/017944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-0465/">CVE-2020-0465</cve>
	<bugzilla href="https://bugzilla.suse.com/1180029">SUSE bug 1180029</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180030">SUSE bug 1180030</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200466" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0466</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0466" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0466" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0466" ref_url="https://www.suse.com/security/cve/CVE-2020-0466" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0377-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-February/017944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In do_epoll_ctl and ep_loop_check_proc of eventpoll.c, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147802478References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-0466/">CVE-2020-0466</cve>
	<bugzilla href="https://bugzilla.suse.com/1180031">SUSE bug 1180031</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180032">SUSE bug 1180032</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199255">SUSE bug 1199255</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200084">SUSE bug 1200084</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200543" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0543</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0543" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0543" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0543" ref_url="https://www.suse.com/security/cve/CVE-2020-0543" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14393-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006913.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006917.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006925.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006958.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1634-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1902-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007126.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008731.html" source="SUSE-SU"/>
		<reference ref_id="TID000019439" ref_url="https://www.suse.com/support/kb/doc/?id=000019439" source="SUSE-SU"/>
		<reference ref_id="TID000019643" ref_url="https://www.suse.com/support/kb/doc/?id=000019643" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0791-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0818-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0965-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-0543/">CVE-2020-0543</cve>
	<bugzilla href="https://bugzilla.suse.com/1154824">SUSE bug 1154824</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172205">SUSE bug 1172205</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172206">SUSE bug 1172206</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172207">SUSE bug 1172207</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172770">SUSE bug 1172770</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201877">SUSE bug 1201877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200548" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0548</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0548" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0548" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0548" ref_url="https://www.suse.com/security/cve/CVE-2020-0548" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:14394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006917.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006925.html" source="SUSE-SU"/>
		<reference ref_id="TID000019635" ref_url="https://www.suse.com/support/kb/doc/?id=000019635" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0791-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00016.html" source="SUSE-SU"/>
    <description>
    Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="2.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-0548/">CVE-2020-0548</cve>
	<bugzilla href="https://bugzilla.suse.com/1156353">SUSE bug 1156353</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200549" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0549</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0549" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0549" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0549" ref_url="https://www.suse.com/security/cve/CVE-2020-0549" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:14394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006917.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006925.html" source="SUSE-SU"/>
		<reference ref_id="TID000019635" ref_url="https://www.suse.com/support/kb/doc/?id=000019635" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0791-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00016.html" source="SUSE-SU"/>
    <description>
    Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-0549/">CVE-2020-0549</cve>
	<bugzilla href="https://bugzilla.suse.com/1156353">SUSE bug 1156353</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20200556" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-0556</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-0556" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0556" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-0556" ref_url="https://www.suse.com/security/cve/CVE-2020-0556" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3034-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007858.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0479-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0872-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00055.html" source="SUSE-SU"/>
    <description>
    Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-0556/">CVE-2020-0556</cve>
	<bugzilla href="https://bugzilla.suse.com/1166751">SUSE bug 1166751</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760813" comment="libbluetooth3-5.48-13.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010029" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10029</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10029" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10029" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10029" ref_url="https://www.suse.com/security/cve/CVE-2020-10029" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006661.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006614.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0668-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006655.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3024-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007618.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0381-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00033.html" source="SUSE-SU"/>
    <description>
    The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-10029/">CVE-2020-10029</cve>
	<bugzilla href="https://bugzilla.suse.com/1165784">SUSE bug 1165784</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010135" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10135</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10135" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10135" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10135" ref_url="https://www.suse.com/security/cve/CVE-2020-10135" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007405.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2610-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007408.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-10135/">CVE-2020-10135</cve>
	<bugzilla href="https://bugzilla.suse.com/1171988">SUSE bug 1171988</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010543" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10543</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10543" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10543" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10543" ref_url="https://www.suse.com/security/cve/CVE-2020-10543" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:340-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1682-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007092.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0850-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html" source="SUSE-SU"/>
    <description>
    Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-10543/">CVE-2020-10543</cve>
	<bugzilla href="https://bugzilla.suse.com/1171863">SUSE bug 1171863</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760842" comment="perl-5.26.1-7.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760843" comment="perl-base-5.26.1-7.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010663" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10663</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10663" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10663" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10663" ref_url="https://www.suse.com/security/cve/CVE-2020-10663" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0995-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006905.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1901-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007124.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0586-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00004.html" source="SUSE-SU"/>
    <description>
    The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-10663/">CVE-2020-10663</cve>
	<bugzilla href="https://bugzilla.suse.com/1167244">SUSE bug 1167244</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1171517">SUSE bug 1171517</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010690" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10690</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10690" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10690" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10690" ref_url="https://www.suse.com/security/cve/CVE-2020-10690" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14393-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006913.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
    <description>
    There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it can cause an exploitable condition as the process wakes up to terminate and clean all attached files. The system crashes due to the cdev structure being invalid (as already freed) which is pointed to by the inode.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-10690/">CVE-2020-10690</cve>
	<bugzilla href="https://bugzilla.suse.com/1170056">SUSE bug 1170056</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010701" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10701</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10701" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10701" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10701" ref_url="https://www.suse.com/security/cve/CVE-2020-10701" source="SUSE CVE"/>
    <description>
    A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-10701/">CVE-2020-10701</cve>
	<bugzilla href="https://bugzilla.suse.com/1168680">SUSE bug 1168680</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010702" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10702</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10702" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10702" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10702" ref_url="https://www.suse.com/security/cve/CVE-2020-10702" source="SUSE CVE"/>
    <description>
    A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-10702/">CVE-2020-10702</cve>
	<bugzilla href="https://bugzilla.suse.com/1168681">SUSE bug 1168681</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010708" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10708</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10708" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10708" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10708" ref_url="https://www.suse.com/security/cve/CVE-2020-10708" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2020-10708/">CVE-2020-10708</cve>
	<bugzilla href="https://bugzilla.suse.com/1169737">SUSE bug 1169737</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010711" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10711</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10711" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10711" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10711" ref_url="https://www.suse.com/security/cve/CVE-2020-10711" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_parsetag_rbm' routine, it sets the security attribute to indicate that the category bitmap is present, even if it has not been allocated. This issue leads to a NULL pointer dereference issue while importing the same category bitmap into SELinux. This flaw allows a remote network user to crash the system kernel, resulting in a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-10711/">CVE-2020-10711</cve>
	<bugzilla href="https://bugzilla.suse.com/1171191">SUSE bug 1171191</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010713" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10713</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10713" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10713" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10713" ref_url="https://www.suse.com/security/cve/CVE-2020-10713" source="SUSE CVE"/>
		<reference ref_id="BOOTHOLE-BLOG" ref_url="https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007428.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2078-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007198.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007423.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007424.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2629-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007421.html" source="SUSE-SU"/>
		<reference ref_id="TID000019673" ref_url="https://www.suse.com/support/kb/doc/?id=000019673" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.html" source="SUSE-SU"/>
    <description>
    A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker would first need to establish access to the system such as gaining physical access, obtain the ability to alter a pxe-boot network, or have remote access to a networked system with root access. With this access, an attacker could then craft a string to cause a buffer overflow by injecting a malicious payload that leads to arbitrary code execution within GRUB. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-10713/">CVE-2020-10713</cve>
	<bugzilla href="https://bugzilla.suse.com/1168994">SUSE bug 1168994</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173456">SUSE bug 1173456</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173812">SUSE bug 1173812</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199353">SUSE bug 1199353</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760789" comment="grub2-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760790" comment="grub2-arm64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760791" comment="grub2-i386-pc-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760792" comment="grub2-powerpc-ieee1275-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760793" comment="grub2-s390x-emu-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760794" comment="grub2-snapper-plugin-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760795" comment="grub2-x86_64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760796" comment="grub2-x86_64-xen-2.04-9.30.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010732" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10732</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10732" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10732" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10732" ref_url="https://www.suse.com/security/cve/CVE-2020-10732" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-10732/">CVE-2020-10732</cve>
	<bugzilla href="https://bugzilla.suse.com/1171220">SUSE bug 1171220</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010742" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10742</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10742" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10742" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10742" ref_url="https://www.suse.com/security/cve/CVE-2020-10742" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat from this vulnerability is to data confidentiality and system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-10742/">CVE-2020-10742</cve>
	<bugzilla href="https://bugzilla.suse.com/1171984">SUSE bug 1171984</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010749" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10749</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10749" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10749" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10749" ref_url="https://www.suse.com/security/cve/CVE-2020-10749" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1049-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00063.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1050-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00065.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-10749/">CVE-2020-10749</cve>
	<bugzilla href="https://bugzilla.suse.com/1172375">SUSE bug 1172375</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172410">SUSE bug 1172410</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629066" comment="cni-plugins-0.8.6-3.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010751" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10751</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10751" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10751" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10751" ref_url="https://www.suse.com/security/cve/CVE-2020-10751" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with the granted permission without further processing.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-10751/">CVE-2020-10751</cve>
	<bugzilla href="https://bugzilla.suse.com/1171189">SUSE bug 1171189</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1174963">SUSE bug 1174963</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010756" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10756</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10756" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10756" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10756" ref_url="https://www.suse.com/security/cve/CVE-2020-10756" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008910.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1895-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008990.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0987-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0994-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
    <description>
    An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-10756/">CVE-2020-10756</cve>
	<bugzilla href="https://bugzilla.suse.com/1172380">SUSE bug 1172380</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1184743">SUSE bug 1184743</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704898" comment="qemu-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499897" comment="qemu-arm-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499905" comment="qemu-ipxe-1.0.0+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499911" comment="qemu-seabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499912" comment="qemu-sgabios-8-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704899" comment="qemu-tools-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499916" comment="qemu-vgabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499917" comment="qemu-x86-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629075" comment="slirp4netns-0.4.7-3.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010757" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10757</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10757" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10757" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10757" ref_url="https://www.suse.com/security/cve/CVE-2020-10757" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1656-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1758-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007368.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-19"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-10757/">CVE-2020-10757</cve>
	<bugzilla href="https://bugzilla.suse.com/1159281">SUSE bug 1159281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172317">SUSE bug 1172317</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172437">SUSE bug 1172437</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010761" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10761</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10761" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10761" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10761" ref_url="https://www.suse.com/security/cve/CVE-2020-10761" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007171.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1108-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.html" source="SUSE-SU"/>
    <description>
    An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-10761/">CVE-2020-10761</cve>
	<bugzilla href="https://bugzilla.suse.com/1172710">SUSE bug 1172710</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010766" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10766</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10766" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10766" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10766" ref_url="https://www.suse.com/security/cve/CVE-2020-10766" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1693-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to disable SSBD protection during a context switch when additional speculative execution mitigations are in place. This issue was introduced when the per task/process conditional STIPB switching was added on top of the existing SSBD switching. The highest threat from this vulnerability is to confidentiality.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-10766/">CVE-2020-10766</cve>
	<bugzilla href="https://bugzilla.suse.com/1159281">SUSE bug 1159281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172781">SUSE bug 1172781</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010767" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10767</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10767" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10767" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10767" ref_url="https://www.suse.com/security/cve/CVE-2020-10767" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1693-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPB mitigation will be disabled when STIBP is not available or when the Enhanced Indirect Branch Restricted Speculation (IBRS) is available. This flaw allows a local attacker to perform a Spectre V2 style attack when this configuration is active. The highest threat from this vulnerability is to confidentiality.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-10767/">CVE-2020-10767</cve>
	<bugzilla href="https://bugzilla.suse.com/1159281">SUSE bug 1159281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172782">SUSE bug 1172782</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010768" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10768</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10768" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10768" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10768" ref_url="https://www.suse.com/security/cve/CVE-2020-10768" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1693-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being 'force disabled' when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-10768/">CVE-2020-10768</cve>
	<bugzilla href="https://bugzilla.suse.com/1159281">SUSE bug 1159281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172783">SUSE bug 1172783</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010773" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10773</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10773" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10773" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10773" ref_url="https://www.suse.com/security/cve/CVE-2020-10773" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-10773/">CVE-2020-10773</cve>
	<bugzilla href="https://bugzilla.suse.com/1172999">SUSE bug 1172999</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010781" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10781</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10781" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10781" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10781" ref_url="https://www.suse.com/security/cve/CVE-2020-10781" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This read allocates kernel memory and is not accounted for a user that triggers the creation of that ZRAM device. With this vulnerability, continually reading the device may consume a large amount of system memory and cause the Out-of-Memory (OOM) killer to activate and terminate random userspace processes, possibly making the system inoperable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-10781/">CVE-2020-10781</cve>
	<bugzilla href="https://bugzilla.suse.com/1173074">SUSE bug 1173074</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010878" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10878</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10878" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10878" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10878" ref_url="https://www.suse.com/security/cve/CVE-2020-10878" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:340-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1682-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007092.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0850-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html" source="SUSE-SU"/>
    <description>
    Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-10878/">CVE-2020-10878</cve>
	<bugzilla href="https://bugzilla.suse.com/1171864">SUSE bug 1171864</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760842" comment="perl-5.26.1-7.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760843" comment="perl-base-5.26.1-7.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010933" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10933</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10933" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10933" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10933" ref_url="https://www.suse.com/security/cve/CVE-2020-10933" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0995-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006711.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0586-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00004.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap. This may expose possibly sensitive data from the interpreter.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-10933/">CVE-2020-10933</cve>
	<bugzilla href="https://bugzilla.suse.com/1168938">SUSE bug 1168938</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202010942" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-10942</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-10942" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10942" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-10942" ref_url="https://www.suse.com/security/cve/CVE-2020-10942" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1085-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006727.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0543-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00035.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-10942/">CVE-2020-10942</cve>
	<bugzilla href="https://bugzilla.suse.com/1167629">SUSE bug 1167629</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011080" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11080</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11080" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11080" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11080" ref_url="https://www.suse.com/security/cve/CVE-2020-11080" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1568-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006909.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1576-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006908.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006933.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008538.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008539.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008541.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0468-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3FQEUDKQEBT4RUZ2JLDQBWSAYUJ4SCTW/" source="SUSE-SU"/>
    <description>
    In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., &gt; 32), then drop the connection.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-24"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-11080/">CVE-2020-11080</cve>
	<bugzilla href="https://bugzilla.suse.com/1172441">SUSE bug 1172441</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172442">SUSE bug 1172442</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181358">SUSE bug 1181358</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705014" comment="libnghttp2-14-1.40.0-3.5.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011102" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11102</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11102" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11102" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11102" ref_url="https://www.suse.com/security/cve/CVE-2020-11102" source="SUSE CVE"/>
    <description>
    hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-11102/">CVE-2020-11102</cve>
	<bugzilla href="https://bugzilla.suse.com/1168713">SUSE bug 1168713</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011494" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11494</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11494" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11494" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11494" ref_url="https://www.suse.com/security/cve/CVE-2020-11494" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1085-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006727.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0543-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00035.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL, aka CID-b9258a2cece4.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-11494/">CVE-2020-11494</cve>
	<bugzilla href="https://bugzilla.suse.com/1168424">SUSE bug 1168424</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011501" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11501</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11501" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11501" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11501" ref_url="https://www.suse.com/security/cve/CVE-2020-11501" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006699.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006700.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006686.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0948-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011542.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0501-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00015.html" source="SUSE-SU"/>
    <description>
    GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-11501/">CVE-2020-11501</cve>
	<bugzilla href="https://bugzilla.suse.com/1168345">SUSE bug 1168345</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011608" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11608</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11608" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11608" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11608" ref_url="https://www.suse.com/security/cve/CVE-2020-11608" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs when there are zero endpoints, aka CID-998912346c0d.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-11608/">CVE-2020-11608</cve>
	<bugzilla href="https://bugzilla.suse.com/1168829">SUSE bug 1168829</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011651" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11651</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11651" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11651" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11651" ref_url="https://www.suse.com/security/cve/CVE-2020-11651" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006766.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006762.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1392-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006763.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006765.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14403-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14404-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007158.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1974-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007156.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009063.html" source="SUSE-SU"/>
		<reference ref_id="TID000019619" ref_url="https://www.suse.com/support/kb/doc/?id=000019619" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0564-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0899-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6E3YAO2VV3WBUS7PMAT26ZYDS3AXW5VL/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2106-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MU6P3NIODW6ZMC4HZLBROO6ZEOD5KAUX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-11651/">CVE-2020-11651</cve>
	<bugzilla href="https://bugzilla.suse.com/1170595">SUSE bug 1170595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009494057" comment="python3-distro-1.5.0-3.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504114" comment="python3-salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504115" comment="salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504120" comment="salt-minion-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504125" comment="salt-transactional-update-3002.2-37.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011652" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11652</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11652" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11652" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11652" ref_url="https://www.suse.com/security/cve/CVE-2020-11652" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006766.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006762.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1392-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006763.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006765.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14403-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14404-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007158.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1974-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007156.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009063.html" source="SUSE-SU"/>
		<reference ref_id="TID000019619" ref_url="https://www.suse.com/support/kb/doc/?id=000019619" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0564-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1074-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0899-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6E3YAO2VV3WBUS7PMAT26ZYDS3AXW5VL/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2106-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MU6P3NIODW6ZMC4HZLBROO6ZEOD5KAUX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="7.2/CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-11652/">CVE-2020-11652</cve>
	<bugzilla href="https://bugzilla.suse.com/1170595">SUSE bug 1170595</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009494057" comment="python3-distro-1.5.0-3.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504114" comment="python3-salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504115" comment="salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504120" comment="salt-minion-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504125" comment="salt-transactional-update-3002.2-37.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011668" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11668</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11668" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11668" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11668" ref_url="https://www.suse.com/security/cve/CVE-2020-11668" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007355.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007357.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007359.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007358.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2525-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007706.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3656-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007925.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3705-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-11668/">CVE-2020-11668</cve>
	<bugzilla href="https://bugzilla.suse.com/1168952">SUSE bug 1168952</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173942">SUSE bug 1173942</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011739" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11739</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11739" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11739" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11739" ref_url="https://www.suse.com/security/cve/CVE-2020-11739" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1634-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007264.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0599-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00006.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read-write unlock paths don't contain a memory barrier. On Arm, this means a processor is allowed to re-order the memory access with the preceding ones. In other words, the unlock may be seen by another processor before all the memory accesses within the "critical" section. As a consequence, it may be possible to have a writer executing a critical section at the same time as readers or another writer. In other words, many of the assumptions (e.g., a variable cannot be modified after a check) in the critical sections are not safe anymore. The read-write locks are used in hypercalls (such as grant-table ones), so a malicious guest could exploit the race. For instance, there is a small window where Xen can leak memory if XENMAPSPACE_grant_table is used concurrently. A malicious guest may be able to leak memory, or cause a hypervisor crash resulting in a Denial of Service (DoS). Information leak and privilege escalation cannot be excluded.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-11739/">CVE-2020-11739</cve>
	<bugzilla href="https://bugzilla.suse.com/1168142">SUSE bug 1168142</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011740" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11740</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11740" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11740" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11740" ref_url="https://www.suse.com/security/cve/CVE-2020-11740" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1634-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007264.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0599-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00006.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. These buffers were not scrubbed.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-11740/">CVE-2020-11740</cve>
	<bugzilla href="https://bugzilla.suse.com/1168140">SUSE bug 1168140</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011741" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11741</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11741" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11741" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11741" ref_url="https://www.suse.com/security/cve/CVE-2020-11741" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1634-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007264.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0599-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00006.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly gain privileges. For guests for which "active" profiling was enabled by the administrator, the xenoprof code uses the standard Xen shared ring structure. Unfortunately, this code did not treat the guest as a potential adversary: it trusts the guest not to modify buffer size information or modify head / tail pointers in unexpected ways. This can crash the host (DoS). Privilege escalation cannot be ruled out.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-11741/">CVE-2020-11741</cve>
	<bugzilla href="https://bugzilla.suse.com/1168140">SUSE bug 1168140</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011742" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11742</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11742" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11742" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11742" ref_url="https://www.suse.com/security/cve/CVE-2020-11742" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1634-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007264.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0599-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00006.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of bad continuation handling in GNTTABOP_copy. Grant table operations are expected to return 0 for success, and a negative number for errors. The fix for CVE-2017-12135 introduced a path through grant copy handling where success may be returned to the caller without any action taken. In particular, the status fields of individual operations are left uninitialised, and may result in errant behaviour in the caller of GNTTABOP_copy. A buggy or malicious guest can construct its grant table in such a way that, when a backend domain tries to copy a grant, it hits the incorrect exit path. This returns success to the caller without doing anything, which may cause crashes or other incorrect behaviour.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-11742/">CVE-2020-11742</cve>
	<bugzilla href="https://bugzilla.suse.com/1169392">SUSE bug 1169392</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011743" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11743</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11743" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11743" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11743" ref_url="https://www.suse.com/security/cve/CVE-2020-11743" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1634-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006957.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0599-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00006.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of a bad error path in GNTTABOP_map_grant. Grant table operations are expected to return 0 for success, and a negative number for errors. Some misplaced brackets cause one error path to return 1 instead of a negative value. The grant table code in Linux treats this condition as success, and proceeds with incorrectly initialised state. A buggy or malicious guest can construct its grant table in such a way that, when a backend domain tries to map a grant, it hits the incorrect error path. This will crash a Linux based dom0 or backend domain.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-11743/">CVE-2020-11743</cve>
	<bugzilla href="https://bugzilla.suse.com/1168143">SUSE bug 1168143</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011869" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11869</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11869" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11869" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11869" ref_url="https://www.suse.com/security/cve/CVE-2020-11869" source="SUSE CVE"/>
    <description>
    An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati-2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-11869/">CVE-2020-11869</cve>
	<bugzilla href="https://bugzilla.suse.com/1170537">SUSE bug 1170537</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188609">SUSE bug 1188609</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011884" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11884</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11884" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11884" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11884" ref_url="https://www.suse.com/security/cve/CVE-2020-11884" source="SUSE CVE"/>
    <description>
    In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-11884/">CVE-2020-11884</cve>
	<bugzilla href="https://bugzilla.suse.com/1170030">SUSE bug 1170030</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173947">SUSE bug 1173947</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011935" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11935</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11935" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11935" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11935" ref_url="https://www.suse.com/security/cve/CVE-2020-11935" source="SUSE CVE"/>
    <description>
    It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-08"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-11935/">CVE-2020-11935</cve>
	<bugzilla href="https://bugzilla.suse.com/1173977">SUSE bug 1173977</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202011947" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-11947</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-11947" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11947" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-11947" ref_url="https://www.suse.com/security/cve/CVE-2020-11947" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14774-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019812.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SDUPZEIOIEXWFR2ZTWFFOIO2ZA3AI3VM/" source="SUSE-SU"/>
    <description>
    iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-11947/">CVE-2020-11947</cve>
	<bugzilla href="https://bugzilla.suse.com/1180523">SUSE bug 1180523</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012049" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12049</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12049" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12049" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12049" ref_url="https://www.suse.com/security/cve/CVE-2020-12049" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009192.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2470-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009214.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2590-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009240.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009330.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1204-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LPUICUYAOLJREPLAWO5JOKCXD4HSH4KT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2810-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ILND7MBTQAFIRZBI5CMERWHRUVEAKAOD/" source="SUSE-SU"/>
    <description>
    An issue was discovered in dbus &gt;= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-12049/">CVE-2020-12049</cve>
	<bugzilla href="https://bugzilla.suse.com/1172505">SUSE bug 1172505</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704937" comment="dbus-1-1.12.2-8.11.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704938" comment="libdbus-1-3-1.12.2-8.11.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012243" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12243</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12243" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12243" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12243" ref_url="https://www.suse.com/security/cve/CVE-2020-12243" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:160-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:161-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006790.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006806.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:170-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006807.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006783.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1210-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006805.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006801.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0647-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00016.html" source="SUSE-SU"/>
    <description>
    In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-12243/">CVE-2020-12243</cve>
	<bugzilla href="https://bugzilla.suse.com/1170771">SUSE bug 1170771</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012321" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12321</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12321" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12321" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12321" ref_url="https://www.suse.com/security/cve/CVE-2020-12321" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3330-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007786.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1960-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SNZ3NYJWZSI2ISRG5U4RX3XMDBRHDRTX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1962-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WWOUPKVHO4A2R27BZDEYM2EMS4RXKDM4/" source="SUSE-SU"/>
    <description>
    Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.6/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-12321/">CVE-2020-12321</cve>
	<bugzilla href="https://bugzilla.suse.com/1178671">SUSE bug 1178671</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760799" comment="kernel-firmware-20200107-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012351" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12351</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12351" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12351" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12351" ref_url="https://www.suse.com/security/cve/CVE-2020-12351" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2980-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2981-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007601.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007798.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3400-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007802.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007803.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3449-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007816.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="TID000019735" ref_url="https://www.suse.com/support/kb/doc/?id=000019735" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1682-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-12351/">CVE-2020-12351</cve>
	<bugzilla href="https://bugzilla.suse.com/1177724">SUSE bug 1177724</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177729">SUSE bug 1177729</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178397">SUSE bug 1178397</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012352" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12352</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12352" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12352" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12352" ref_url="https://www.suse.com/security/cve/CVE-2020-12352" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2980-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2981-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007601.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="TID000019735" ref_url="https://www.suse.com/support/kb/doc/?id=000019735" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1682-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.1/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-12352/">CVE-2020-12352</cve>
	<bugzilla href="https://bugzilla.suse.com/1177725">SUSE bug 1177725</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178398">SUSE bug 1178398</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012362" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12362</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12362" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12362" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12362" ref_url="https://www.suse.com/security/cve/CVE-2020-12362" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008452.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0393-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/R5J7TLH5AZYERG7B3PW3ALPYSBMFCGV5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0407-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KH2XS5MRKRSCX3I5AS4LGZH576PO6KUD/" source="SUSE-SU"/>
    <description>
    Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-12362/">CVE-2020-12362</cve>
	<bugzilla href="https://bugzilla.suse.com/1181720">SUSE bug 1181720</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182033">SUSE bug 1182033</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190859">SUSE bug 1190859</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705005" comment="kernel-default-5.3.18-24.52.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705006" comment="kernel-default-base-5.3.18-24.52.1.9.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012363" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12363</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12363" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12363" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12363" ref_url="https://www.suse.com/security/cve/CVE-2020-12363" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008452.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0393-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/R5J7TLH5AZYERG7B3PW3ALPYSBMFCGV5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0407-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KH2XS5MRKRSCX3I5AS4LGZH576PO6KUD/" source="SUSE-SU"/>
    <description>
    Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="1.9/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-12363/">CVE-2020-12363</cve>
	<bugzilla href="https://bugzilla.suse.com/1181720">SUSE bug 1181720</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181735">SUSE bug 1181735</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705005" comment="kernel-default-5.3.18-24.52.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705006" comment="kernel-default-base-5.3.18-24.52.1.9.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012364" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12364</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12364" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12364" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12364" ref_url="https://www.suse.com/security/cve/CVE-2020-12364" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008452.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0393-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/R5J7TLH5AZYERG7B3PW3ALPYSBMFCGV5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0407-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KH2XS5MRKRSCX3I5AS4LGZH576PO6KUD/" source="SUSE-SU"/>
    <description>
    Null pointer reference in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before version Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="1.9/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-12364/">CVE-2020-12364</cve>
	<bugzilla href="https://bugzilla.suse.com/1181720">SUSE bug 1181720</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181736">SUSE bug 1181736</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705005" comment="kernel-default-5.3.18-24.52.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705006" comment="kernel-default-base-5.3.18-24.52.1.9.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012373" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12373</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12373" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12373" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12373" ref_url="https://www.suse.com/security/cve/CVE-2020-12373" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008452.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0393-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/R5J7TLH5AZYERG7B3PW3ALPYSBMFCGV5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0407-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KH2XS5MRKRSCX3I5AS4LGZH576PO6KUD/" source="SUSE-SU"/>
    <description>
    Expired pointer dereference in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="1.9/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-12373/">CVE-2020-12373</cve>
	<bugzilla href="https://bugzilla.suse.com/1181720">SUSE bug 1181720</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181738">SUSE bug 1181738</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705005" comment="kernel-default-5.3.18-24.52.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705006" comment="kernel-default-base-5.3.18-24.52.1.9.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012399" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12399</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12399" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12399" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12399" ref_url="https://www.suse.com/security/cve/CVE-2020-12399" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:299-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14418-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007069.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0854-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00047.html" source="SUSE-SU"/>
    <description>
    NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird &lt; 68.9.0, Firefox &lt; 77, and Firefox ESR &lt; 68.9.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-12399/">CVE-2020-12399</cve>
	<bugzilla href="https://bugzilla.suse.com/1171978">SUSE bug 1171978</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172402">SUSE bug 1172402</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012400" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12400</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12400" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12400" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12400" ref_url="https://www.suse.com/security/cve/CVE-2020-12400" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
    <description>
    When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox &lt; 80 and Firefox for Android &lt; 80.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-12400/">CVE-2020-12400</cve>
	<bugzilla href="https://bugzilla.suse.com/1174763">SUSE bug 1174763</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1175686">SUSE bug 1175686</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009632956" comment="libfreebl3-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632960" comment="libsoftokn3-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632964" comment="mozilla-nspr-4.32-3.20.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632967" comment="mozilla-nss-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632969" comment="mozilla-nss-certs-3.68-3.56.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012401" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12401</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12401" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12401" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12401" ref_url="https://www.suse.com/security/cve/CVE-2020-12401" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
    <description>
    During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox &lt; 80 and Firefox for Android &lt; 80.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-12401/">CVE-2020-12401</cve>
	<bugzilla href="https://bugzilla.suse.com/1174763">SUSE bug 1174763</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1175686">SUSE bug 1175686</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009632956" comment="libfreebl3-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632960" comment="libsoftokn3-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632964" comment="mozilla-nspr-4.32-3.20.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632967" comment="mozilla-nss-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632969" comment="mozilla-nss-certs-3.68-3.56.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012402" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12402</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12402" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12402" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12402" ref_url="https://www.suse.com/security/cve/CVE-2020-12402" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14418-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1898-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007123.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007121.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0953-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0955-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0983-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1017-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html" source="SUSE-SU"/>
    <description>
    During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does not generate RSA keys in normal operation and is not affected, but products built on top of it might. This vulnerability affects Firefox &lt; 78.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-12402/">CVE-2020-12402</cve>
	<bugzilla href="https://bugzilla.suse.com/1173032">SUSE bug 1173032</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173576">SUSE bug 1173576</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1174230">SUSE bug 1174230</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628729" comment="libfreebl3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628731" comment="libsoftokn3-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628733" comment="mozilla-nss-3.53.1-3.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628735" comment="mozilla-nss-certs-3.53.1-3.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012403" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12403</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12403" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12403" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12403" ref_url="https://www.suse.com/security/cve/CVE-2020-12403" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-12403/">CVE-2020-12403</cve>
	<bugzilla href="https://bugzilla.suse.com/1174763">SUSE bug 1174763</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009632956" comment="libfreebl3-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632960" comment="libsoftokn3-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632964" comment="mozilla-nspr-4.32-3.20.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632967" comment="mozilla-nss-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632969" comment="mozilla-nss-certs-3.68-3.56.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012413" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12413</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12413" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12413" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12413" ref_url="https://www.suse.com/security/cve/CVE-2020-12413" source="SUSE CVE"/>
		<reference ref_id="TID000019697" ref_url="https://www.suse.com/support/kb/doc/?id=000019697" source="SUSE-SU"/>
    <description>
    The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-12413/">CVE-2020-12413</cve>
	<bugzilla href="https://bugzilla.suse.com/1176332">SUSE bug 1176332</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009338955" comment="libfreebl3 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338959" comment="libsoftokn3 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338881" comment="mozilla-nss is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338964" comment="mozilla-nss-certs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012430" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12430</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12430" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12430" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12430" ref_url="https://www.suse.com/security/cve/CVE-2020-12430" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:1208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006819.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-12430/">CVE-2020-12430</cve>
	<bugzilla href="https://bugzilla.suse.com/1170765">SUSE bug 1170765</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012464" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12464</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12464" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12464" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12464" ref_url="https://www.suse.com/security/cve/CVE-2020-12464" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
    <description>
    usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="1.8/CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-12464/">CVE-2020-12464</cve>
	<bugzilla href="https://bugzilla.suse.com/1170901">SUSE bug 1170901</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012465" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12465</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12465" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12465" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12465" ref_url="https://www.suse.com/security/cve/CVE-2020-12465" source="SUSE CVE"/>
    <description>
    An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-12465/">CVE-2020-12465</cve>
	<bugzilla href="https://bugzilla.suse.com/1170828">SUSE bug 1170828</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1170888">SUSE bug 1170888</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012652" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12652</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12652" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12652" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12652" ref_url="https://www.suse.com/security/cve/CVE-2020-12652" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14393-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006913.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to hold an incorrect lock during the ioctl operation and trigger a race condition, i.e., a "double fetch" vulnerability, aka CID-28d76df18f0a. NOTE: the vendor states "The security impact of this bug is not as bad as it could have been because these operations are all privileged and root already has enormous destructive power."
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-12652/">CVE-2020-12652</cve>
	<bugzilla href="https://bugzilla.suse.com/1171218">SUSE bug 1171218</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012653" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12653</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12653" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12653" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12653" ref_url="https://www.suse.com/security/cve/CVE-2020-12653" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14393-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006913.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1475-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
    <description>
    An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, aka CID-b70261a288ea.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-19"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-12653/">CVE-2020-12653</cve>
	<bugzilla href="https://bugzilla.suse.com/1159281">SUSE bug 1159281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1171195">SUSE bug 1171195</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1171254">SUSE bug 1171254</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012654" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12654</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12654" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12654" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12654" ref_url="https://www.suse.com/security/cve/CVE-2020-12654" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14393-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006913.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1475-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
    <description>
    An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wmm.c allows a remote AP to trigger a heap-based buffer overflow because of an incorrect memcpy, aka CID-3a9b153c5591.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-19"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8/CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-12654/">CVE-2020-12654</cve>
	<bugzilla href="https://bugzilla.suse.com/1159281">SUSE bug 1159281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1171202">SUSE bug 1171202</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1171252">SUSE bug 1171252</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012655" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12655</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12655" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12655" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12655" ref_url="https://www.suse.com/security/cve/CVE-2020-12655" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in xfs_agf_verify in fs/xfs/libxfs/xfs_alloc.c in the Linux kernel through 5.6.10. Attackers may trigger a sync of excessive duration via an XFS v5 image with crafted metadata, aka CID-d0c7feaf8767.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-12655/">CVE-2020-12655</cve>
	<bugzilla href="https://bugzilla.suse.com/1171217">SUSE bug 1171217</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012656" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12656</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12656" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12656" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12656" ref_url="https://www.suse.com/security/cve/CVE-2020-12656" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through 5.6.10 lacks certain domain_release calls, leading to a memory leak. Note: This was disputed with the assertion that the issue does not grant any access not already available. It is a problem that on unloading a specific kernel module some memory is leaked, but loading kernel modules is a privileged operation. A user could also write a kernel module to consume any amount of memory they like and load that replicating the effect of this bug.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-12656/">CVE-2020-12656</cve>
	<bugzilla href="https://bugzilla.suse.com/1171219">SUSE bug 1171219</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012657" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12657</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12657" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12657" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12657" ref_url="https://www.suse.com/security/cve/CVE-2020-12657" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-12657/">CVE-2020-12657</cve>
	<bugzilla href="https://bugzilla.suse.com/1171205">SUSE bug 1171205</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201585">SUSE bug 1201585</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012659" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12659</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12659" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12659" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12659" ref_url="https://www.suse.com/security/cve/CVE-2020-12659" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom validation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-12659/">CVE-2020-12659</cve>
	<bugzilla href="https://bugzilla.suse.com/1171214">SUSE bug 1171214</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012723" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12723</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12723" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12723" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12723" ref_url="https://www.suse.com/security/cve/CVE-2020-12723" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:340-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1682-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007092.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0850-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00044.html" source="SUSE-SU"/>
    <description>
    regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-12723/">CVE-2020-12723</cve>
	<bugzilla href="https://bugzilla.suse.com/1171866">SUSE bug 1171866</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760842" comment="perl-5.26.1-7.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760843" comment="perl-base-5.26.1-7.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012762" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12762</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12762" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12762" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12762" ref_url="https://www.suse.com/security/cve/CVE-2020-12762" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0184-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3001-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2135-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014792.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0184-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LS5Y2M6XDX2JOBPPLIMAXXAXRPAU65ND/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0184-2" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IDXGYZS2VAIBN2IO5VQRKJVJGNOKHZF7/" source="SUSE-SU"/>
    <description>
    json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-12"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-12762/">CVE-2020-12762</cve>
	<bugzilla href="https://bugzilla.suse.com/1171479">SUSE bug 1171479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208644">SUSE bug 1208644</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664167" comment="libjson-c3-0.13-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012769" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12769</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12769" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12769" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12769" ref_url="https://www.suse.com/security/cve/CVE-2020-12769" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-12769/">CVE-2020-12769</cve>
	<bugzilla href="https://bugzilla.suse.com/1171983">SUSE bug 1171983</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012771" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12771</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12771" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12771" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12771" ref_url="https://www.suse.com/security/cve/CVE-2020-12771" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1062-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-12771/">CVE-2020-12771</cve>
	<bugzilla href="https://bugzilla.suse.com/1171732">SUSE bug 1171732</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012825" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12825</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12825" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12825" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12825" ref_url="https://www.suse.com/security/cve/CVE-2020-12825" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2909-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/012001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012482.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1294-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FYZZYH2MI4PFNRWE2NZ5CTA5TOHKDLPC/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3123-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WG6EJIK3ZOQTMMMAGVUCMM2QCK7CQQ77/" source="SUSE-SU"/>
    <description>
    libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-12825/">CVE-2020-12825</cve>
	<bugzilla href="https://bugzilla.suse.com/1171685">SUSE bug 1171685</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1203730">SUSE bug 1203730</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208647">SUSE bug 1208647</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704945" comment="libcroco-0_6-3-0.6.13-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012829" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12829</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12829" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12829" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12829" ref_url="https://www.suse.com/security/cve/CVE-2020-12829" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
    <description>
    In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host, resulting in a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-12829/">CVE-2020-12829</cve>
	<bugzilla href="https://bugzilla.suse.com/1172385">SUSE bug 1172385</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704859" comment="qemu-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499829" comment="qemu-arm-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499837" comment="qemu-ipxe-1.0.0+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499843" comment="qemu-seabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499844" comment="qemu-sgabios-8-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704860" comment="qemu-tools-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499848" comment="qemu-vgabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499849" comment="qemu-x86-4.2.1-11.16.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012888" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12888</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12888" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12888" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12888" ref_url="https://www.suse.com/security/cve/CVE-2020-12888" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-12888/">CVE-2020-12888</cve>
	<bugzilla href="https://bugzilla.suse.com/1159281">SUSE bug 1159281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1171868">SUSE bug 1171868</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1176979">SUSE bug 1176979</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179612">SUSE bug 1179612</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202012912" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-12912</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-12912" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12912" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-12912" ref_url="https://www.suse.com/security/cve/CVE-2020-12912" source="SUSE CVE"/>
    <description>
    A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Running Average Power Limit (RAPL) interface to show various side channel attacks. In line with industry partners, AMD has updated the RAPL interface to require privileged access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-12912/">CVE-2020-12912</cve>
	<bugzilla href="https://bugzilla.suse.com/1178760">SUSE bug 1178760</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013143" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13143</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13143" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13143" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13143" ref_url="https://www.suse.com/security/cve/CVE-2020-13143" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0801-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-13143/">CVE-2020-13143</cve>
	<bugzilla href="https://bugzilla.suse.com/1171982">SUSE bug 1171982</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013253" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13253</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13253" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13253" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13253" ref_url="https://www.suse.com/security/cve/CVE-2020-13253" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0210-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010125.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0210-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0210-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ORE7QLMZXD7OV3HIKQUG3SXU2RG6ONFC/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0210-2" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IUV2UU2CMT6KXSJ7THBLFDIVHI27MZFH/" source="SUSE-SU"/>
    <description>
    sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-17"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-13253/">CVE-2020-13253</cve>
	<bugzilla href="https://bugzilla.suse.com/1172033">SUSE bug 1172033</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705033" comment="qemu-4.2.1-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705034" comment="qemu-arm-4.2.1-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667529" comment="qemu-ipxe-1.0.0+-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667533" comment="qemu-seabios-1.12.1+-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667534" comment="qemu-sgabios-8-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705035" comment="qemu-tools-4.2.1-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667539" comment="qemu-vgabios-1.12.1+-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667540" comment="qemu-x86-4.2.1-11.34.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013361" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13361</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13361" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13361" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13361" ref_url="https://www.suse.com/security/cve/CVE-2020-13361" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1108-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.html" source="SUSE-SU"/>
    <description>
    In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.9/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-13361/">CVE-2020-13361</cve>
	<bugzilla href="https://bugzilla.suse.com/1172384">SUSE bug 1172384</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013362" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13362</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13362" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13362" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13362" ref_url="https://www.suse.com/security/cve/CVE-2020-13362" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1108-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.html" source="SUSE-SU"/>
    <description>
    In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-13362/">CVE-2020-13362</cve>
	<bugzilla href="https://bugzilla.suse.com/1172383">SUSE bug 1172383</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013401" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13401</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13401" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13401" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13401" ref_url="https://www.suse.com/security/cve/CVE-2020-13401" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1657-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1657-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1664-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006968.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0846-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00040.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-13401/">CVE-2020-13401</cve>
	<bugzilla href="https://bugzilla.suse.com/1172375">SUSE bug 1172375</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172377">SUSE bug 1172377</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013434" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13434</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13434" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13434" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13434" ref_url="https://www.suse.com/security/cve/CVE-2020-13434" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-13434/">CVE-2020-13434</cve>
	<bugzilla href="https://bugzilla.suse.com/1172115">SUSE bug 1172115</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013435" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13435</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13435" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13435" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13435" ref_url="https://www.suse.com/security/cve/CVE-2020-13435" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-13435/">CVE-2020-13435</cve>
	<bugzilla href="https://bugzilla.suse.com/1172091">SUSE bug 1172091</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013630" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13630</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13630" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13630" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13630" ref_url="https://www.suse.com/security/cve/CVE-2020-13630" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-13630/">CVE-2020-13630</cve>
	<bugzilla href="https://bugzilla.suse.com/1172234">SUSE bug 1172234</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013631" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13631</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13631" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13631" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13631" ref_url="https://www.suse.com/security/cve/CVE-2020-13631" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-13631/">CVE-2020-13631</cve>
	<bugzilla href="https://bugzilla.suse.com/1172236">SUSE bug 1172236</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013632" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13632</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13632" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13632" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13632" ref_url="https://www.suse.com/security/cve/CVE-2020-13632" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-13632/">CVE-2020-13632</cve>
	<bugzilla href="https://bugzilla.suse.com/1172240">SUSE bug 1172240</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013645" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13645</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13645" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13645" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13645" ref_url="https://www.suse.com/security/cve/CVE-2020-13645" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:3944-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3997-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009879.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4004-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009886.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1094-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42QNVR5Y3Z3YQLA2G7H66ZAGRYHVNWHT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1554-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7ALNGEQGJBIVTIE7PVRV4LMX5VCNHFOZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3944-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3WJQDO7GLZV6KOOPFA2ZGLO6YGORWTRO/" source="SUSE-SU"/>
    <description>
    In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-13645/">CVE-2020-13645</cve>
	<bugzilla href="https://bugzilla.suse.com/1172460">SUSE bug 1172460</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705002" comment="glib-networking-2.62.4-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013659" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13659</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13659" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13659" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13659" ref_url="https://www.suse.com/security/cve/CVE-2020-13659" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1108-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.html" source="SUSE-SU"/>
    <description>
    address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-13659/">CVE-2020-13659</cve>
	<bugzilla href="https://bugzilla.suse.com/1172386">SUSE bug 1172386</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013777" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13777</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13777" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13777" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13777" ref_url="https://www.suse.com/security/cve/CVE-2020-13777" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006939.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006910.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0790-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00015.html" source="SUSE-SU"/>
    <description>
    GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-13777/">CVE-2020-13777</cve>
	<bugzilla href="https://bugzilla.suse.com/1172461">SUSE bug 1172461</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1172506">SUSE bug 1172506</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013790" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13790</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13790" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13790" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13790" ref_url="https://www.suse.com/security/cve/CVE-2020-13790" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2569-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007379.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1413-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00031.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1458-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00062.html" source="SUSE-SU"/>
    <description>
    libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-13790/">CVE-2020-13790</cve>
	<bugzilla href="https://bugzilla.suse.com/1172491">SUSE bug 1172491</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628779" comment="libjpeg8-8.1.2-5.15.7 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013800" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13800</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13800" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13800" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13800" ref_url="https://www.suse.com/security/cve/CVE-2020-13800" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007171.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1108-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00086.html" source="SUSE-SU"/>
    <description>
    ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or ati_mm_write call.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-13800/">CVE-2020-13800</cve>
	<bugzilla href="https://bugzilla.suse.com/1172495">SUSE bug 1172495</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013844" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13844</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13844" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13844" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13844" ref_url="https://www.suse.com/security/cve/CVE-2020-13844" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:552-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007586.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:553-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:567-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:568-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:571-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:572-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007643.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007644.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:579-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:669-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:670-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1007-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007963.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1692-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00040.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1693-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00039.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2300-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J4EOEHZ7Q27TTGN54YMFIIKDEJ5OS3SI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2301-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OIESM64GYREKLMRLTSQUIOYAUT6QG6A2/" source="SUSE-SU"/>
    <description>
    Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-13844/">CVE-2020-13844</cve>
	<bugzilla href="https://bugzilla.suse.com/1172798">SUSE bug 1172798</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628610" comment="libgcc_s1-10.2.1+git583-1.3.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628625" comment="libstdc++6-10.2.1+git583-1.3.4 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013974" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13974</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13974" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13974" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13974" ref_url="https://www.suse.com/security/cve/CVE-2020-13974" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1693-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does not lead to a security issue in this case.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-13974/">CVE-2020-13974</cve>
	<bugzilla href="https://bugzilla.suse.com/1172775">SUSE bug 1172775</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013987" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13987</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13987" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13987" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13987" ref_url="https://www.suse.com/security/cve/CVE-2020-13987" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008407.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011912.html" source="SUSE-SU"/>
		<reference ref_id="TID000019813" ref_url="https://www.suse.com/support/kb/doc/?id=000019813" source="SUSE-SU"/>
    <description>
    An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-16"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-13987/">CVE-2020-13987</cve>
	<bugzilla href="https://bugzilla.suse.com/1179907">SUSE bug 1179907</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179908">SUSE bug 1179908</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193385">SUSE bug 1193385</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705047" comment="iscsiuio-0.7.8.6-22.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705048" comment="libopeniscsiusr0_2_0-2.1.4-22.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705049" comment="open-iscsi-2.1.4-22.14.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202013988" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-13988</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-13988" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13988" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-13988" ref_url="https://www.suse.com/security/cve/CVE-2020-13988" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008407.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011912.html" source="SUSE-SU"/>
		<reference ref_id="TID000019813" ref_url="https://www.suse.com/support/kb/doc/?id=000019813" source="SUSE-SU"/>
    <description>
    An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsing TCP MSS options of IPv4 network packets in uip_process in net/ipv4/uip.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-16"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-13988/">CVE-2020-13988</cve>
	<bugzilla href="https://bugzilla.suse.com/1179907">SUSE bug 1179907</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179908">SUSE bug 1179908</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193385">SUSE bug 1193385</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705047" comment="iscsiuio-0.7.8.6-22.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705048" comment="libopeniscsiusr0_2_0-2.1.4-22.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705049" comment="open-iscsi-2.1.4-22.14.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014145" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14145</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14145" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14145" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14145" ref_url="https://www.suse.com/security/cve/CVE-2020-14145" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3866-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3882-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0022-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008149.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2240-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OTSUNUWKKFI2BZV3IR5RLHAQFXINNKM7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2298-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/D34ALFN2MMC67CCWTOANPH5DLTSAHLOG/" source="SUSE-SU"/>
    <description>
    The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-14145/">CVE-2020-14145</cve>
	<bugzilla href="https://bugzilla.suse.com/1173513">SUSE bug 1173513</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177569">SUSE bug 1177569</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189078">SUSE bug 1189078</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760841" comment="openssh-8.1p1-5.12.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14155" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14155" ref_url="https://www.suse.com/security/cve/CVE-2020-14155" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:472-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009675.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:473-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009676.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:476-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-October/020654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009722.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009725.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009758.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:571-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:572-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3529-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-October/020617.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3652-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009715.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1441-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ANBRV4PU5AWEEYUWZYBLJCQBG3AHEGD/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3529-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DOG6FED4Y3TBAFL2V2XUUC43MKZLFGH3/" source="SUSE-SU"/>
    <description>
    libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-14155/">CVE-2020-14155</cve>
	<bugzilla href="https://bugzilla.suse.com/1172974">SUSE bug 1172974</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704972" comment="libpcre1-8.45-20.10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014305" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14305</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14305" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14305" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14305" ref_url="https://www.suse.com/security/cve/CVE-2020-14305" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-14305/">CVE-2020-14305</cve>
	<bugzilla href="https://bugzilla.suse.com/1173346">SUSE bug 1173346</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014308" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14308</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14308" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14308" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14308" ref_url="https://www.suse.com/security/cve/CVE-2020-14308" source="SUSE CVE"/>
		<reference ref_id="BOOTHOLE-BLOG" ref_url="https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2078-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007198.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007197.html" source="SUSE-SU"/>
		<reference ref_id="TID000019673" ref_url="https://www.suse.com/support/kb/doc/?id=000019673" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.html" source="SUSE-SU"/>
    <description>
    In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integrity, confidentiality and availability impacts during the boot process.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14308/">CVE-2020-14308</cve>
	<bugzilla href="https://bugzilla.suse.com/1168994">SUSE bug 1168994</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173812">SUSE bug 1173812</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760789" comment="grub2-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760790" comment="grub2-arm64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760791" comment="grub2-i386-pc-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760792" comment="grub2-powerpc-ieee1275-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760793" comment="grub2-s390x-emu-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760794" comment="grub2-snapper-plugin-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760795" comment="grub2-x86_64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760796" comment="grub2-x86_64-xen-2.04-9.30.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014309" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14309</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14309" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14309" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14309" ref_url="https://www.suse.com/security/cve/CVE-2020-14309" source="SUSE CVE"/>
		<reference ref_id="BOOTHOLE-BLOG" ref_url="https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2078-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007198.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007197.html" source="SUSE-SU"/>
		<reference ref_id="TID000019673" ref_url="https://www.suse.com/support/kb/doc/?id=000019673" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.html" source="SUSE-SU"/>
    <description>
    There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14309/">CVE-2020-14309</cve>
	<bugzilla href="https://bugzilla.suse.com/1168994">SUSE bug 1168994</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173812">SUSE bug 1173812</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760789" comment="grub2-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760790" comment="grub2-arm64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760791" comment="grub2-i386-pc-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760792" comment="grub2-powerpc-ieee1275-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760793" comment="grub2-s390x-emu-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760794" comment="grub2-snapper-plugin-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760795" comment="grub2-x86_64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760796" comment="grub2-x86_64-xen-2.04-9.30.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014310" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14310</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14310" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14310" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14310" ref_url="https://www.suse.com/security/cve/CVE-2020-14310" source="SUSE CVE"/>
		<reference ref_id="BOOTHOLE-BLOG" ref_url="https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2078-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007198.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007197.html" source="SUSE-SU"/>
		<reference ref_id="TID000019673" ref_url="https://www.suse.com/support/kb/doc/?id=000019673" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.html" source="SUSE-SU"/>
    <description>
    There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14310/">CVE-2020-14310</cve>
	<bugzilla href="https://bugzilla.suse.com/1168994">SUSE bug 1168994</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173812">SUSE bug 1173812</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760789" comment="grub2-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760790" comment="grub2-arm64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760791" comment="grub2-i386-pc-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760792" comment="grub2-powerpc-ieee1275-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760793" comment="grub2-s390x-emu-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760794" comment="grub2-snapper-plugin-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760795" comment="grub2-x86_64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760796" comment="grub2-x86_64-xen-2.04-9.30.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014311" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14311</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14311" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14311" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14311" ref_url="https://www.suse.com/security/cve/CVE-2020-14311" source="SUSE CVE"/>
		<reference ref_id="BOOTHOLE-BLOG" ref_url="https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2078-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007198.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007197.html" source="SUSE-SU"/>
		<reference ref_id="TID000019673" ref_url="https://www.suse.com/support/kb/doc/?id=000019673" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.html" source="SUSE-SU"/>
    <description>
    There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14311/">CVE-2020-14311</cve>
	<bugzilla href="https://bugzilla.suse.com/1168994">SUSE bug 1168994</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173812">SUSE bug 1173812</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760789" comment="grub2-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760790" comment="grub2-arm64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760791" comment="grub2-i386-pc-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760792" comment="grub2-powerpc-ieee1275-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760793" comment="grub2-s390x-emu-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760794" comment="grub2-snapper-plugin-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760795" comment="grub2-x86_64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760796" comment="grub2-x86_64-xen-2.04-9.30.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014312" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14312</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14312" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14312" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14312" ref_url="https://www.suse.com/security/cve/CVE-2020-14312" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1426-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q5SXZU2UVUXVIVOLI6OT32WIQ6OJBE5E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3530-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2DP73HQCB6UNPUB54KPOZEMBUQDVN6M6/" source="SUSE-SU"/>
    <description>
    A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option `local-service` is not enabled. Running dnsmasq in this manner may inadvertently make it an open resolver accessible from any address on the internet. This flaw allows an attacker to conduct a Distributed Denial of Service (DDoS) against other systems.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-14312/">CVE-2020-14312</cve>
	<bugzilla href="https://bugzilla.suse.com/1173646">SUSE bug 1173646</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009653320" comment="dnsmasq-2.86-7.14.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014314" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14314</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14314" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14314" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14314" ref_url="https://www.suse.com/security/cve/CVE-2020-14314" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007348.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007350.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007375.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2576-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007405.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2610-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007408.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007419.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007426.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1325-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-14314/">CVE-2020-14314</cve>
	<bugzilla href="https://bugzilla.suse.com/1173798">SUSE bug 1173798</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014331" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14331</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14331" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14331" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14331" ref_url="https://www.suse.com/security/cve/CVE-2020-14331" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007350.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007367.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007355.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007357.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007359.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2515-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2517-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007358.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2525-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2537-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007371.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007375.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2576-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007405.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2610-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007408.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007419.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007426.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1325-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with access to the VGA console to crash the system, potentially escalating their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14331/">CVE-2020-14331</cve>
	<bugzilla href="https://bugzilla.suse.com/1174205">SUSE bug 1174205</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1174247">SUSE bug 1174247</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014339" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14339</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14339" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14339" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14339" ref_url="https://www.suse.com/security/cve/CVE-2020-14339" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:2233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007268.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007278.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1455-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00058.html" source="SUSE-SU"/>
    <description>
    A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14339/">CVE-2020-14339</cve>
	<bugzilla href="https://bugzilla.suse.com/1174458">SUSE bug 1174458</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014343" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14343</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14343" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14343" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14343" ref_url="https://www.suse.com/security/cve/CVE-2020-14343" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009336.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011943.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012200.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14343/">CVE-2020-14343</cve>
	<bugzilla href="https://bugzilla.suse.com/1174514">SUSE bug 1174514</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009511395" comment="python3-PyYAML-5.3.1-6.10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014344" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14344</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14344" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14344" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14344" ref_url="https://www.suse.com/security/cve/CVE-2020-14344" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14445-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007226.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14447-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007247.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007222.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007253.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007252.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1162-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00014.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1164-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1182-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1198-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00031.html" source="SUSE-SU"/>
    <description>
    An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14344/">CVE-2020-14344</cve>
	<bugzilla href="https://bugzilla.suse.com/1174628">SUSE bug 1174628</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1174638">SUSE bug 1174638</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1175880">SUSE bug 1175880</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760801" comment="libX11-6-1.6.5-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760802" comment="libX11-data-1.6.5-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760803" comment="libX11-xcb1-1.6.5-3.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014351" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14351</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14351" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14351" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14351" ref_url="https://www.suse.com/security/cve/CVE-2020-14351" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1906-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7MTGDUP74HR4XORTRYN7I7MANTKWCGQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-14351/">CVE-2020-14351</cve>
	<bugzilla href="https://bugzilla.suse.com/1177086">SUSE bug 1177086</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014355" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14355</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14355" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14355" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14355" ref_url="https://www.suse.com/security/cve/CVE-2020-14355" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3070-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007651.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3071-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007658.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3085-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007662.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1901-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1902-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019243.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1905-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019242.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1911-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1928-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1956-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008998.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1802-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1803-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00000.html" source="SUSE-SU"/>
    <description>
    Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-14355/">CVE-2020-14355</cve>
	<bugzilla href="https://bugzilla.suse.com/1177158">SUSE bug 1177158</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760828" comment="libspice-server1-0.14.2-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014356" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14356</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14356" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14356" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14356" ref_url="https://www.suse.com/security/cve/CVE-2020-14356" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007348.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007350.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007375.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007405.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2610-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007408.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007419.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007426.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1325-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-14356/">CVE-2020-14356</cve>
	<bugzilla href="https://bugzilla.suse.com/1175213">SUSE bug 1175213</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1176392">SUSE bug 1176392</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014363" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14363</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14363" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14363" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14363" ref_url="https://www.suse.com/security/cve/CVE-2020-14363" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2474-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2475-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2475-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007895.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1368-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1370-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00018.html" source="SUSE-SU"/>
    <description>
    An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14363/">CVE-2020-14363</cve>
	<bugzilla href="https://bugzilla.suse.com/1175239">SUSE bug 1175239</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760801" comment="libX11-6-1.6.5-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760802" comment="libX11-data-1.6.5-3.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760803" comment="libX11-xcb1-1.6.5-3.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014364" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14364</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14364" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14364" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14364" ref_url="https://www.suse.com/security/cve/CVE-2020-14364" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007532.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008910.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1895-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008990.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1664-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
    <description>
    An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU process, resulting in a denial of service, or the potential execution of arbitrary code with the privileges of the QEMU process on the host.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-14364/">CVE-2020-14364</cve>
	<bugzilla href="https://bugzilla.suse.com/1175441">SUSE bug 1175441</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1175534">SUSE bug 1175534</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1176494">SUSE bug 1176494</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177130">SUSE bug 1177130</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704898" comment="qemu-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499897" comment="qemu-arm-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499905" comment="qemu-ipxe-1.0.0+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499911" comment="qemu-seabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499912" comment="qemu-sgabios-8-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704899" comment="qemu-tools-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499916" comment="qemu-vgabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499917" comment="qemu-x86-4.2.1-11.19.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014367" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14367</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14367" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14367" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14367" ref_url="https://www.suse.com/security/cve/CVE-2020-14367" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010514.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010526.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:363-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010531.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:368-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010532.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010538.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0845-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010756.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0845-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GIUHNUKYNY5JRZHWXP7NXCJOMX4HEQMQ/" source="SUSE-SU"/>
    <description>
    A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged access to create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service due to the path traversal.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14367/">CVE-2020-14367</cve>
	<bugzilla href="https://bugzilla.suse.com/1174911">SUSE bug 1174911</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
</definition>
<definition id="oval:org.opensuse.security:def:202014370" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14370</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14370" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14370" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14370" ref_url="https://www.suse.com/security/cve/CVE-2020-14370" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3378-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:23018-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010347.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4AHS44MM5VJQEFYSAEM4XLRKSPLU53H7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2063-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WEYG3UZ6PAJGRLA4U75IIT2HGWDPPZWR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:23018-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5BA2TLW7O5ZURGQUAQUH4HD5SQYNDDZ6/" source="SUSE-SU"/>
    <description>
    An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-14370/">CVE-2020-14370</cve>
	<bugzilla href="https://bugzilla.suse.com/1176804">SUSE bug 1176804</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629073" comment="podman-2.1.1-4.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629074" comment="podman-cni-config-2.1.1-4.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014385" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14385</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14385" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14385" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14385" ref_url="https://www.suse.com/security/cve/CVE-2020-14385" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007551.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1586-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, or otherwise rendered inaccessible until it is remounted, leading to a denial of service. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-14385/">CVE-2020-14385</cve>
	<bugzilla href="https://bugzilla.suse.com/1176137">SUSE bug 1176137</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014386" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14386</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14386" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14386" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14386" ref_url="https://www.suse.com/security/cve/CVE-2020-14386" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2576-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2579-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2610-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007408.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007419.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007712.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007722.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3210-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3225-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-November/016787.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1379-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1382-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1655-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14386/">CVE-2020-14386</cve>
	<bugzilla href="https://bugzilla.suse.com/1176069">SUSE bug 1176069</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1176072">SUSE bug 1176072</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014390" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14390</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14390" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14390" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14390" ref_url="https://www.suse.com/security/cve/CVE-2020-14390" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2907-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1586-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1655-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14390/">CVE-2020-14390</cve>
	<bugzilla href="https://bugzilla.suse.com/1176235">SUSE bug 1176235</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1176253">SUSE bug 1176253</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1176278">SUSE bug 1176278</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014416" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14416</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14416" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14416" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14416" ref_url="https://www.suse.com/security/cve/CVE-2020-14416" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0935-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.4.16, a race condition in tty-&gt;disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/slip/slip.c and drivers/net/can/slcan.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-14416/">CVE-2020-14416</cve>
	<bugzilla href="https://bugzilla.suse.com/1162002">SUSE bug 1162002</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202014422" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-14422</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-14422" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14422" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-14422" ref_url="https://www.suse.com/security/cve/CVE-2020-14422" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1920-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1939-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1940-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2157-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007239.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007260.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008118.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0931-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0940-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00006.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0989-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00032.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1002-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2332-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S3JTHM6LLDKL7VPNRJUSRPNZAD2FZ25H/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2333-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FLGERALYYFTBIX3ZKPM6EQ2WJVUXLOXY/" source="SUSE-SU"/>
    <description>
    Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-14422/">CVE-2020-14422</cve>
	<bugzilla href="https://bugzilla.suse.com/1173274">SUSE bug 1173274</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015157" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15157</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15157" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15157" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15157" ref_url="https://www.suse.com/security/cve/CVE-2020-15157" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0445-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:23018-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010347.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:23018-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5BA2TLW7O5ZURGQUAQUH4HD5SQYNDDZ6/" source="SUSE-SU"/>
    <description>
    In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the default containerd resolver will follow that URL to attempt to download it. In v1.2.x but not 1.3.0 or later, the default containerd resolver will provide its authentication credentials if the server where the URL is located presents an HTTP 401 status code along with registry-specific HTTP headers. If an attacker publishes a public image with a manifest that directs one of the layers to be fetched from a web server they control and they trick a user or system into pulling the image, they can obtain the credentials used for pulling that image. In some cases, this may be the user's username and password for the registry. In other cases, this may be the credentials attached to the cloud virtual instance which can grant access to other cloud resources in the account. The default containerd resolver is used by the cri-containerd plugin (which can be used by Kubernetes), the ctr development tool, and other client programs that have explicitly linked against it. This vulnerability has been fixed in containerd 1.2.14. containerd 1.3 and later are not affected. If you are using containerd 1.3 or later, you are not affected. If you are using cri-containerd in the 1.2 series or prior, you should ensure you only pull images from trusted sources. Other container runtimes built on top of containerd but not using the default resolver (such as Docker) are not affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-15157/">CVE-2020-15157</cve>
	<bugzilla href="https://bugzilla.suse.com/1177598">SUSE bug 1177598</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629067" comment="containerd-1.3.9-5.29.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015166" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15166</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15166" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15166" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15166" ref_url="https://www.suse.com/security/cve/CVE-2020-15166" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:696-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:709-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007869.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007741.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1907-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZFPGMWNYFF7TPILP2K22BE5SUUBZBMNS/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1910-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PNPGMJDNXG4YN2UCUL54ZUIYNPJTE25F/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socket is opened and connected to an endpoint that is fully configured with CURVE/ZAP, legitimate clients will not be able to exchange any message. Handshakes complete successfully, and messages are delivered to the library, but the server application never receives them. This is patched in version 4.3.3.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-15166/">CVE-2020-15166</cve>
	<bugzilla href="https://bugzilla.suse.com/1176116">SUSE bug 1176116</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628931" comment="libzmq5-4.2.3-3.15.4 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015257" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15257</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15257" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15257" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15257" ref_url="https://www.suse.com/security/cve/CVE-2020-15257" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3938-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008125.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008311.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0278-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UGKTLORCQ4MPZPDFGWKJEEPQRXFUTZYZ/" source="SUSE-SU"/>
    <description>
    containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified that the connecting process had an effective UID of 0, but did not otherwise restrict access to the abstract Unix domain socket. This would allow malicious containers running in the same network namespace as the shim, with an effective UID of 0 but otherwise reduced privileges, to cause new processes to be run with elevated privileges. This vulnerability has been fixed in containerd 1.3.9 and 1.4.3. Users should update to these versions as soon as they are released. It should be noted that containers started with an old version of containerd-shim should be stopped and restarted, as running containers will continue to be vulnerable even after an upgrade. If you are not providing the ability for untrusted users to start containers in the same network namespace as the shim (typically the "host" network namespace, for example with docker run --net=host or hostNetwork: true in a Kubernetes pod) and run with an effective UID of 0, you are not vulnerable to this issue. If you are running containers with a vulnerable configuration, you can deny access to all abstract sockets with AppArmor by adding a line similar to deny unix addr=@**, to your policy. It is best practice to run containers with a reduced set of privileges, with a non-zero UID, and with isolated namespaces. The containerd maintainers strongly advise against sharing namespaces with the host. Reducing the set of isolation mechanisms used for a container necessarily increases that container's privilege, regardless of what container runtime is used for running that container.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-15257/">CVE-2020-15257</cve>
	<bugzilla href="https://bugzilla.suse.com/1178969">SUSE bug 1178969</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629067" comment="containerd-1.3.9-5.29.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629068" comment="docker-19.03.15_ce-6.46.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015358" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15358</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15358" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15358" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15358" ref_url="https://www.suse.com/security/cve/CVE-2020-15358" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-15358/">CVE-2020-15358</cve>
	<bugzilla href="https://bugzilla.suse.com/1173641">SUSE bug 1173641</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015393" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15393</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15393" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15393" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15393" ref_url="https://www.suse.com/security/cve/CVE-2020-15393" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2840-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011942.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013765.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1062-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00071.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-15393/">CVE-2020-15393</cve>
	<bugzilla href="https://bugzilla.suse.com/1173514">SUSE bug 1173514</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015436" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15436</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15436" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15436" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15436" ref_url="https://www.suse.com/security/cve/CVE-2020-15436" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2161-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ICEKZTGIQ6MSKDFOTIOJ2RLWAWJFPSYA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2193-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4YRSQJNKLIOJJTD3P2UKMHRFMCIG3JDN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-15436/">CVE-2020-15436</cve>
	<bugzilla href="https://bugzilla.suse.com/1179141">SUSE bug 1179141</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015437" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15437</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15437" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15437" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15437" ref_url="https://www.suse.com/security/cve/CVE-2020-15437" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3714-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-December/017242.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2161-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ICEKZTGIQ6MSKDFOTIOJ2RLWAWJFPSYA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2193-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4YRSQJNKLIOJJTD3P2UKMHRFMCIG3JDN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    The Linux kernel before version 5.8 is vulnerable to a NULL pointer dereference in drivers/tty/serial/8250/8250_core.c:serial8250_isa_init_ports() that allows local users to cause a denial of service by using the p-&gt;serial_in pointer which uninitialized.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-15437/">CVE-2020-15437</cve>
	<bugzilla href="https://bugzilla.suse.com/1179140">SUSE bug 1179140</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015469" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15469</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15469" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15469" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15469" ref_url="https://www.suse.com/security/cve/CVE-2020-15469" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14774-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019812.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
    <description>
    In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-15469/">CVE-2020-15469</cve>
	<bugzilla href="https://bugzilla.suse.com/1173612">SUSE bug 1173612</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704859" comment="qemu-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499829" comment="qemu-arm-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499837" comment="qemu-ipxe-1.0.0+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499843" comment="qemu-seabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499844" comment="qemu-sgabios-8-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704860" comment="qemu-tools-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499848" comment="qemu-vgabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499849" comment="qemu-x86-4.2.1-11.16.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015563" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15563</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15563" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15563" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15563" ref_url="https://www.suse.com/security/cve/CVE-2020-15563" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1886-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1902-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007126.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0965-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00031.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests' dirty video RAM tracking code allows such guests to make Xen de-reference a pointer guaranteed to point at unmapped space. A malicious or buggy HVM guest may cause the hypervisor to crash, resulting in Denial of Service (DoS) affecting the entire host. Xen versions from 4.8 onwards are affected. Xen versions 4.7 and earlier are not affected. Only x86 systems are affected. Arm systems are not affected. Only x86 HVM guests using shadow paging can leverage the vulnerability. In addition, there needs to be an entity actively monitoring a guest's video frame buffer (typically for display purposes) in order for such a guest to be able to leverage the vulnerability. x86 PV guests, as well as x86 HVM guests using hardware assisted paging (HAP), cannot leverage the vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-15563/">CVE-2020-15563</cve>
	<bugzilla href="https://bugzilla.suse.com/1173377">SUSE bug 1173377</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015564" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15564</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15564" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15564" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15564" ref_url="https://www.suse.com/security/cve/CVE-2020-15564" source="SUSE CVE"/>
    <description>
    An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to cause a hypervisor crash because of a missing alignment check in VCPUOP_register_vcpu_info. The hypercall VCPUOP_register_vcpu_info is used by a guest to register a shared region with the hypervisor. The region will be mapped into Xen address space so it can be directly accessed. On Arm, the region is accessed with instructions that require a specific alignment. Unfortunately, there is no check that the address provided by the guest will be correctly aligned. As a result, a malicious guest could cause a hypervisor crash by passing a misaligned address. A malicious guest administrator may cause a hypervisor crash, resulting in a Denial of Service (DoS). All Xen versions are vulnerable. Only Arm systems are vulnerable. x86 systems are not affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-15564/">CVE-2020-15564</cve>
	<bugzilla href="https://bugzilla.suse.com/1173379">SUSE bug 1173379</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015565" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15565</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15565" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15565" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15565" ref_url="https://www.suse.com/security/cve/CVE-2020-15565" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1886-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1902-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007126.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0965-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00031.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and CPU, changes to them require flushing of both TLBs. Furthermore, IOMMUs may be non-coherent, and hence prior to flushing IOMMU TLBs, a CPU cache also needs writing back to memory after changes were made. Such writing back of cached data was missing in particular when splitting large page mappings into smaller granularity ones. A malicious guest may be able to retain read/write DMA access to frames returned to Xen's free pool, and later reused for another purpose. Host crashes (leading to a Denial of Service) and privilege escalation cannot be ruled out. Xen versions from at least 3.2 onwards are affected. Only x86 Intel systems are affected. x86 AMD as well as Arm systems are not affected. Only x86 HVM guests using hardware assisted paging (HAP), having a passed through PCI device assigned, and having page table sharing enabled can leverage the vulnerability. Note that page table sharing will be enabled (by default) only if Xen considers IOMMU and CPU large page size support compatible.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.9/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-15565/">CVE-2020-15565</cve>
	<bugzilla href="https://bugzilla.suse.com/1173378">SUSE bug 1173378</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015566" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15566</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15566" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15566" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15566" ref_url="https://www.suse.com/security/cve/CVE-2020-15566" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1902-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007126.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0965-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00031.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash because of incorrect error handling in event-channel port allocation. The allocation of an event-channel port may fail for multiple reasons: (1) port is already in use, (2) the memory allocation failed, or (3) the port we try to allocate is higher than what is supported by the ABI (e.g., 2L or FIFO) used by the guest or the limit set by an administrator (max_event_channels in xl cfg). Due to the missing error checks, only (1) will be considered an error. All the other cases will provide a valid port and will result in a crash when trying to access the event channel. When the administrator configured a guest to allow more than 1023 event channels, that guest may be able to crash the host. When Xen is out-of-memory, allocation of new event channels will result in crashing the host rather than reporting an error. Xen versions 4.10 and later are affected. All architectures are affected. The default configuration, when guests are created with xl/libxl, is not vulnerable, because of the default event-channel limit.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-15566/">CVE-2020-15566</cve>
	<bugzilla href="https://bugzilla.suse.com/1173376">SUSE bug 1173376</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015567" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15567</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15567" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15567" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15567" ref_url="https://www.suse.com/security/cve/CVE-2020-15567" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1886-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1902-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007126.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0965-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00024.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0985-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00031.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of non-atomic bitfield writes. Depending on the compiler version and optimisation flags, Xen might expose a dangerous partially written PTE to the hardware, which an attacker might be able to race to exploit. A guest administrator or perhaps even an unprivileged guest user might be able to cause denial of service, data corruption, or privilege escalation. Only systems using Intel CPUs are vulnerable. Systems using AMD CPUs, and Arm systems, are not vulnerable. Only systems using nested paging (hap, aka nested paging, aka in this case Intel EPT) are vulnerable. Only HVM and PVH guests can exploit the vulnerability. The presence and scope of the vulnerability depends on the precise optimisations performed by the compiler used to build Xen. If the compiler generates (a) a single 64-bit write, or (b) a series of read-modify-write operations in the same order as the source code, the hypervisor is not vulnerable. For example, in one test build using GCC 8.3 with normal settings, the compiler generated multiple (unlocked) read-modify-write operations in source-code order, which did not constitute a vulnerability. We have not been able to survey compilers; consequently we cannot say which compiler(s) might produce vulnerable code (with which code-generation options). The source code clearly violates the C rules, and thus should be considered vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-15567/">CVE-2020-15567</cve>
	<bugzilla href="https://bugzilla.suse.com/1173380">SUSE bug 1173380</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015705" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15705</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15705" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15705" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15705" ref_url="https://www.suse.com/security/cve/CVE-2020-15705" source="SUSE CVE"/>
		<reference ref_id="BOOTHOLE-BLOG" ref_url="https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007297.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2304-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2307-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2308-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007292.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1280-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1282-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00069.html" source="SUSE-SU"/>
    <description>
    GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-15705/">CVE-2020-15705</cve>
	<bugzilla href="https://bugzilla.suse.com/1174421">SUSE bug 1174421</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182890">SUSE bug 1182890</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760789" comment="grub2-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760790" comment="grub2-arm64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760791" comment="grub2-i386-pc-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760792" comment="grub2-powerpc-ieee1275-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760793" comment="grub2-s390x-emu-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760794" comment="grub2-snapper-plugin-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760795" comment="grub2-x86_64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760796" comment="grub2-x86_64-xen-2.04-9.30.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015706" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15706</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15706" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15706" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15706" ref_url="https://www.suse.com/security/cve/CVE-2020-15706" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2078-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007198.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007197.html" source="SUSE-SU"/>
		<reference ref_id="TID000019673" ref_url="https://www.suse.com/support/kb/doc/?id=000019673" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.html" source="SUSE-SU"/>
    <description>
    GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-15706/">CVE-2020-15706</cve>
	<bugzilla href="https://bugzilla.suse.com/1174463">SUSE bug 1174463</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760789" comment="grub2-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760790" comment="grub2-arm64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760791" comment="grub2-i386-pc-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760792" comment="grub2-powerpc-ieee1275-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760793" comment="grub2-s390x-emu-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760794" comment="grub2-snapper-plugin-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760795" comment="grub2-x86_64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760796" comment="grub2-x86_64-xen-2.04-9.30.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015707" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15707</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15707" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15707" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15707" ref_url="https://www.suse.com/security/cve/CVE-2020-15707" source="SUSE CVE"/>
		<reference ref_id="BOOTHOLE-BLOG" ref_url="https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2078-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007198.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007197.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1168-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1169-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.html" source="SUSE-SU"/>
    <description>
    Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-15707/">CVE-2020-15707</cve>
	<bugzilla href="https://bugzilla.suse.com/1174570">SUSE bug 1174570</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760789" comment="grub2-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760790" comment="grub2-arm64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760791" comment="grub2-i386-pc-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760792" comment="grub2-powerpc-ieee1275-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760793" comment="grub2-s390x-emu-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760794" comment="grub2-snapper-plugin-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760795" comment="grub2-x86_64-efi-2.04-9.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760796" comment="grub2-x86_64-xen-2.04-9.30.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015708" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15708</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15708" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15708" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15708" ref_url="https://www.suse.com/security/cve/CVE-2020-15708" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:2969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2970-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007626.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007628.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007687.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1777-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00072.html" source="SUSE-SU"/>
    <description>
    Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-15708/">CVE-2020-15708</cve>
	<bugzilla href="https://bugzilla.suse.com/1174955">SUSE bug 1174955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015719" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15719</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15719" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15719" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15719" ref_url="https://www.suse.com/security/cve/CVE-2020-15719" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007396.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007569.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2581-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007391.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1416-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1459-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00059.html" source="SUSE-SU"/>
    <description>
    libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-15719/">CVE-2020-15719</cve>
	<bugzilla href="https://bugzilla.suse.com/1174154">SUSE bug 1174154</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015780" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15780</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15780" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15780" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15780" ref_url="https://www.suse.com/security/cve/CVE-2020-15780" source="SUSE CVE"/>
		<reference ref_id="BOOTHOLE-BLOG" ref_url="https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007219.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007355.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007357.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007368.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007359.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2515-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2517-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007358.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007353.html" source="SUSE-SU"/>
		<reference ref_id="TID000019673" ref_url="https://www.suse.com/support/kb/doc/?id=000019673" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-15780/">CVE-2020-15780</cve>
	<bugzilla href="https://bugzilla.suse.com/1173573">SUSE bug 1173573</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1174186">SUSE bug 1174186</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015852" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15852</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15852" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15852" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15852" ref_url="https://www.suse.com/security/cve/CVE-2020-15852" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-04"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-15852/">CVE-2020-15852</cve>
	<bugzilla href="https://bugzilla.suse.com/1174063">SUSE bug 1174063</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015859" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15859</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15859" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15859" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15859" ref_url="https://www.suse.com/security/cve/CVE-2020-15859" source="SUSE CVE"/>
    <description>
    QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-15859/">CVE-2020-15859</cve>
	<bugzilla href="https://bugzilla.suse.com/1174373">SUSE bug 1174373</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015863" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15863</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15863" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15863" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15863" ref_url="https://www.suse.com/security/cve/CVE-2020-15863" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007532.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14774-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019812.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1664-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00024.html" source="SUSE-SU"/>
    <description>
    hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects the highbank and midway emulated machines. A guest user or process could use this flaw to crash the QEMU process on the host, resulting in a denial of service or potential privileged code execution. This was fixed in commit 5519724a13664b43e225ca05351c60b4468e4555.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-15863/">CVE-2020-15863</cve>
	<bugzilla href="https://bugzilla.suse.com/1174386">SUSE bug 1174386</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015888" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15888</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15888" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15888" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15888" ref_url="https://www.suse.com/security/cve/CVE-2020-15888" source="SUSE CVE"/>
    <description>
    Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-15888/">CVE-2020-15888</cve>
	<bugzilla href="https://bugzilla.suse.com/1174367">SUSE bug 1174367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348261" comment="liblua5_3-5 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202015999" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-15999</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-15999" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15999" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-15999" ref_url="https://www.suse.com/security/cve/CVE-2020-15999" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:571-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2995-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007609.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3383-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007870.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007883.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1718-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00051.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1731-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00055.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1734-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00056.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1737-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00059.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1744-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00061.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1829-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1952-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MZPDJYULXAMSZLQSDCDB6AOO535U72YK/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2020-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LK7W6L42GLCUWLGKEJNDWSRASOS3CLIA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2031-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KX646YBHO2LBCWJZORVE6CWXY2DMCYHR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2096-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DVMMW4XRNOGVJH2XZU4UUV2ATGSF6TJ6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2187-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JXIRQKYZLZFQPPH6RZY4V3IIMPGHUT5V/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2315-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/76P3E35NHCSZCWGVU63J3OKJKJO3HUJD/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1134-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/N6MMS3NOFXF2TZBZ5M3EC6VOB65FRP4I/" source="SUSE-SU"/>
    <description>
    Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-15999/">CVE-2020-15999</cve>
	<bugzilla href="https://bugzilla.suse.com/1177914">SUSE bug 1177914</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177936">SUSE bug 1177936</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178824">SUSE bug 1178824</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178894">SUSE bug 1178894</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628448" comment="libfreetype6-2.10.1-4.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202016092" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-16092</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-16092" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16092" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-16092" ref_url="https://www.suse.com/security/cve/CVE-2020-16092" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007532.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1664-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00024.html" source="SUSE-SU"/>
    <description>
    In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-16092/">CVE-2020-16092</cve>
	<bugzilla href="https://bugzilla.suse.com/1174641">SUSE bug 1174641</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202016119" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-16119</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-16119" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16119" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-16119" ref_url="https://www.suse.com/security/cve/CVE-2020-16119" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013765.html" source="SUSE-SU"/>
    <description>
    Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-121.123, 4.4.0-193.224, 3.13.0.182.191 and 3.2.0-149.196.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-16"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-16119/">CVE-2020-16119</cve>
	<bugzilla href="https://bugzilla.suse.com/1177471">SUSE bug 1177471</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177742">SUSE bug 1177742</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202016120" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-16120</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-16120" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16120" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-16120" ref_url="https://www.suse.com/security/cve/CVE-2020-16120" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1906-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7MTGDUP74HR4XORTRYN7I7MANTKWCGQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possible to have a file not readable by an unprivileged user to be copied to a mountpoint controlled by the user, like a removable device. This was introduced in kernel version 4.19 by commit d1d04ef ("ovl: stack file ops"). This was fixed in kernel version 5.8 by commits 56230d9 ("ovl: verify permissions in ovl_path_open()"), 48bd024 ("ovl: switch to mounter creds in readdir") and 05acefb ("ovl: check permission to open real file"). Additionally, commits 130fdbc ("ovl: pass correct flags for opening real directory") and 292f902 ("ovl: call secutiry hook in ovl_real_ioctl()") in kernel 5.8 might also be desired or necessary. These additional commits introduced a regression in overlay mounts within user namespaces which prevented access to files with ownership outside of the user namespace. This regression was mitigated by subsequent commit b6650da ("ovl: do not fail because of O_NOATIMEi") in kernel 5.11.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-16120/">CVE-2020-16120</cve>
	<bugzilla href="https://bugzilla.suse.com/1177470">SUSE bug 1177470</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202016155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-16155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-16155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16155" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-16155" ref_url="https://www.suse.com/security/cve/CVE-2020-16155" source="SUSE CVE"/>
    <description>
    The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-16155/">CVE-2020-16155</cve>
	<bugzilla href="https://bugzilla.suse.com/1193811">SUSE bug 1193811</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334114" comment="perl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336057" comment="perl-base is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202016166" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-16166</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-16166" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16166" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-16166" ref_url="https://www.suse.com/security/cve/CVE-2020-16166" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007348.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007350.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007375.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2576-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2582-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007405.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2610-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007408.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007419.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007426.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1153-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1236-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-16166/">CVE-2020-16166</cve>
	<bugzilla href="https://bugzilla.suse.com/1174757">SUSE bug 1174757</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202016846" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-16846</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-16846" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16846" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-16846" ref_url="https://www.suse.com/security/cve/CVE-2020-16846" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:14535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14537-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007715.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3155-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3171-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007716.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3250-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007714.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3251-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007729.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008325.html" source="SUSE-SU"/>
		<reference ref_id="TID000019775" ref_url="https://www.suse.com/support/kb/doc/?id=000019775" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1833-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1868-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00029.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-16846/">CVE-2020-16846</cve>
	<bugzilla href="https://bugzilla.suse.com/1178361">SUSE bug 1178361</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20201711" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-1711</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-1711" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1711" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-1711" ref_url="https://www.suse.com/security/cve/CVE-2020-1711" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006662.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006664.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006868.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1523-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006874.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006886.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU process, resulting in a denial of service or potential execution of arbitrary code with privileges of the QEMU process on the host.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.6/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-1711/">CVE-2020-1711</cve>
	<bugzilla href="https://bugzilla.suse.com/1166240">SUSE bug 1166240</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20201712" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-1712</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-1712" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1712" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-1712" ref_url="https://www.suse.com/security/cve/CVE-2020-1712" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:46-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:47-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:48-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:50-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:98-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-March/014232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:99-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-March/014233.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0335-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006464.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0208-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00014.html" source="SUSE-SU"/>
    <description>
    A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-1712/">CVE-2020-1712</cve>
	<bugzilla href="https://bugzilla.suse.com/1162108">SUSE bug 1162108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760829" comment="libsystemd0-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760830" comment="libudev1-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760831" comment="systemd-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760832" comment="systemd-sysvinit-246.10-2.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760833" comment="udev-246.10-2.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20201726" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-1726</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-1726" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1726" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-1726" ref_url="https://www.suse.com/security/cve/CVE-2020-1726" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:2731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007476.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1552-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00097.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1559-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00103.html" source="SUSE-SU"/>
    <description>
    A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume.This issue was introduced in version 1.6.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-1726/">CVE-2020-1726</cve>
	<bugzilla href="https://bugzilla.suse.com/1164090">SUSE bug 1164090</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009629073" comment="podman-2.1.1-4.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629074" comment="podman-cni-config-2.1.1-4.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20201730" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-1730</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-1730" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1730" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-1730" ref_url="https://www.suse.com/security/cve/CVE-2020-1730" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006706.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006707.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0967-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0968-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006692.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0510-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00018.html" source="SUSE-SU"/>
    <description>
    A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-1730/">CVE-2020-1730</cve>
	<bugzilla href="https://bugzilla.suse.com/1168699">SUSE bug 1168699</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482409" comment="libssh4-0.8.7-10.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202017437" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-17437</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-17437" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17437" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-17437" ref_url="https://www.suse.com/security/cve/CVE-2020-17437" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008407.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2861-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011958.html" source="SUSE-SU"/>
		<reference ref_id="TID000019813" ref_url="https://www.suse.com/support/kb/doc/?id=000019813" source="SUSE-SU"/>
    <description>
    An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-17437/">CVE-2020-17437</cve>
	<bugzilla href="https://bugzilla.suse.com/1179907">SUSE bug 1179907</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179908">SUSE bug 1179908</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705047" comment="iscsiuio-0.7.8.6-22.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705048" comment="libopeniscsiusr0_2_0-2.1.4-22.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705049" comment="open-iscsi-2.1.4-22.14.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202017438" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-17438</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-17438" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17438" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-17438" ref_url="https://www.suse.com/security/cve/CVE-2020-17438" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008407.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008619.html" source="SUSE-SU"/>
		<reference ref_id="TID000019813" ref_url="https://www.suse.com/support/kb/doc/?id=000019813" source="SUSE-SU"/>
    <description>
    An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate the total length of an incoming packet specified in its IP header, as well as the fragmentation offset value specified in the IP header. By crafting a packet with specific values of the IP header length and the fragmentation offset, attackers can write into the .bss section of the program (past the statically allocated buffer that is used for storing the fragmented data) and cause a denial of service in uip_reass() in uip.c, or possibly execute arbitrary code on some target architectures.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-17438/">CVE-2020-17438</cve>
	<bugzilla href="https://bugzilla.suse.com/1179907">SUSE bug 1179907</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179908">SUSE bug 1179908</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705047" comment="iscsiuio-0.7.8.6-22.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705048" comment="libopeniscsiusr0_2_0-2.1.4-22.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705049" comment="open-iscsi-2.1.4-22.14.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20201747" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-1747</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-1747" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1747" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-1747" ref_url="https://www.suse.com/security/cve/CVE-2020-1747" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0959-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011943.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0507-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0630-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00017.html" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-1747/">CVE-2020-1747</cve>
	<bugzilla href="https://bugzilla.suse.com/1165439">SUSE bug 1165439</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1174514">SUSE bug 1174514</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482516" comment="python3-PyYAML-5.1.2-6.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20201749" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-1749</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-1749" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1749" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-1749" ref_url="https://www.suse.com/security/cve/CVE-2020-1749" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0868-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006672.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0940-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006683.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006720.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2517-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007358.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2525-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007375.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2610-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007408.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007419.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3656-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007925.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008612.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1325-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly routing tunneled data over the encrypted link; rather sending the data unencrypted. This would allow anyone in between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-10-11"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-1749/">CVE-2020-1749</cve>
	<bugzilla href="https://bugzilla.suse.com/1165629">SUSE bug 1165629</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1165631">SUSE bug 1165631</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177511">SUSE bug 1177511</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177513">SUSE bug 1177513</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189302">SUSE bug 1189302</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202017490" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-17490</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-17490" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17490" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-17490" ref_url="https://www.suse.com/security/cve/CVE-2020-17490" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:14535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14537-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007715.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3155-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3171-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007716.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3250-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007714.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3251-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007729.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008325.html" source="SUSE-SU"/>
		<reference ref_id="TID000019775" ref_url="https://www.suse.com/support/kb/doc/?id=000019775" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1833-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1868-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00029.html" source="SUSE-SU"/>
    <description>
    The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-17490/">CVE-2020-17490</cve>
	<bugzilla href="https://bugzilla.suse.com/1178362">SUSE bug 1178362</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20201751" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-1751</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-1751" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1751" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-1751" ref_url="https://www.suse.com/security/cve/CVE-2020-1751" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006661.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006655.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-1751/">CVE-2020-1751</cve>
	<bugzilla href="https://bugzilla.suse.com/1167630">SUSE bug 1167630</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20201752" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-1752</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-1752" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1752" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-1752" ref_url="https://www.suse.com/security/cve/CVE-2020-1752" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:100-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006658.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:101-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006661.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:537-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010665.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006655.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010664.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0467-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00006.html" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-1752/">CVE-2020-1752</cve>
	<bugzilla href="https://bugzilla.suse.com/1167631">SUSE bug 1167631</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760786" comment="glibc-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760787" comment="glibc-locale-2.26-13.51.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760788" comment="glibc-locale-base-2.26-13.51.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202017541" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-17541</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-17541" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17541" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-17541" ref_url="https://www.suse.com/security/cve/CVE-2020-17541" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:1957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1958-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009002.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0892-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5QFMY5PC6YGRRPOTKEDLIS6VQ2KCVUDF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1958-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JEVT5FS4C2453YNMGNJH5GEW4YPAD5DS/" source="SUSE-SU"/>
    <description>
    Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-17541/">CVE-2020-17541</cve>
	<bugzilla href="https://bugzilla.suse.com/1186764">SUSE bug 1186764</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704903" comment="libjpeg8-8.1.2-5.18.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20201967" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-1967</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-1967" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1967" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-1967" ref_url="https://www.suse.com/security/cve/CVE-2020-1967" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:1058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006722.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2041-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007183.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0933-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00004.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0945-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00011.html" source="SUSE-SU"/>
    <description>
    Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-1967/">CVE-2020-1967</cve>
	<bugzilla href="https://bugzilla.suse.com/1169407">SUSE bug 1169407</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20201971" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-1971</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-1971" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1971" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-1971" ref_url="https://www.suse.com/security/cve/CVE-2020-1971" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007958.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:815-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:20-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008164.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3720-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3722-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007948.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007976.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0060-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008175.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2223-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GMYUDIGG7RM42AIH4Q3WW4VZGFRAPLQ7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YDLYD3JFZSOPG5DPXOHFTMZTUOLPOK5J/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2245-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DET3T3KBOIXDZC2VZ5XGHXVGQ54LOAI5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2269-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SGJECGZC6A7C36WKBWL3FKK6U7IGO4OK/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0064-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EIIX5B6YLG6I6J4WR546EWZU23BNUSV6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3MAV3V72VVUTVO6VC6SN5XB5EYX3TJWK/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0082-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JQ2RC7AEXMLHMCFO7K3XLJO5WMPQXS7V/" source="SUSE-SU"/>
    <description>
    The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the "-crl_download" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-1971/">CVE-2020-1971</cve>
	<bugzilla href="https://bugzilla.suse.com/1179491">SUSE bug 1179491</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196179">SUSE bug 1196179</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199303">SUSE bug 1199303</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760819" comment="libopenssl1_1-1.1.1d-11.12.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760820" comment="openssl-1_1-1.1.1d-11.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20201983" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-1983</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-1983" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1983" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-1983" ref_url="https://www.suse.com/security/cve/CVE-2020-1983" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006785.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006934.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006868.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006869.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006873.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1523-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006874.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0636-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-05/msg00022.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0756-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00001.html" source="SUSE-SU"/>
    <description>
    A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-1983/">CVE-2020-1983</cve>
	<bugzilla href="https://bugzilla.suse.com/1170940">SUSE bug 1170940</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629075" comment="slirp4netns-0.4.7-3.12.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024352" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24352</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24352" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24352" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24352" ref_url="https://www.suse.com/security/cve/CVE-2020-24352" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007532.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1664-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00024.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-24352/">CVE-2020-24352</cve>
	<bugzilla href="https://bugzilla.suse.com/1175370">SUSE bug 1175370</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188609">SUSE bug 1188609</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024370" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24370</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24370" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24370" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24370" ref_url="https://www.suse.com/security/cve/CVE-2020-24370" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009100.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0962-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OOVDNMRFDTKUTT25LOX5ABPHFFAREA4V/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2196-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EASBVV4MIBIGZHO5CD23ITJBJVVHVDEU/" source="SUSE-SU"/>
    <description>
    ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-24370/">CVE-2020-24370</cve>
	<bugzilla href="https://bugzilla.suse.com/1175448">SUSE bug 1175448</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704904" comment="liblua5_3-5-5.3.6-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024371" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24371</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24371" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24371" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24371" ref_url="https://www.suse.com/security/cve/CVE-2020-24371" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009100.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0962-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OOVDNMRFDTKUTT25LOX5ABPHFFAREA4V/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2196-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EASBVV4MIBIGZHO5CD23ITJBJVVHVDEU/" source="SUSE-SU"/>
    <description>
    lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-24371/">CVE-2020-24371</cve>
	<bugzilla href="https://bugzilla.suse.com/1175449">SUSE bug 1175449</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704904" comment="liblua5_3-5-5.3.6-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024489" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24489</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24489" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24489" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24489" ref_url="https://www.suse.com/security/cve/CVE-2020-24489" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:14758-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1930-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008987.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LVSPIXHZZESTI3IJTF7URWDUHHXIRWBP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1933-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JL4WBLDZZMRKCJPRBNYNFPGJBJE5OQZO/" source="SUSE-SU"/>
    <description>
    Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-24489/">CVE-2020-24489</cve>
	<bugzilla href="https://bugzilla.suse.com/1179839">SUSE bug 1179839</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192359">SUSE bug 1192359</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199300">SUSE bug 1199300</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201731">SUSE bug 1201731</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009494035" comment="ucode-intel-20210525-7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024490" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24490</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24490" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24490" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24490" ref_url="https://www.suse.com/security/cve/CVE-2020-24490" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2980-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007798.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="TID000019735" ref_url="https://www.suse.com/support/kb/doc/?id=000019735" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. This affects all Linux kernel versions that support BlueZ.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-24490/">CVE-2020-24490</cve>
	<bugzilla href="https://bugzilla.suse.com/1177726">SUSE bug 1177726</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177727">SUSE bug 1177727</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024502" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24502</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24502" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24502" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24502" ref_url="https://www.suse.com/security/cve/CVE-2020-24502" source="SUSE CVE"/>
    <description>
    Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before version 1.4.29.0 for Windows*, may allow an authenticated user to potentially enable a denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-24502/">CVE-2020-24502</cve>
	<bugzilla href="https://bugzilla.suse.com/1182409">SUSE bug 1182409</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024503" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24503</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24503" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24503" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24503" ref_url="https://www.suse.com/security/cve/CVE-2020-24503" source="SUSE CVE"/>
    <description>
    Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-24503/">CVE-2020-24503</cve>
	<bugzilla href="https://bugzilla.suse.com/1182405">SUSE bug 1182405</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024504" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24504</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24504" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24504" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24504" ref_url="https://www.suse.com/security/cve/CVE-2020-24504" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
    <description>
    Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-24504/">CVE-2020-24504</cve>
	<bugzilla href="https://bugzilla.suse.com/1182404">SUSE bug 1182404</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024511" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24511</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24511" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24511" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24511" ref_url="https://www.suse.com/security/cve/CVE-2020-24511" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:14758-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1930-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008987.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LVSPIXHZZESTI3IJTF7URWDUHHXIRWBP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1933-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JL4WBLDZZMRKCJPRBNYNFPGJBJE5OQZO/" source="SUSE-SU"/>
    <description>
    Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-24511/">CVE-2020-24511</cve>
	<bugzilla href="https://bugzilla.suse.com/1179836">SUSE bug 1179836</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192360">SUSE bug 1192360</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199300">SUSE bug 1199300</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201731">SUSE bug 1201731</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009494035" comment="ucode-intel-20210525-7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024512" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24512</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24512" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24512" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24512" ref_url="https://www.suse.com/security/cve/CVE-2020-24512" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:14758-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1930-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008987.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LVSPIXHZZESTI3IJTF7URWDUHHXIRWBP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1933-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JL4WBLDZZMRKCJPRBNYNFPGJBJE5OQZO/" source="SUSE-SU"/>
    <description>
    Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-24512/">CVE-2020-24512</cve>
	<bugzilla href="https://bugzilla.suse.com/1179837">SUSE bug 1179837</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192360">SUSE bug 1192360</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199300">SUSE bug 1199300</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201731">SUSE bug 1201731</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009494035" comment="ucode-intel-20210525-7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024513" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24513</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24513" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24513" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24513" ref_url="https://www.suse.com/security/cve/CVE-2020-24513" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:14758-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1930-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008987.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LVSPIXHZZESTI3IJTF7URWDUHHXIRWBP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1933-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JL4WBLDZZMRKCJPRBNYNFPGJBJE5OQZO/" source="SUSE-SU"/>
    <description>
    Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-24513/">CVE-2020-24513</cve>
	<bugzilla href="https://bugzilla.suse.com/1179833">SUSE bug 1179833</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192360">SUSE bug 1192360</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199300">SUSE bug 1199300</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201731">SUSE bug 1201731</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009494035" comment="ucode-intel-20210525-7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024586" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24586</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24586" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24586" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24586" ref_url="https://www.suse.com/security/cve/CVE-2020-24586" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="TID000020244" ref_url="https://www.suse.com/support/kb/doc/?id=000020244" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-24586/">CVE-2020-24586</cve>
	<bugzilla href="https://bugzilla.suse.com/1185859">SUSE bug 1185859</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192868">SUSE bug 1192868</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024587" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24587</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24587" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24587" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24587" ref_url="https://www.suse.com/security/cve/CVE-2020-24587" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="TID000020244" ref_url="https://www.suse.com/support/kb/doc/?id=000020244" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-24587/">CVE-2020-24587</cve>
	<bugzilla href="https://bugzilla.suse.com/1185859">SUSE bug 1185859</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1185862">SUSE bug 1185862</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192868">SUSE bug 1192868</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024588" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24588</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24588" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24588" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24588" ref_url="https://www.suse.com/security/cve/CVE-2020-24588" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:154-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:155-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013801.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="TID000020244" ref_url="https://www.suse.com/support/kb/doc/?id=000020244" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
    <description>
    The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-07-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-24588/">CVE-2020-24588</cve>
	<bugzilla href="https://bugzilla.suse.com/1185861">SUSE bug 1185861</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192868">SUSE bug 1192868</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199701">SUSE bug 1199701</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024659" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24659</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24659" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24659" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24659" ref_url="https://www.suse.com/security/cve/CVE-2020-24659" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007569.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:561-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:564-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2864-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2864-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2988-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007605.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1724-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00054.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1743-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00060.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutls_deinit function is called after detecting a handshake failure.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-24659/">CVE-2020-24659</cve>
	<bugzilla href="https://bugzilla.suse.com/1176181">SUSE bug 1176181</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178057">SUSE bug 1178057</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760814" comment="libgnutls30-3.6.7-14.7.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202024977" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-24977</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-24977" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24977" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-24977" ref_url="https://www.suse.com/security/cve/CVE-2020-24977" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007413.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007415.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007416.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007417.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007418.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007569.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007409.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2612-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008797.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1430-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00036.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1465-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00061.html" source="SUSE-SU"/>
    <description>
    GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-24977/">CVE-2020-24977</cve>
	<bugzilla href="https://bugzilla.suse.com/1176179">SUSE bug 1176179</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191860">SUSE bug 1191860</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025084" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25084</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25084" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25084" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25084" ref_url="https://www.suse.com/security/cve/CVE-2020-25084" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
    <description>
    QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-25084/">CVE-2020-25084</cve>
	<bugzilla href="https://bugzilla.suse.com/1176673">SUSE bug 1176673</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704859" comment="qemu-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499829" comment="qemu-arm-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499837" comment="qemu-ipxe-1.0.0+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499843" comment="qemu-seabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499844" comment="qemu-sgabios-8-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704860" comment="qemu-tools-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499848" comment="qemu-vgabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499849" comment="qemu-x86-4.2.1-11.16.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025085" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25085</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25085" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25085" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25085" ref_url="https://www.suse.com/security/cve/CVE-2020-25085" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009241.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2591-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W3DOLLXJN6UCIAFW2F6437T6CGXJTVQO/" source="SUSE-SU"/>
    <description>
    QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-25085/">CVE-2020-25085</cve>
	<bugzilla href="https://bugzilla.suse.com/1176681">SUSE bug 1176681</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182282">SUSE bug 1182282</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704898" comment="qemu-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499897" comment="qemu-arm-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499905" comment="qemu-ipxe-1.0.0+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499911" comment="qemu-seabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499912" comment="qemu-sgabios-8-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704899" comment="qemu-tools-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499916" comment="qemu-vgabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499917" comment="qemu-x86-4.2.1-11.19.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20202521" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-2521</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-2521" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2521" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-2521" ref_url="https://www.suse.com/security/cve/CVE-2020-2521" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1586-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2020-2521/">CVE-2020-2521</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025211" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25211</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25211" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25211" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25211" ref_url="https://www.suse.com/security/cve/CVE-2020-25211" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0241-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GZRN6BW22C4S3GVCJVPHDT4HHTLVGVZE/" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c, aka CID-1cc5ef91d2ff.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-25211/">CVE-2020-25211</cve>
	<bugzilla href="https://bugzilla.suse.com/1176395">SUSE bug 1176395</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192356">SUSE bug 1192356</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025212" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25212</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25212" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25212" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25212" ref_url="https://www.suse.com/security/cve/CVE-2020-25212" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2907-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2981-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007601.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007706.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007712.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007707.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007722.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3210-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007721.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3225-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-November/016787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007730.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1655-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1682-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25212/">CVE-2020-25212</cve>
	<bugzilla href="https://bugzilla.suse.com/1176381">SUSE bug 1176381</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1176382">SUSE bug 1176382</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177027">SUSE bug 1177027</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025219" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25219</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25219" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25219" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25219" ref_url="https://www.suse.com/security/cve/CVE-2020-25219" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:518-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:519-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007569.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2900-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007543.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2901-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007540.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1676-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1680-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00033.html" source="SUSE-SU"/>
    <description>
    url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25219/">CVE-2020-25219</cve>
	<bugzilla href="https://bugzilla.suse.com/1176410">SUSE bug 1176410</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760823" comment="libproxy1-0.4.15-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025220" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25220</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25220" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25220" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25220" ref_url="https://www.suse.com/security/cve/CVE-2020-25220" source="SUSE CVE"/>
    <description>
    The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd-&gt;no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25220/">CVE-2020-25220</cve>
	<bugzilla href="https://bugzilla.suse.com/1176392">SUSE bug 1176392</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025221" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25221</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25221" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25221" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25221" ref_url="https://www.suse.com/security/cve/CVE-2020-25221" source="SUSE CVE"/>
    <description>
    get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow. This can be triggered by any 64-bit process that can use ptrace() or process_vm_readv(), aka CID-9fa2dd946743.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25221/">CVE-2020-25221</cve>
	<bugzilla href="https://bugzilla.suse.com/1176286">SUSE bug 1176286</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025284" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25284</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25284" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25284" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25284" ref_url="https://www.suse.com/security/cve/CVE-2020-25284" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2907-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1586-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1655-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25284/">CVE-2020-25284</cve>
	<bugzilla href="https://bugzilla.suse.com/1176482">SUSE bug 1176482</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025285" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25285</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25285" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25285" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25285" ref_url="https://www.suse.com/security/cve/CVE-2020-25285" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1906-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7MTGDUP74HR4XORTRYN7I7MANTKWCGQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25285/">CVE-2020-25285</cve>
	<bugzilla href="https://bugzilla.suse.com/1176485">SUSE bug 1176485</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025592" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25592</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25592" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25592" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25592" ref_url="https://www.suse.com/security/cve/CVE-2020-25592" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14537-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007715.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14562-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14564-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3155-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3171-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007716.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3250-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007714.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3251-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007729.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009063.html" source="SUSE-SU"/>
		<reference ref_id="TID000019775" ref_url="https://www.suse.com/support/kb/doc/?id=000019775" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1833-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1868-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00029.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0899-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6E3YAO2VV3WBUS7PMAT26ZYDS3AXW5VL/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2106-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MU6P3NIODW6ZMC4HZLBROO6ZEOD5KAUX/" source="SUSE-SU"/>
    <description>
    In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25592/">CVE-2020-25592</cve>
	<bugzilla href="https://bugzilla.suse.com/1178319">SUSE bug 1178319</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009494057" comment="python3-distro-1.5.0-3.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504114" comment="python3-salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504115" comment="salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504120" comment="salt-minion-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504125" comment="salt-transactional-update-3002.2-37.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025595" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25595</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25595" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25595" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25595" ref_url="https://www.suse.com/security/cve/CVE-2020-25595" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1608-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been identified that act on unsanitized values read back from device hardware registers. While devices strictly compliant with PCI specifications shouldn't be able to affect these registers, experience shows that it's very common for devices to have out-of-spec "backdoor" operations that can affect the result of these reads. A not fully trusted guest may be able to crash Xen, leading to a Denial of Service (DoS) for the entire system. Privilege escalation and information leaks cannot be excluded. All versions of Xen supporting PCI passthrough are affected. Only x86 systems are vulnerable. Arm systems are not vulnerable. Only guests with passed through PCI devices may be able to leverage the vulnerability. Only systems passing through devices with out-of-spec ("backdoor") functionality can cause issues. Experience shows that such out-of-spec functionality is common; unless you have reason to believe that your device does not have such functionality, it's better to assume that it does.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25595/">CVE-2020-25595</cve>
	<bugzilla href="https://bugzilla.suse.com/1176344">SUSE bug 1176344</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025596" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25596</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25596" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25596" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25596" ref_url="https://www.suse.com/security/cve/CVE-2020-25596" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1608-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault, and incorrectly delivers it twice to the guest. This causes the guest kernel to observe a kernel-privilege #GP fault (typically fatal) rather than a user-privilege #GP fault (usually converted into SIGSEGV/etc.). Malicious or buggy userspace can crash the guest kernel, resulting in a VM Denial of Service. All versions of Xen from 3.2 onwards are vulnerable. Only x86 systems are vulnerable. ARM platforms are not vulnerable. Only x86 systems that support the SYSENTER instruction in 64bit mode are vulnerable. This is believed to be Intel, Centaur, and Shanghai CPUs. AMD and Hygon CPUs are not believed to be vulnerable. Only x86 PV guests can exploit the vulnerability. x86 PVH / HVM guests cannot exploit the vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25596/">CVE-2020-25596</cve>
	<bugzilla href="https://bugzilla.suse.com/1176345">SUSE bug 1176345</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025597" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25597</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25597" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25597" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25597" ref_url="https://www.suse.com/security/cve/CVE-2020-25597" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1608-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may not turn invalid. Logic in the handling of event channel operations in Xen assumes that an event channel, once valid, will not become invalid over the life time of a guest. However, operations like the resetting of all event channels may involve decreasing one of the bounds checked when determining validity. This may lead to bug checks triggering, crashing the host. An unprivileged guest may be able to crash Xen, leading to a Denial of Service (DoS) for the entire system. All Xen versions from 4.4 onwards are vulnerable. Xen versions 4.3 and earlier are not vulnerable. Only systems with untrusted guests permitted to create more than the default number of event channels are vulnerable. This number depends on the architecture and type of guest. For 32-bit x86 PV guests, this is 1023; for 64-bit x86 PV guests, and for all ARM guests, this number is 4095. Systems where untrusted guests are limited to fewer than this number are not vulnerable. Note that xl and libxl limit max_event_channels to 1023 by default, so systems using exclusively xl, libvirt+libxl, or their own toolstack based on libxl, and not explicitly setting max_event_channels, are not vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25597/">CVE-2020-25597</cve>
	<bugzilla href="https://bugzilla.suse.com/1176346">SUSE bug 1176346</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025598" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25598</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25598" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25598" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25598" ref_url="https://www.suse.com/security/cve/CVE-2020-25598" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007499.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1608-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Read, Copy, Update) mechanism is a synchronisation primitive. A buggy error path in the XENMEM_acquire_resource exits without releasing an RCU reference, which is conceptually similar to forgetting to unlock a spinlock. A buggy or malicious HVM stubdomain can cause an RCU reference to be leaked. This causes subsequent administration operations, (e.g., CPU offline) to livelock, resulting in a host Denial of Service. The buggy codepath has been present since Xen 4.12. Xen 4.14 and later are vulnerable to the DoS. The side effects are believed to be benign on Xen 4.12 and 4.13, but patches are provided nevertheless. The vulnerability can generally only be exploited by x86 HVM VMs, as these are generally the only type of VM that have a Qemu stubdomain. x86 PV and PVH domains, as well as ARM VMs, typically don't use a stubdomain. Only VMs using HVM stubdomains can exploit the vulnerability. VMs using PV stubdomains, or with emulators running in dom0, cannot exploit the vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25598/">CVE-2020-25598</cve>
	<bugzilla href="https://bugzilla.suse.com/1176341">SUSE bug 1176341</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025599" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25599</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25599" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25599" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25599" ref_url="https://www.suse.com/security/cve/CVE-2020-25599" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1608-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or triggering of bug checks. In particular, x86 PV guests may be able to elevate their privilege to that of the host. Host and guest crashes are also possible, leading to a Denial of Service (DoS). Information leaks cannot be ruled out. All Xen versions from 4.5 onwards are vulnerable. Xen versions 4.4 and earlier are not vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25599/">CVE-2020-25599</cve>
	<bugzilla href="https://bugzilla.suse.com/1176349">SUSE bug 1176349</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025600" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25600</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25600" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25600" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25600" ref_url="https://www.suse.com/security/cve/CVE-2020-25600" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1608-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of usable event channels for 32-bit x86 domains vs 64-bit or Arm (either bitness) ones. 32-bit x86 domains can use only 1023 channels, due to limited space in their shared (between guest and Xen) information structure, whereas all other domains can use up to 4095 in this model. The recording of the respective limit during domain initialization, however, has occurred at a time where domains are still deemed to be 64-bit ones, prior to actually honoring respective domain properties. At the point domains get recognized as 32-bit ones, the limit didn't get updated accordingly. Due to this misbehavior in Xen, 32-bit domains (including Domain 0) servicing other domains may observe event channel allocations to succeed when they should really fail. Subsequent use of such event channels would then possibly lead to corruption of other parts of the shared info structure. An unprivileged guest may cause another domain, in particular Domain 0, to misbehave. This may lead to a Denial of Service (DoS) for the entire system. All Xen versions from 4.4 onwards are vulnerable. Xen versions 4.3 and earlier are not vulnerable. Only x86 32-bit domains servicing other domains are vulnerable. Arm systems, as well as x86 64-bit domains, are not vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25600/">CVE-2020-25600</cve>
	<bugzilla href="https://bugzilla.suse.com/1176348">SUSE bug 1176348</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025601" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25601</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25601" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25601" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25601" ref_url="https://www.suse.com/security/cve/CVE-2020-25601" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1608-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event channel model allows guests to have a large number of event channels active at a time. Closing all of these (when resetting all event channels or when cleaning up after the guest) may take extended periods of time. So far, there was no arrangement for preemption at suitable intervals, allowing a CPU to spend an almost unbounded amount of time in the processing of these operations. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting the entire system. All Xen versions are vulnerable in principle. Whether versions 4.3 and older are vulnerable depends on underlying hardware characteristics.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25601/">CVE-2020-25601</cve>
	<bugzilla href="https://bugzilla.suse.com/1176350">SUSE bug 1176350</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025602" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25602</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25602" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25602" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25602" ref_url="https://www.suse.com/security/cve/CVE-2020-25602" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007499.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1608-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to MSR_MISC_ENABLE. When a guest accesses certain Model Specific Registers, Xen first reads the value from hardware to use as the basis for auditing the guest access. For the MISC_ENABLE MSR, which is an Intel specific MSR, this MSR read is performed without error handling for a #GP fault, which is the consequence of trying to read this MSR on non-Intel hardware. A buggy or malicious PV guest administrator can crash Xen, resulting in a host Denial of Service. Only x86 systems are vulnerable. ARM systems are not vulnerable. Only Xen versions 4.11 and onwards are vulnerable. 4.10 and earlier are not vulnerable. Only x86 systems that do not implement the MISC_ENABLE MSR (0x1a0) are vulnerable. AMD and Hygon systems do not implement this MSR and are vulnerable. Intel systems do implement this MSR and are not vulnerable. Other manufacturers have not been checked. Only x86 PV guests can exploit the vulnerability. x86 HVM/PVH guests cannot exploit the vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25602/">CVE-2020-25602</cve>
	<bugzilla href="https://bugzilla.suse.com/1176339">SUSE bug 1176339</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025603" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25603</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25603" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25603" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25603" ref_url="https://www.suse.com/security/cve/CVE-2020-25603" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1608-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event channel. Event channels control structures can be accessed lockless as long as the port is considered to be valid. Such a sequence is missing an appropriate memory barrier (e.g., smp_*mb()) to prevent both the compiler and CPU from re-ordering access. A malicious guest may be able to cause a hypervisor crash resulting in a Denial of Service (DoS). Information leak and privilege escalation cannot be excluded. Systems running all versions of Xen are affected. Whether a system is vulnerable will depend on the CPU and compiler used to build Xen. For all systems, the presence and the scope of the vulnerability depend on the precise re-ordering performed by the compiler used to build Xen. We have not been able to survey compilers; consequently we cannot say which compiler(s) might produce vulnerable code (with which code generation options). GCC documentation clearly suggests that re-ordering is possible. Arm systems will also be vulnerable if the CPU is able to re-order memory access. Please consult your CPU vendor. x86 systems are only vulnerable if a compiler performs re-ordering.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25603/">CVE-2020-25603</cve>
	<bugzilla href="https://bugzilla.suse.com/1176347">SUSE bug 1176347</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025604" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25604</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25604" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25604" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25604" ref_url="https://www.suse.com/security/cve/CVE-2020-25604" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007503.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007511.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1608-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. When migrating timers of x86 HVM guests between its vCPUs, the locking model used allows for a second vCPU of the same guest (also operating on the timers) to release a lock that it didn't acquire. The most likely effect of the issue is a hang or crash of the hypervisor, i.e., a Denial of Service (DoS). All versions of Xen are affected. Only x86 systems are vulnerable. Arm systems are not vulnerable. Only x86 HVM guests can leverage the vulnerability. x86 PV and PVH cannot leverage the vulnerability. Only guests with more than one vCPU can exploit the vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25604/">CVE-2020-25604</cve>
	<bugzilla href="https://bugzilla.suse.com/1176343">SUSE bug 1176343</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025613" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25613</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25613" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25613" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25613" ref_url="https://www.suse.com/security/cve/CVE-2020-25613" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008549.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009790.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0471-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RPFN4SV4JCJUNCQC4PQZ6VEJN63VN2FS/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-25613/">CVE-2020-25613</cve>
	<bugzilla href="https://bugzilla.suse.com/1177125">SUSE bug 1177125</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009503809" comment="libruby2_5-2_5-2.5.8-4.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009503810" comment="ruby2.5-2.5.8-4.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009503813" comment="ruby2.5-stdlib-2.5.8-4.14.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025624" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25624</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25624" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25624" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25624" ref_url="https://www.suse.com/security/cve/CVE-2020-25624" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
    <description>
    hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-25624/">CVE-2020-25624</cve>
	<bugzilla href="https://bugzilla.suse.com/1176682">SUSE bug 1176682</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704859" comment="qemu-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499829" comment="qemu-arm-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499837" comment="qemu-ipxe-1.0.0+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499843" comment="qemu-seabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499844" comment="qemu-sgabios-8-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704860" comment="qemu-tools-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499848" comment="qemu-vgabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499849" comment="qemu-x86-4.2.1-11.16.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025625" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25625</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25625" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25625" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25625" ref_url="https://www.suse.com/security/cve/CVE-2020-25625" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
    <description>
    hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-25625/">CVE-2020-25625</cve>
	<bugzilla href="https://bugzilla.suse.com/1176684">SUSE bug 1176684</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704859" comment="qemu-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499829" comment="qemu-arm-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499837" comment="qemu-ipxe-1.0.0+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499843" comment="qemu-seabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499844" comment="qemu-sgabios-8-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704860" comment="qemu-tools-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499848" comment="qemu-vgabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499849" comment="qemu-x86-4.2.1-11.16.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025637" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25637</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25637" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25637" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25637" ref_url="https://www.suse.com/security/cve/CVE-2020-25637" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:2969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2970-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007626.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007628.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007687.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1777-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00073.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1778-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00072.html" source="SUSE-SU"/>
    <description>
    A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-write socket with limited ACL permissions could use this flaw to crash the libvirt daemon, resulting in a denial of service, or potentially escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25637/">CVE-2020-25637</cve>
	<bugzilla href="https://bugzilla.suse.com/1174955">SUSE bug 1174955</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177155">SUSE bug 1177155</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760835" comment="libvirt-libs-6.0.0-13.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025639" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25639</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25639" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25639" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25639" ref_url="https://www.suse.com/security/cve/CVE-2020-25639" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008354.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25639/">CVE-2020-25639</cve>
	<bugzilla href="https://bugzilla.suse.com/1176846">SUSE bug 1176846</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025641" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25641</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25641" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25641" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25641" ref_url="https://www.suse.com/security/cve/CVE-2020-25641" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2907-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2980-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007730.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1655-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block device, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25641/">CVE-2020-25641</cve>
	<bugzilla href="https://bugzilla.suse.com/1177121">SUSE bug 1177121</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025643" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25643</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25643" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25643" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25643" ref_url="https://www.suse.com/security/cve/CVE-2020-25643" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2907-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2980-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007730.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1655-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25643/">CVE-2020-25643</cve>
	<bugzilla href="https://bugzilla.suse.com/1177206">SUSE bug 1177206</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177226">SUSE bug 1177226</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025645" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25645</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25645" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25645" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25645" ref_url="https://www.suse.com/security/cve/CVE-2020-25645" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2980-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2981-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007601.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007730.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007798.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3400-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007802.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007803.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3449-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007816.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3656-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007925.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008612.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1682-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00035.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1698-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00042.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-25645/">CVE-2020-25645</cve>
	<bugzilla href="https://bugzilla.suse.com/1177511">SUSE bug 1177511</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177513">SUSE bug 1177513</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025648" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25648</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25648" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25648" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25648" ref_url="https://www.suse.com/security/cve/CVE-2020-25648" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25648/">CVE-2020-25648</cve>
	<bugzilla href="https://bugzilla.suse.com/1177917">SUSE bug 1177917</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009632956" comment="libfreebl3-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632960" comment="libsoftokn3-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632964" comment="mozilla-nspr-4.32-3.20.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632967" comment="mozilla-nss-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632969" comment="mozilla-nss-certs-3.68-3.56.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025656" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25656</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25656" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25656" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25656" ref_url="https://www.suse.com/security/cve/CVE-2020-25656" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1906-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7MTGDUP74HR4XORTRYN7I7MANTKWCGQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25656/">CVE-2020-25656</cve>
	<bugzilla href="https://bugzilla.suse.com/1177766">SUSE bug 1177766</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025659" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25659</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25659" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25659" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25659" ref_url="https://www.suse.com/security/cve/CVE-2020-25659" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007932.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007933.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2854-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016085.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:3070-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:3073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016268.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:3084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:629-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:953-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:612-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3592-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007905.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3629-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2783-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016228.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2173-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6HSP2RSDCASVO7P7KBUV5GDZ6SYI6L7I/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-25659/">CVE-2020-25659</cve>
	<bugzilla href="https://bugzilla.suse.com/1178168">SUSE bug 1178168</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
</definition>
<definition id="oval:org.opensuse.security:def:202025661" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25661</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25661" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25661" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25661" ref_url="https://www.suse.com/security/cve/CVE-2020-25661" source="SUSE CVE"/>
    <description>
    A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID. This flaw allows a remote attacker in an adjacent range to crash the system, causing a denial of service or potentially executing arbitrary code on the system by sending a specially crafted L2CAP packet. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25661/">CVE-2020-25661</cve>
	<bugzilla href="https://bugzilla.suse.com/1178397">SUSE bug 1178397</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025662" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25662</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25662" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25662" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25662" ref_url="https://www.suse.com/security/cve/CVE-2020-25662" source="SUSE CVE"/>
    <description>
    A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remote attacker in an adjacent range to leak small portions of stack memory on the system by sending specially crafted AMP packets. The highest threat from this vulnerability is to data confidentiality.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-25662/">CVE-2020-25662</cve>
	<bugzilla href="https://bugzilla.suse.com/1178398">SUSE bug 1178398</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025668" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25668</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25668" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25668" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25668" ref_url="https://www.suse.com/security/cve/CVE-2020-25668" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3651-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3670-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3690-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3698-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1906-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7MTGDUP74HR4XORTRYN7I7MANTKWCGQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25668/">CVE-2020-25668</cve>
	<bugzilla href="https://bugzilla.suse.com/1178123">SUSE bug 1178123</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178622">SUSE bug 1178622</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196914">SUSE bug 1196914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025669" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25669</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25669" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25669" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25669" ref_url="https://www.suse.com/security/cve/CVE-2020-25669" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2034-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7GIP2AYRG3VCHD6CCU4URBF5KVBKIT63/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2161-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ICEKZTGIQ6MSKDFOTIOJ2RLWAWJFPSYA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd being freed. Though the dangling pointer is set to NULL in sunkbd_disconnect, there is still an alias in sunkbd_reinit causing Use After Free.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25669/">CVE-2020-25669</cve>
	<bugzilla href="https://bugzilla.suse.com/1178182">SUSE bug 1178182</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025670" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25670</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25670" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25670" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25670" ref_url="https://www.suse.com/security/cve/CVE-2020-25670" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1248-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010158.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010183.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-25670/">CVE-2020-25670</cve>
	<bugzilla href="https://bugzilla.suse.com/1178181">SUSE bug 1178181</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194680">SUSE bug 1194680</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025671" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25671</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25671" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25671" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25671" ref_url="https://www.suse.com/security/cve/CVE-2020-25671" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1248-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010158.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010183.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25671/">CVE-2020-25671</cve>
	<bugzilla href="https://bugzilla.suse.com/1178181">SUSE bug 1178181</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025672" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25672</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25672" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25672" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25672" ref_url="https://www.suse.com/security/cve/CVE-2020-25672" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1248-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010158.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010183.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25672/">CVE-2020-25672</cve>
	<bugzilla href="https://bugzilla.suse.com/1178181">SUSE bug 1178181</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025673" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25673</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25673" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25673" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25673" ref_url="https://www.suse.com/security/cve/CVE-2020-25673" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1248-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010158.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010183.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25673/">CVE-2020-25673</cve>
	<bugzilla href="https://bugzilla.suse.com/1178181">SUSE bug 1178181</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025692" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25692</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25692" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25692" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25692" ref_url="https://www.suse.com/security/cve/CVE-2020-25692" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:673-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:674-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007772.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007773.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007774.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:683-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007790.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:696-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:698-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:705-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:707-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007868.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:709-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007869.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:815-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007765.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007764.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1918-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3VC65YBN4WMTACGDQE7SGD2ZBAJBKS3O/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1920-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/P5OV5ACOVPOXU3LAYTZRU6RI5XRK4L6W/" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25692/">CVE-2020-25692</cve>
	<bugzilla href="https://bugzilla.suse.com/1178387">SUSE bug 1178387</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025704" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25704</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25704" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25704" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25704" ref_url="https://www.suse.com/security/cve/CVE-2020-25704" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1906-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7MTGDUP74HR4XORTRYN7I7MANTKWCGQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2034-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7GIP2AYRG3VCHD6CCU4URBF5KVBKIT63/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25704/">CVE-2020-25704</cve>
	<bugzilla href="https://bugzilla.suse.com/1178393">SUSE bug 1178393</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025705" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25705</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25705" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25705" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25705" ref_url="https://www.suse.com/security/cve/CVE-2020-25705" source="SUSE CVE"/>
		<reference ref_id="SADDNS-BLOG" ref_url="https://www.suse.com/c/suse-releases-fix-for-saddns-vulnerability/" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3651-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3670-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3690-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007977.html" source="SUSE-SU"/>
		<reference ref_id="TID000019786" ref_url="https://www.suse.com/support/kb/doc/?id=000019786" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2034-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7GIP2AYRG3VCHD6CCU4URBF5KVBKIT63/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2161-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ICEKZTGIQ6MSKDFOTIOJ2RLWAWJFPSYA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as well on the Linux Based Products (RUGGEDCOM RM1224: All versions between v5.0 and v6.4, SCALANCE M-800: All versions between v5.0 and v6.4, SCALANCE S615: All versions between v5.0 and v6.4, SCALANCE SC-600: All versions prior to v2.1.3, SCALANCE W1750D: v8.3.0.1, v8.6.0, and v8.7.0, SIMATIC Cloud Connect 7: All versions, SIMATIC MV500 Family: All versions, SIMATIC NET CP 1243-1 (incl. SIPLUS variants): Versions 3.1.39 and later, SIMATIC NET CP 1243-7 LTE EU: Version
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-25705/">CVE-2020-25705</cve>
	<bugzilla href="https://bugzilla.suse.com/1175721">SUSE bug 1175721</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178782">SUSE bug 1178782</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178783">SUSE bug 1178783</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191790">SUSE bug 1191790</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025707" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25707</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25707" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25707" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25707" ref_url="https://www.suse.com/security/cve/CVE-2020-25707" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14774-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1895-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008990.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate is a duplicate of CVE-2020-28916
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25707/">CVE-2020-25707</cve>
	<bugzilla href="https://bugzilla.suse.com/1178683">SUSE bug 1178683</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179468">SUSE bug 1179468</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704898" comment="qemu-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499897" comment="qemu-arm-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499905" comment="qemu-ipxe-1.0.0+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499911" comment="qemu-seabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499912" comment="qemu-sgabios-8-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704899" comment="qemu-tools-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499916" comment="qemu-vgabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499917" comment="qemu-x86-4.2.1-11.19.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025709" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25709</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25709" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25709" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25709" ref_url="https://www.suse.com/security/cve/CVE-2020-25709" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:22-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:23-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:24-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:26-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008214.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:50-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:51-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008286.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0128-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008207.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0102-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HXI5DVBGML6XRCQGGMOYKQFUJDZ2JPS6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0107-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DU5LAY3LI5VYENQTLYA5AGNA47GQHI2B/" source="SUSE-SU"/>
    <description>
    A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25709/">CVE-2020-25709</cve>
	<bugzilla href="https://bugzilla.suse.com/1178909">SUSE bug 1178909</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025710" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25710</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25710" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25710" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25710" ref_url="https://www.suse.com/security/cve/CVE-2020-25710" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:22-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:23-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008209.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:24-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:26-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008214.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:50-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:51-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008286.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0128-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008207.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0102-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HXI5DVBGML6XRCQGGMOYKQFUJDZ2JPS6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0107-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/DU5LAY3LI5VYENQTLYA5AGNA47GQHI2B/" source="SUSE-SU"/>
    <description>
    A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-25710/">CVE-2020-25710</cve>
	<bugzilla href="https://bugzilla.suse.com/1178909">SUSE bug 1178909</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202025723" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-25723</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-25723" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25723" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-25723" ref_url="https://www.suse.com/security/cve/CVE-2020-25723" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008910.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1895-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008990.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
    <description>
    A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host, resulting in a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-25723/">CVE-2020-25723</cve>
	<bugzilla href="https://bugzilla.suse.com/1178934">SUSE bug 1178934</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178935">SUSE bug 1178935</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704898" comment="qemu-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499897" comment="qemu-arm-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499905" comment="qemu-ipxe-1.0.0+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499911" comment="qemu-seabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499912" comment="qemu-sgabios-8-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704899" comment="qemu-tools-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499916" comment="qemu-vgabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499917" comment="qemu-x86-4.2.1-11.19.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202026088" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-26088</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-26088" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26088" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-26088" ref_url="https://www.suse.com/security/cve/CVE-2020-26088" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2879-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2907-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3014-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1586-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00001.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1655-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-26088/">CVE-2020-26088</cve>
	<bugzilla href="https://bugzilla.suse.com/1176990">SUSE bug 1176990</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202026116" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-26116</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-26116" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26116" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-26116" ref_url="https://www.suse.com/security/cve/CVE-2020-26116" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:410-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008464.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0299-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0341-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008330.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0515-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008345.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1859-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1988-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KQJZUPSO3MIAIYJBX2VTZETYQSLUJQPN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2332-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S3JTHM6LLDKL7VPNRJUSRPNZAD2FZ25H/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2333-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FLGERALYYFTBIX3ZKPM6EQ2WJVUXLOXY/" source="SUSE-SU"/>
    <description>
    http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-26116/">CVE-2020-26116</cve>
	<bugzilla href="https://bugzilla.suse.com/1177120">SUSE bug 1177120</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177211">SUSE bug 1177211</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192361">SUSE bug 1192361</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202026137" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-26137</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-26137" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26137" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-26137" ref_url="https://www.suse.com/security/cve/CVE-2020-26137" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:612-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007763.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009334.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3251-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009517.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2237-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3Y5UAWOTOHQRGI2VNSOUDC2SOAHGJLAH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2282-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VS7J7DOJY26YMLJIUVHRH7UQFVLGBWIQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1206-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6CAFSANHH6TU43VSKAJ5JA2EMHSREMKP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2817-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TOZI5ZFPFR2BACIE74HUJWDXC2ZWXNGD/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-26137/">CVE-2020-26137</cve>
	<bugzilla href="https://bugzilla.suse.com/1177120">SUSE bug 1177120</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1177211">SUSE bug 1177211</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009626945" comment="python3-asn1crypto-0.24.0-3.2.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704939" comment="python3-cffi-1.13.2-3.2.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704940" comment="python3-cryptography-2.8-10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626950" comment="python3-pyOpenSSL-17.5.0-8.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626951" comment="python3-pyasn1-0.4.2-3.2.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626952" comment="python3-pycparser-2.17-3.2.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626953" comment="python3-urllib3-1.25.10-9.14.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202026139" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-26139</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-26139" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26139" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-26139" ref_url="https://www.suse.com/security/cve/CVE-2020-26139" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="TID000020244" ref_url="https://www.suse.com/support/kb/doc/?id=000020244" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-26139/">CVE-2020-26139</cve>
	<bugzilla href="https://bugzilla.suse.com/1186062">SUSE bug 1186062</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192868">SUSE bug 1192868</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202026141" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-26141</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-26141" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26141" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-26141" ref_url="https://www.suse.com/security/cve/CVE-2020-26141" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="TID000020244" ref_url="https://www.suse.com/support/kb/doc/?id=000020244" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP data-confidentiality protocol.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-26141/">CVE-2020-26141</cve>
	<bugzilla href="https://bugzilla.suse.com/1185987">SUSE bug 1185987</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202026145" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-26145</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-26145" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26145" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-26145" ref_url="https://www.suse.com/security/cve/CVE-2020-26145" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="TID000020244" ref_url="https://www.suse.com/support/kb/doc/?id=000020244" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-26145/">CVE-2020-26145</cve>
	<bugzilla href="https://bugzilla.suse.com/1185860">SUSE bug 1185860</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202026147" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-26147</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-26147" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26147" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-26147" ref_url="https://www.suse.com/security/cve/CVE-2020-26147" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="TID000020244" ref_url="https://www.suse.com/support/kb/doc/?id=000020244" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-26147/">CVE-2020-26147</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202026154" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-26154</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-26154" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26154" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-26154" ref_url="https://www.suse.com/security/cve/CVE-2020-26154" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:518-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:519-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007569.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2900-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007543.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2901-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007540.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1676-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1680-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00033.html" source="SUSE-SU"/>
    <description>
    url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-26154/">CVE-2020-26154</cve>
	<bugzilla href="https://bugzilla.suse.com/1177143">SUSE bug 1177143</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760823" comment="libproxy1-0.4.15-4.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202026558" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-26558</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-26558" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26558" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-26558" ref_url="https://www.suse.com/security/cve/CVE-2020-26558" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009123.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3691-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012602.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2184-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GJZ4RMNGAPDHTNV6KJGNPSEJH2RUZFKU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/T4PWFRJWECGAGZTBIOYHZ6KUMSA6KC43/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2291-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FGEHNTYN7DOZBN7IPNNCVSIU2JNPC226/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
    <description>
    Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-26558/">CVE-2020-26558</cve>
	<bugzilla href="https://bugzilla.suse.com/1179610">SUSE bug 1179610</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186463">SUSE bug 1186463</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704907" comment="kernel-default-5.3.18-24.70.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704908" comment="kernel-default-base-5.3.18-24.70.1.9.32.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624613" comment="kernel-rt-4.12.14-10.49.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336474" comment="libbluetooth3 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027068" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27068</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27068" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27068" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27068" ref_url="https://www.suse.com/security/cve/CVE-2020-27068" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    Product: AndroidVersions: Android kernelAndroid ID: A-127973231References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-27068/">CVE-2020-27068</cve>
	<bugzilla href="https://bugzilla.suse.com/1180086">SUSE bug 1180086</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027152" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27152</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27152" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27152" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27152" ref_url="https://www.suse.com/security/cve/CVE-2020-27152" source="SUSE CVE"/>
    <description>
    An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-27152/">CVE-2020-27152</cve>
	<bugzilla href="https://bugzilla.suse.com/1177785">SUSE bug 1177785</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027153" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27153</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27153" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27153" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27153" ref_url="https://www.suse.com/security/cve/CVE-2020-27153" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:3034-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007701.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1876-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00034.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1880-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00036.html" source="SUSE-SU"/>
    <description>
    In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconnect MGMT event.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-27153/">CVE-2020-27153</cve>
	<bugzilla href="https://bugzilla.suse.com/1177895">SUSE bug 1177895</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760813" comment="libbluetooth3-5.48-13.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027170" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27170</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27170" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27170" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27170" ref_url="https://www.suse.com/security/cve/CVE-2020-27170" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-27170/">CVE-2020-27170</cve>
	<bugzilla href="https://bugzilla.suse.com/1183686">SUSE bug 1183686</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183775">SUSE bug 1183775</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027171" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27171</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27171" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27171" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27171" ref_url="https://www.suse.com/security/cve/CVE-2020-27171" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-10d2bb2e6b1d.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-27171/">CVE-2020-27171</cve>
	<bugzilla href="https://bugzilla.suse.com/1183686">SUSE bug 1183686</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183775">SUSE bug 1183775</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027194" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27194</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27194" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27194" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27194" ref_url="https://www.suse.com/security/cve/CVE-2020-27194" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-27194/">CVE-2020-27194</cve>
	<bugzilla href="https://bugzilla.suse.com/1177889">SUSE bug 1177889</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20202732" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-2732</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-2732" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2732" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-2732" ref_url="https://www.suse.com/security/cve/CVE-2020-2732" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0667-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0688-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006612.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-2732/">CVE-2020-2732</cve>
	<bugzilla href="https://bugzilla.suse.com/1163971">SUSE bug 1163971</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027418" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27418</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27418" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27418" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27418" ref_url="https://www.suse.com/security/cve/CVE-2020-27418" source="SUSE CVE"/>
    <description>
    A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_invert_region() function.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-05"/>
	<updated date="2023-09-05"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-27418/">CVE-2020-27418</cve>
	<bugzilla href="https://bugzilla.suse.com/1214919">SUSE bug 1214919</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027616" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27616</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27616" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27616" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27616" ref_url="https://www.suse.com/security/cve/CVE-2020-27616" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
    <description>
    ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. A guest can crash the QEMU process.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-27616/">CVE-2020-27616</cve>
	<bugzilla href="https://bugzilla.suse.com/1178400">SUSE bug 1178400</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188609">SUSE bug 1188609</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704859" comment="qemu-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499829" comment="qemu-arm-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499837" comment="qemu-ipxe-1.0.0+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499843" comment="qemu-seabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499844" comment="qemu-sgabios-8-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704860" comment="qemu-tools-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499848" comment="qemu-vgabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499849" comment="qemu-x86-4.2.1-11.16.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027617" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27617</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27617" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27617" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27617" ref_url="https://www.suse.com/security/cve/CVE-2020-27617" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
    <description>
    eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-27617/">CVE-2020-27617</cve>
	<bugzilla href="https://bugzilla.suse.com/1178174">SUSE bug 1178174</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704859" comment="qemu-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499829" comment="qemu-arm-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499837" comment="qemu-ipxe-1.0.0+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499843" comment="qemu-seabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499844" comment="qemu-sgabios-8-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704860" comment="qemu-tools-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499848" comment="qemu-vgabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499849" comment="qemu-x86-4.2.1-11.16.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027619" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27619</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27619" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27619" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27619" ref_url="https://www.suse.com/security/cve/CVE-2020-27619" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3865-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008081.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008118.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2332-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S3JTHM6LLDKL7VPNRJUSRPNZAD2FZ25H/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2333-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FLGERALYYFTBIX3ZKPM6EQ2WJVUXLOXY/" source="SUSE-SU"/>
    <description>
    In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-27619/">CVE-2020-27619</cve>
	<bugzilla href="https://bugzilla.suse.com/1178009">SUSE bug 1178009</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180254">SUSE bug 1180254</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193386">SUSE bug 1193386</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027670" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27670</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27670" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27670" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27670" ref_url="https://www.suse.com/security/cve/CVE-2020-27670" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3052-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007667.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007911.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007914.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007959.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1783-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1844-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2162-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4FGJHRZRKWQ2TYU34S47P4GNDICF6RCY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2192-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5GBNU2YMLJN6R7ACNKZML4MG7X35FZTY/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because an AMD IOMMU page-table entry can be half-updated.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-27670/">CVE-2020-27670</cve>
	<bugzilla href="https://bugzilla.suse.com/1177414">SUSE bug 1177414</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183925">SUSE bug 1183925</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027671" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27671</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27671" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27671" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27671" ref_url="https://www.suse.com/security/cve/CVE-2020-27671" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3052-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007667.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007911.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007914.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007959.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1783-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1844-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2162-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4FGJHRZRKWQ2TYU34S47P4GNDICF6RCY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2192-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5GBNU2YMLJN6R7ACNKZML4MG7X35FZTY/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing of per-page IOMMU TLB flushes is mishandled.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-27671/">CVE-2020-27671</cve>
	<bugzilla href="https://bugzilla.suse.com/1177413">SUSE bug 1177413</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183925">SUSE bug 1183925</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027672" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27672</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27672" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27672" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27672" ref_url="https://www.suse.com/security/cve/CVE-2020-27672" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3052-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007667.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007911.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007914.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007959.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1783-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1844-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2162-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4FGJHRZRKWQ2TYU34S47P4GNDICF6RCY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2192-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5GBNU2YMLJN6R7ACNKZML4MG7X35FZTY/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-27672/">CVE-2020-27672</cve>
	<bugzilla href="https://bugzilla.suse.com/1177412">SUSE bug 1177412</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183925">SUSE bug 1183925</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027673" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27673</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27673" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27673" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27673" ref_url="https://www.suse.com/security/cve/CVE-2020-27673" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3052-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007667.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1783-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00075.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1844-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00025.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-27673/">CVE-2020-27673</cve>
	<bugzilla href="https://bugzilla.suse.com/1177411">SUSE bug 1177411</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1184583">SUSE bug 1184583</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027674" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27674</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27674" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27674" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27674" ref_url="https://www.suse.com/security/cve/CVE-2020-27674" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007911.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007914.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007959.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2162-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4FGJHRZRKWQ2TYU34S47P4GNDICF6RCY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2192-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5GBNU2YMLJN6R7ACNKZML4MG7X35FZTY/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-27674/">CVE-2020-27674</cve>
	<bugzilla href="https://bugzilla.suse.com/1177409">SUSE bug 1177409</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027675" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27675</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27675" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27675" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27675" ref_url="https://www.suse.com/security/cve/CVE-2020-27675" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condition). This can cause a use-after-free or NULL pointer dereference, as demonstrated by a dom0 crash via events for an in-reconfiguration paravirtualized device, aka CID-073d0552ead5.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-27675/">CVE-2020-27675</cve>
	<bugzilla href="https://bugzilla.suse.com/1177410">SUSE bug 1177410</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027777" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27777</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27777" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27777" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27777" ref_url="https://www.suse.com/security/cve/CVE-2020-27777" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3714-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-December/017242.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2161-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ICEKZTGIQ6MSKDFOTIOJ2RLWAWJFPSYA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2193-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4YRSQJNKLIOJJTD3P2UKMHRFMCIG3JDN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further increase their privileges to that of a running kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-27777/">CVE-2020-27777</cve>
	<bugzilla href="https://bugzilla.suse.com/1179107">SUSE bug 1179107</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179419">SUSE bug 1179419</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200343">SUSE bug 1200343</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027784" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27784</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27784" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27784" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27784" ref_url="https://www.suse.com/security/cve/CVE-2020-27784" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in the Linux kernel, where accessing a deallocated instance in printer_ioctl() printer_ioctl() tries to access of a printer_dev instance. However, use-after-free arises because it had been freed by gprinter_free().
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-31"/>
	<updated date="2022-11-01"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-27784/">CVE-2020-27784</cve>
	<bugzilla href="https://bugzilla.suse.com/1202895">SUSE bug 1202895</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027786" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27786</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27786" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27786" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27786" ref_url="https://www.suse.com/security/cve/CVE-2020-27786" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0818-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008500.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008509.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008502.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0868-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0870-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this specific memory while freed and before use causes the flow of execution to change and possibly allow for memory corruption or privilege escalation. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-27786/">CVE-2020-27786</cve>
	<bugzilla href="https://bugzilla.suse.com/1179601">SUSE bug 1179601</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179616">SUSE bug 1179616</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027815" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27815</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27815" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27815" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27815" ref_url="https://www.suse.com/security/cve/CVE-2020-27815" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-27815/">CVE-2020-27815</cve>
	<bugzilla href="https://bugzilla.suse.com/1179454">SUSE bug 1179454</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179458">SUSE bug 1179458</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027820" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27820</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27820" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27820" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27820" ref_url="https://www.suse.com/security/cve/CVE-2020-27820" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009873.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010396.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.1/CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-27820/">CVE-2020-27820</cve>
	<bugzilla href="https://bugzilla.suse.com/1179599">SUSE bug 1179599</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658974" comment="kernel-rt-5.3.18-62.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027821" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27821</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27821" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27821" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27821" ref_url="https://www.suse.com/security/cve/CVE-2020-27821" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
    <description>
    A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-27821/">CVE-2020-27821</cve>
	<bugzilla href="https://bugzilla.suse.com/1179686">SUSE bug 1179686</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704859" comment="qemu-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499829" comment="qemu-arm-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499837" comment="qemu-ipxe-1.0.0+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499843" comment="qemu-seabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499844" comment="qemu-sgabios-8-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704860" comment="qemu-tools-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499848" comment="qemu-vgabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499849" comment="qemu-x86-4.2.1-11.16.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027825" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27825</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27825" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27825" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27825" ref_url="https://www.suse.com/security/cve/CVE-2020-27825" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-27825/">CVE-2020-27825</cve>
	<bugzilla href="https://bugzilla.suse.com/1179960">SUSE bug 1179960</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179961">SUSE bug 1179961</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027830" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27830</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27830" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27830" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27830" ref_url="https://www.suse.com/security/cve/CVE-2020-27830" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checking whether it is NULL or not, and may lead to a NULL-ptr deref crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-27830/">CVE-2020-27830</cve>
	<bugzilla href="https://bugzilla.suse.com/1179656">SUSE bug 1179656</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202027835" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-27835</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-27835" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27835" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-27835" ref_url="https://www.suse.com/security/cve/CVE-2020-27835" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1669-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011033.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
    <description>
    A use after free in the Linux kernel infiniband hfi1 driver in versions prior to 5.10-rc6 was found in the way user calls Ioctl after open dev file and fork. A local user could use this flaw to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-27835/">CVE-2020-27835</cve>
	<bugzilla href="https://bugzilla.suse.com/1179878">SUSE bug 1179878</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202028196" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-28196</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-28196" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28196" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-28196" ref_url="https://www.suse.com/security/cve/CVE-2020-28196" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:686-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:688-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:693-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:696-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:698-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:703-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:705-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:707-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:708-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007868.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:709-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007869.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:815-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3375-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-November/016941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3377-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3379-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007792.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2CMUQ7G43OCIKDTP2ILYUJLUD37RPPA3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2062-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/O6PZTATZYCUQYKCJ6QBS7JJHNWPXIDNL/" source="SUSE-SU"/>
    <description>
    MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-28196/">CVE-2020-28196</cve>
	<bugzilla href="https://bugzilla.suse.com/1178512">SUSE bug 1178512</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183911">SUSE bug 1183911</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628540" comment="krb5-1.16.3-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202028243" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-28243</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-28243" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28243" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-28243" ref_url="https://www.suse.com/security/cve/CVE-2020-28243" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14679-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1690-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008813.html" source="SUSE-SU"/>
		<reference ref_id="TID000019887" ref_url="https://www.suse.com/support/kb/doc/?id=000019887" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0347-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CYH7ONK65HNBANHLED5R64OBSM2EORYI/" source="SUSE-SU"/>
    <description>
    An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-28243/">CVE-2020-28243</cve>
	<bugzilla href="https://bugzilla.suse.com/1181550">SUSE bug 1181550</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181556">SUSE bug 1181556</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202028368" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-28368</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-28368" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28368" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-28368" ref_url="https://www.suse.com/security/cve/CVE-2020-28368" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007814.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007815.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3414-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007813.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007811.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007911.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3612-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007910.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007914.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1023-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1460-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008718.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2017-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NHV4EWRFFS4A6PZIGBZQ2KTQFUWF52LY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2030-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CK4ZVHN5CZEV5SEFNJFHEB2GTN3V6YCK/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2162-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4FGJHRZRKWQ2TYU34S47P4GNDICF6RCY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2192-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5GBNU2YMLJN6R7ACNKZML4MG7X35FZTY/" source="SUSE-SU"/>
    <description>
    Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-28368/">CVE-2020-28368</cve>
	<bugzilla href="https://bugzilla.suse.com/1178591">SUSE bug 1178591</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202028374" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-28374</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-28374" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28374" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-28374" ref_url="https://www.suse.com/security/cve/CVE-2020-28374" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0093-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-January/017662.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0818-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008500.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008509.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008502.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0868-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0870-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008497.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
    <description>
    In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-28374/">CVE-2020-28374</cve>
	<bugzilla href="https://bugzilla.suse.com/1178372">SUSE bug 1178372</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178684">SUSE bug 1178684</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180676">SUSE bug 1180676</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202028588" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-28588</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-28588" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28588" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-28588" ref_url="https://www.suse.com/security/cve/CVE-2020-28588" source="SUSE CVE"/>
    <description>
    An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in v5.10-rc4, so it’s likely that all versions in between are affected. An attacker can read /proc/pid/syscall to trigger this vulnerability, which leads to the kernel leaking memory contents.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-28588/">CVE-2020-28588</cve>
	<bugzilla href="https://bugzilla.suse.com/1182806">SUSE bug 1182806</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202028915" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-28915</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-28915" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28915" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-28915" ref_url="https://www.suse.com/security/cve/CVE-2020-28915" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3714-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-December/017242.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2034-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7GIP2AYRG3VCHD6CCU4URBF5KVBKIT63/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2161-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ICEKZTGIQ6MSKDFOTIOJ2RLWAWJFPSYA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-28915/">CVE-2020-28915</cve>
	<bugzilla href="https://bugzilla.suse.com/1178886">SUSE bug 1178886</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202028916" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-28916</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-28916" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28916" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-28916" ref_url="https://www.suse.com/security/cve/CVE-2020-28916" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
    <description>
    hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-28916/">CVE-2020-28916</cve>
	<bugzilla href="https://bugzilla.suse.com/1178683">SUSE bug 1178683</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179468">SUSE bug 1179468</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704859" comment="qemu-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499829" comment="qemu-arm-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499837" comment="qemu-ipxe-1.0.0+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499843" comment="qemu-seabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499844" comment="qemu-sgabios-8-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704860" comment="qemu-tools-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499848" comment="qemu-vgabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499849" comment="qemu-x86-4.2.1-11.16.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202028941" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-28941</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-28941" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28941" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-28941" ref_url="https://www.suse.com/security/cve/CVE-2020-28941" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007977.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2161-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ICEKZTGIQ6MSKDFOTIOJ2RLWAWJFPSYA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more than once.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-28941/">CVE-2020-28941</cve>
	<bugzilla href="https://bugzilla.suse.com/1178740">SUSE bug 1178740</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202028972" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-28972</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-28972" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28972" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-28972" ref_url="https://www.suse.com/security/cve/CVE-2020-28972" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14679-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1690-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008813.html" source="SUSE-SU"/>
		<reference ref_id="TID000019887" ref_url="https://www.suse.com/support/kb/doc/?id=000019887" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0347-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CYH7ONK65HNBANHLED5R64OBSM2EORYI/" source="SUSE-SU"/>
    <description>
    In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-28972/">CVE-2020-28972</cve>
	<bugzilla href="https://bugzilla.suse.com/1181550">SUSE bug 1181550</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181557">SUSE bug 1181557</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202028974" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-28974</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-28974" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28974" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-28974" ref_url="https://www.suse.com/security/cve/CVE-2020-28974" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3714-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-December/017242.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2161-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ICEKZTGIQ6MSKDFOTIOJ2RLWAWJFPSYA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2193-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4YRSQJNKLIOJJTD3P2UKMHRFMCIG3JDN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel, aka CID-3c4e0dff2095. This occurs because KD_FONT_OP_COPY in drivers/tty/vt/vt.c can be used for manipulations such as font height.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-28974/">CVE-2020-28974</cve>
	<bugzilla href="https://bugzilla.suse.com/1178589">SUSE bug 1178589</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029129" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29129</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29129" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29129" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29129" ref_url="https://www.suse.com/security/cve/CVE-2020-29129" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1895-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0870-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014131.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
    <description>
    ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-29129/">CVE-2020-29129</cve>
	<bugzilla href="https://bugzilla.suse.com/1179466">SUSE bug 1179466</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179467">SUSE bug 1179467</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179477">SUSE bug 1179477</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179484">SUSE bug 1179484</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704898" comment="qemu-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499897" comment="qemu-arm-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499905" comment="qemu-ipxe-1.0.0+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499911" comment="qemu-seabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499912" comment="qemu-sgabios-8-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704899" comment="qemu-tools-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499916" comment="qemu-vgabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499917" comment="qemu-x86-4.2.1-11.19.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029130" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29130</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29130" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29130" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29130" ref_url="https://www.suse.com/security/cve/CVE-2020-29130" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3945-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008910.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1895-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0943-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010763.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0870-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014131.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0943-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JBLIOF4HVH74MTJYI7P5QNH2RNAYWU5E/" source="SUSE-SU"/>
    <description>
    slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-29130/">CVE-2020-29130</cve>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179467">SUSE bug 1179467</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179477">SUSE bug 1179477</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704898" comment="qemu-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499897" comment="qemu-arm-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499905" comment="qemu-ipxe-1.0.0+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499911" comment="qemu-seabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499912" comment="qemu-sgabios-8-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704899" comment="qemu-tools-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499916" comment="qemu-vgabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499917" comment="qemu-x86-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009672628" comment="slirp4netns-0.4.7-3.15.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029361" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29361</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29361" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29361" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29361" ref_url="https://www.suse.com/security/cve/CVE-2020-29361" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009948.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010192.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010181.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1611-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CZHKPKPZEQIHCU2R54QWFT3X2C4JOWBT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:4154-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BWY3OJFF4O6KAVNTWISEXMD7X5Y2XL6I/" source="SUSE-SU"/>
    <description>
    An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-29361/">CVE-2020-29361</cve>
	<bugzilla href="https://bugzilla.suse.com/1180064">SUSE bug 1180064</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009659809" comment="libp11-kit0-0.23.2-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009659810" comment="p11-kit-0.23.2-4.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009659813" comment="p11-kit-tools-0.23.2-4.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029368" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29368</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29368" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29368" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29368" ref_url="https://www.suse.com/security/cve/CVE-2020-29368" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008297.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0377-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-February/017944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0818-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008500.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008509.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0840-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008502.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0864-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0868-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0869-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008507.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1046-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0393-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/R5J7TLH5AZYERG7B3PW3ALPYSBMFCGV5/" source="SUSE-SU"/>
    <description>
    An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-29368/">CVE-2020-29368</cve>
	<bugzilla href="https://bugzilla.suse.com/1179428">SUSE bug 1179428</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179660">SUSE bug 1179660</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179664">SUSE bug 1179664</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705005" comment="kernel-default-5.3.18-24.52.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705006" comment="kernel-default-base-5.3.18-24.52.1.9.24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029369" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29369</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29369" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29369" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29369" ref_url="https://www.suse.com/security/cve/CVE-2020-29369" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008076.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2161-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ICEKZTGIQ6MSKDFOTIOJ2RLWAWJFPSYA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    An issue was discovered in mm/mmap.c in the Linux kernel before 5.7.11. There is a race condition between certain expand functions (expand_downwards and expand_upwards) and page-table free operations from an munmap call, aka CID-246c320a8cfe.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-29369/">CVE-2020-29369</cve>
	<bugzilla href="https://bugzilla.suse.com/1173504">SUSE bug 1173504</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179432">SUSE bug 1179432</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179646">SUSE bug 1179646</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182109">SUSE bug 1182109</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029370" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29370</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29370" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29370" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29370" ref_url="https://www.suse.com/security/cve/CVE-2020-29370" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-29370/">CVE-2020-29370</cve>
	<bugzilla href="https://bugzilla.suse.com/1179435">SUSE bug 1179435</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179648">SUSE bug 1179648</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029371" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29371</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29371" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29371" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29371" ref_url="https://www.suse.com/security/cve/CVE-2020-29371" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2161-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ICEKZTGIQ6MSKDFOTIOJ2RLWAWJFPSYA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2193-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4YRSQJNKLIOJJTD3P2UKMHRFMCIG3JDN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory leaks to userspace, aka CID-bcf85fcedfdd.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-29371/">CVE-2020-29371</cve>
	<bugzilla href="https://bugzilla.suse.com/1179429">SUSE bug 1179429</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029372" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29372</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29372" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29372" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29372" ref_url="https://www.suse.com/security/cve/CVE-2020-29372" source="SUSE CVE"/>
    <description>
    An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="0/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-29372/">CVE-2020-29372</cve>
	<bugzilla href="https://bugzilla.suse.com/1179433">SUSE bug 1179433</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029373" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29373</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29373" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29373" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29373" ref_url="https://www.suse.com/security/cve/CVE-2020-29373" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008297.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0869-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008507.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during path lookups, and thus a process inside a mount namespace can escape to unintended filesystem locations, aka CID-ff002b30181d.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.7/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-29373/">CVE-2020-29373</cve>
	<bugzilla href="https://bugzilla.suse.com/1179434">SUSE bug 1179434</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179779">SUSE bug 1179779</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029374" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29374</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29374" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29374" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29374" ref_url="https://www.suse.com/security/cve/CVE-2020-29374" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0393-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/R5J7TLH5AZYERG7B3PW3ALPYSBMFCGV5/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-29374/">CVE-2020-29374</cve>
	<bugzilla href="https://bugzilla.suse.com/1179428">SUSE bug 1179428</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179660">SUSE bug 1179660</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705005" comment="kernel-default-5.3.18-24.52.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705006" comment="kernel-default-base-5.3.18-24.52.1.9.24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029443" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29443</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29443" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29443" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29443" ref_url="https://www.suse.com/security/cve/CVE-2020-29443" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
    <description>
    ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-06"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.9/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-29443/">CVE-2020-29443</cve>
	<bugzilla href="https://bugzilla.suse.com/1181108">SUSE bug 1181108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704859" comment="qemu-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499829" comment="qemu-arm-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499837" comment="qemu-ipxe-1.0.0+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499843" comment="qemu-seabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499844" comment="qemu-sgabios-8-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704860" comment="qemu-tools-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499848" comment="qemu-vgabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499849" comment="qemu-x86-4.2.1-11.16.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029480" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29480</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29480" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29480" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29480" ref_url="https://www.suse.com/security/cve/CVE-2020-29480" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3881-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3945-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008127.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2313-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ORUQM2NUGI7GTGQ4QQYAXYCCBGXOCR55/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2331-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KLZB3TTBVYNCRCZSSEYYBTXS7RCM6NL7/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored node, which will cause notifications for every created, modified, and deleted key. A guest administrator can also use the special watches, which will cause a notification every time a domain is created and destroyed. Data may include: number, type, and domids of other VMs; existence and domids of driver domains; numbers of virtual interfaces, block devices, vcpus; existence of virtual framebuffers and their backend style (e.g., existence of VNC service); Xen VM UUIDs for other domains; timing information about domain creation and device setup; and some hints at the backend provisioning of VMs and their devices. The watch events do not contain values stored in xenstore, only key names. A guest administrator can observe non-sensitive domain and device lifecycle events relating to other guests. This information allows some insight into overall system configuration (including the number and general nature of other guests), and configuration of other guests (including the number and general nature of other guests' devices). This information might be commercially interesting or might make other attacks easier. There is not believed to be exposure of sensitive data. Specifically, there is no exposure of VNC passwords, port numbers, pathnames in host and guest filesystems, cryptographic keys, or within-guest data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-29480/">CVE-2020-29480</cve>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179496">SUSE bug 1179496</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029481" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29481</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29481" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29481" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29481" ref_url="https://www.suse.com/security/cve/CVE-2020-29481" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3881-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3945-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008127.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2313-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ORUQM2NUGI7GTGQ4QQYAXYCCBGXOCR55/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2331-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KLZB3TTBVYNCRCZSSEYYBTXS7RCM6NL7/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because all Xenstore entries of a guest below /local/domain/&lt;domid&gt; are being deleted by Xen tools when a guest is destroyed, only Xenstore entries of other guests still running are affected. For example, a newly created guest domain might be able to read sensitive information that had belonged to a previously existing guest domain. Both Xenstore implementations (C and Ocaml) are vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-29481/">CVE-2020-29481</cve>
	<bugzilla href="https://bugzilla.suse.com/1176349">SUSE bug 1176349</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179498">SUSE bug 1179498</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029483" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29483</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29483" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29483" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29483" ref_url="https://www.suse.com/security/cve/CVE-2020-29483" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3881-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3945-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008127.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2313-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ORUQM2NUGI7GTGQ4QQYAXYCCBGXOCR55/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2331-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KLZB3TTBVYNCRCZSSEYYBTXS7RCM6NL7/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specific protocol. When a guest violates this protocol, xenstored will drop the connection to that guest. Unfortunately, this is done by just removing the guest from xenstored's internal management, resulting in the same actions as if the guest had been destroyed, including sending an @releaseDomain event. @releaseDomain events do not say that the guest has been removed. All watchers of this event must look at the states of all guests to find the guest that has been removed. When an @releaseDomain is generated due to a domain xenstored protocol violation, because the guest is still running, the watchers will not react. Later, when the guest is actually destroyed, xenstored will no longer have it stored in its internal data base, so no further @releaseDomain event will be sent. This can lead to a zombie domain; memory mappings of that guest's memory will not be removed, due to the missing event. This zombie domain will be cleaned up only after another domain is destroyed, as that will trigger another @releaseDomain event. If the device model of the guest that violated the Xenstore protocol is running in a stub-domain, a use-after-free case could happen in xenstored, after having removed the guest from its internal data base, possibly resulting in a crash of xenstored. A malicious guest can block resources of the host for a period after its own death. Guests with a stub domain device model can eventually crash xenstored, resulting in a more serious denial of service (the prevention of any further domain management operations). Only the C variant of Xenstore is affected; the Ocaml variant is not affected. Only HVM guests with a stubdom device model can cause a serious DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-29483/">CVE-2020-29483</cve>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179502">SUSE bug 1179502</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029484" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29484</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29484" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29484" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29484" ref_url="https://www.suse.com/security/cve/CVE-2020-29484" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3881-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3945-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008127.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2313-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ORUQM2NUGI7GTGQ4QQYAXYCCBGXOCR55/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2331-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KLZB3TTBVYNCRCZSSEYYBTXS7RCM6NL7/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that registered the watch will receive a Xenstore message containing the path of the modified Xenstore entry that triggered the watch, and the tag that was specified when registering the watch. Any communication with xenstored is done via Xenstore messages, consisting of a message header and the payload. The payload length is limited to 4096 bytes. Any request to xenstored resulting in a response with a payload longer than 4096 bytes will result in an error. When registering a watch, the payload length limit applies to the combined length of the watched path and the specified tag. Because watches for a specific path are also triggered for all nodes below that path, the payload of a watch event message can be longer than the payload needed to register the watch. A malicious guest that registers a watch using a very large tag (i.e., with a registration operation payload length close to the 4096 byte limit) can cause the generation of watch events with a payload length larger than 4096 bytes, by writing to Xenstore entries below the watched path. This will result in an error condition in xenstored. This error can result in a NULL pointer dereference, leading to a crash of xenstored. A malicious guest administrator can cause xenstored to crash, leading to a denial of service. Following a xenstored crash, domains may continue to run, but management operations will be impossible. Only C xenstored is affected, oxenstored is not affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-29484/">CVE-2020-29484</cve>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179501">SUSE bug 1179501</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029534" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29534</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29534" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29534" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29534" ref_url="https://www.suse.com/security/cve/CVE-2020-29534" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct of the process that submitted a request, causing execve() to incorrectly optimize unshare_fd(), aka CID-0f2122045b94.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-29534/">CVE-2020-29534</cve>
	<bugzilla href="https://bugzilla.suse.com/1179598">SUSE bug 1179598</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180564">SUSE bug 1180564</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029566" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29566</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29566" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29566" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29566" ref_url="https://www.suse.com/security/cve/CVE-2020-29566" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3881-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3945-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008127.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2313-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ORUQM2NUGI7GTGQ4QQYAXYCCBGXOCR55/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2331-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KLZB3TTBVYNCRCZSSEYYBTXS7RCM6NL7/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x86 HVM guests must be temporarily de-scheduled. The device model will signal Xen when it has completed its operation, via an event channel, so that the relevant vCPU is rescheduled. If the device model were to signal Xen without having actually completed the operation, the de-schedule / re-schedule cycle would repeat. If, in addition, Xen is resignalled very quickly, the re-schedule may occur before the de-schedule was fully complete, triggering a shortcut. This potentially repeating process uses ordinary recursive function calls, and thus could result in a stack overflow. A malicious or buggy stubdomain serving a HVM guest can cause Xen to crash, resulting in a Denial of Service (DoS) to the entire host. Only x86 systems are affected. Arm systems are not affected. Only x86 stubdomains serving HVM guests can exploit the vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-29566/">CVE-2020-29566</cve>
	<bugzilla href="https://bugzilla.suse.com/1178658">SUSE bug 1178658</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179506">SUSE bug 1179506</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029568" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29568</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29568" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29568" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29568" ref_url="https://www.suse.com/security/cve/CVE-2020-29568" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008354.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0241-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GZRN6BW22C4S3GVCJVPHDT4HHTLVGVZE/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any version) dom0 are vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-29568/">CVE-2020-29568</cve>
	<bugzilla href="https://bugzilla.suse.com/1179508">SUSE bug 1179508</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029569" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29569</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29569" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29569" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29569" ref_url="https://www.suse.com/security/cve/CVE-2020-29569" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008297.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0377-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-February/017944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008354.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0241-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GZRN6BW22C4S3GVCJVPHDT4HHTLVGVZE/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring-&gt;xenblkd to NULL when stopped. However, the handler may not have time to run if the frontend quickly toggles between the states connect and disconnect. As a consequence, the block backend may re-use a pointer after it was freed. A misbehaving guest can trigger a dom0 crash by continuously connecting / disconnecting a block frontend. Privilege escalation and information leaks cannot be ruled out. This only affects systems with a Linux blkback.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-29569/">CVE-2020-29569</cve>
	<bugzilla href="https://bugzilla.suse.com/1179509">SUSE bug 1179509</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180008">SUSE bug 1180008</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029570" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29570</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29570" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29570" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29570" ref_url="https://www.suse.com/security/cve/CVE-2020-29570" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3881-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3945-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008127.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2313-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ORUQM2NUGI7GTGQ4QQYAXYCCBGXOCR55/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2331-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KLZB3TTBVYNCRCZSSEYYBTXS7RCM6NL7/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the control block is reversed. The consumer assumes, seeing the former initialized, that the latter are also ready for use. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting the entire system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-29570/">CVE-2020-29570</cve>
	<bugzilla href="https://bugzilla.suse.com/1179514">SUSE bug 1179514</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029571" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29571</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29571" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29571" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29571" ref_url="https://www.suse.com/security/cve/CVE-2020-29571" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3881-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3945-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008127.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2313-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ORUQM2NUGI7GTGQ4QQYAXYCCBGXOCR55/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2331-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KLZB3TTBVYNCRCZSSEYYBTXS7RCM6NL7/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the CPU observing consistent state. While the producer side uses appropriately ordered writes, the consumer side isn't protected against re-ordered reads, and may hence end up de-referencing a NULL pointer. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting the entire system. Only Arm systems may be vulnerable. Whether a system is vulnerable depends on the specific CPU. x86 systems are not vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-29571/">CVE-2020-29571</cve>
	<bugzilla href="https://bugzilla.suse.com/1179516">SUSE bug 1179516</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760869" comment="xen-libs-4.13.2_06-3.22.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029651" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29651</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29651" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29651" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29651" ref_url="https://www.suse.com/security/cve/CVE-2020-29651" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:247-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:250-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:251-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2085-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2229-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3033-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:612-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1963-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011928.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0851-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J5N5MI5XRBM5X46XPGTD3CVA6C5MMBQJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1859-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/B5MZ7NDWQ2PACIOK5L2D7CNODUCJCARI/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-29651/">CVE-2020-29651</cve>
	<bugzilla href="https://bugzilla.suse.com/1179805">SUSE bug 1179805</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009494015" comment="python3-py-1.8.1-5.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029660" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29660</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29660" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29660" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29660" ref_url="https://www.suse.com/security/cve/CVE-2020-29660" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0377-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-February/017944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-29660/">CVE-2020-29660</cve>
	<bugzilla href="https://bugzilla.suse.com/1179745">SUSE bug 1179745</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179877">SUSE bug 1179877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202029661" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-29661</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-29661" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29661" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-29661" ref_url="https://www.suse.com/security/cve/CVE-2020-29661" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0377-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-February/017944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-09-12"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-29661/">CVE-2020-29661</cve>
	<bugzilla href="https://bugzilla.suse.com/1179745">SUSE bug 1179745</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179877">SUSE bug 1179877</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1214268">SUSE bug 1214268</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202035499" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-35499</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-35499" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35499" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-35499" ref_url="https://www.suse.com/security/cve/CVE-2020-35499" source="SUSE CVE"/>
    <description>
    A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when using BT_SNDMTU/BT_RCVMTU for SCO sockets. This could allow a local attacker with a special user privilege to crash the system (DOS) or leak kernel internal information.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-35499/">CVE-2020-35499</cve>
	<bugzilla href="https://bugzilla.suse.com/1180460">SUSE bug 1180460</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202035501" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-35501</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-35501" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35501" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-35501" ref_url="https://www.suse.com/security/cve/CVE-2020-35501" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-35501/">CVE-2020-35501</cve>
	<bugzilla href="https://bugzilla.suse.com/1182435">SUSE bug 1182435</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202035503" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-35503</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-35503" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35503" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-35503" ref_url="https://www.suse.com/security/cve/CVE-2020-35503" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2789-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019909.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009332.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3635-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009705.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2789-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UE3MLTPF62745SPUUDQR6ROYVP4GG6DT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2858-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GGOXRRBMGRJGBNXEGPCZ3JFLXCMIM6A3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3614-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/26KPX43RJBRTCX3JER7CN7MAT4QEGAED/" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasas_command_cancelled() callback function while dropping a SCSI request. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-35503/">CVE-2020-35503</cve>
	<bugzilla href="https://bugzilla.suse.com/1180432">SUSE bug 1180432</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704934" comment="qemu-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630345" comment="qemu-arm-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630353" comment="qemu-ipxe-1.0.0+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630359" comment="qemu-seabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630360" comment="qemu-sgabios-8-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704935" comment="qemu-tools-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630364" comment="qemu-vgabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630365" comment="qemu-x86-4.2.1-11.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202035504" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-35504</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-35504" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35504" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-35504" ref_url="https://www.suse.com/security/cve/CVE-2020-35504" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2789-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019909.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009332.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3635-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009705.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2789-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UE3MLTPF62745SPUUDQR6ROYVP4GG6DT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2858-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GGOXRRBMGRJGBNXEGPCZ3JFLXCMIM6A3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3614-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/26KPX43RJBRTCX3JER7CN7MAT4QEGAED/" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-35504/">CVE-2020-35504</cve>
	<bugzilla href="https://bugzilla.suse.com/1180433">SUSE bug 1180433</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704934" comment="qemu-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630345" comment="qemu-arm-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630353" comment="qemu-ipxe-1.0.0+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630359" comment="qemu-seabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630360" comment="qemu-sgabios-8-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704935" comment="qemu-tools-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630364" comment="qemu-vgabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630365" comment="qemu-x86-4.2.1-11.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202035505" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-35505</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-35505" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35505" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-35505" ref_url="https://www.suse.com/security/cve/CVE-2020-35505" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2789-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019909.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009332.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3635-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009705.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2789-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UE3MLTPF62745SPUUDQR6ROYVP4GG6DT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2858-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GGOXRRBMGRJGBNXEGPCZ3JFLXCMIM6A3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3614-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/26KPX43RJBRTCX3JER7CN7MAT4QEGAED/" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-35505/">CVE-2020-35505</cve>
	<bugzilla href="https://bugzilla.suse.com/1180434">SUSE bug 1180434</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704934" comment="qemu-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630345" comment="qemu-arm-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630353" comment="qemu-ipxe-1.0.0+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630359" comment="qemu-seabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630360" comment="qemu-sgabios-8-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704935" comment="qemu-tools-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630364" comment="qemu-vgabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630365" comment="qemu-x86-4.2.1-11.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202035506" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-35506</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-35506" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35506" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-35506" ref_url="https://www.suse.com/security/cve/CVE-2020-35506" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2789-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019909.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009332.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3635-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009705.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2789-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UE3MLTPF62745SPUUDQR6ROYVP4GG6DT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2858-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GGOXRRBMGRJGBNXEGPCZ3JFLXCMIM6A3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3614-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/26KPX43RJBRTCX3JER7CN7MAT4QEGAED/" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handling of the 'Information Transfer' command (CMD_TI). This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service or potential code execution with the privileges of the QEMU process.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-35506/">CVE-2020-35506</cve>
	<bugzilla href="https://bugzilla.suse.com/1180435">SUSE bug 1180435</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704934" comment="qemu-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630345" comment="qemu-arm-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630353" comment="qemu-ipxe-1.0.0+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630359" comment="qemu-seabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630360" comment="qemu-sgabios-8-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704935" comment="qemu-tools-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630364" comment="qemu-vgabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630365" comment="qemu-x86-4.2.1-11.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202035508" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-35508</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-35508" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35508" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-35508" ref_url="https://www.suse.com/security/cve/CVE-2020-35508" source="SUSE CVE"/>
    <description>
    A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-35508/">CVE-2020-35508</cve>
	<bugzilla href="https://bugzilla.suse.com/1180529">SUSE bug 1180529</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202035512" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-35512</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-35512" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35512" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-35512" ref_url="https://www.suse.com/security/cve/CVE-2020-35512" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009108.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2292-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009192.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2590-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009240.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011899.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SMJEHJSAVUMBFKW6O66TYUT5LCUVZD6Z/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2292-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YPWMH7OQGRFBQ2ZFL5Z3HCT443A45EIB/" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in D-Bus Development branch &lt;= 1.13.16, dbus-1.12.x stable branch &lt;= 1.12.18, and dbus-1.10.x and older branches &lt;= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-05"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-35512/">CVE-2020-35512</cve>
	<bugzilla href="https://bugzilla.suse.com/1187105">SUSE bug 1187105</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189662">SUSE bug 1189662</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205052">SUSE bug 1205052</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009615809" comment="dbus-1-1.12.2-8.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009615812" comment="libdbus-1-3-1.12.2-8.6.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202035513" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-35513</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-35513" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35513" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-35513" ref_url="https://www.suse.com/security/cve/CVE-2020-35513" source="SUSE CVE"/>
    <description>
    A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-35513/">CVE-2020-35513</cve>
	<bugzilla href="https://bugzilla.suse.com/1181362">SUSE bug 1181362</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202035519" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-35519</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-35519" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35519" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-35519" ref_url="https://www.suse.com/security/cve/CVE-2020-35519" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-19"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-35519/">CVE-2020-35519</cve>
	<bugzilla href="https://bugzilla.suse.com/1183696">SUSE bug 1183696</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1184953">SUSE bug 1184953</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1211495">SUSE bug 1211495</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202035662" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-35662</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-35662" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35662" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-35662" ref_url="https://www.suse.com/security/cve/CVE-2020-35662" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14679-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1690-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008813.html" source="SUSE-SU"/>
		<reference ref_id="TID000019887" ref_url="https://www.suse.com/support/kb/doc/?id=000019887" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0347-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CYH7ONK65HNBANHLED5R64OBSM2EORYI/" source="SUSE-SU"/>
    <description>
    In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="9.4/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" href="https://www.suse.com/security/cve/CVE-2020-35662/">CVE-2020-35662</cve>
	<bugzilla href="https://bugzilla.suse.com/1181550">SUSE bug 1181550</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181565">SUSE bug 1181565</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202036158" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-36158</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-36158" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36158" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-36158" ref_url="https://www.suse.com/security/cve/CVE-2020-36158" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0377-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-February/017944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0060-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IGMHKFBCILMH7EZ36H75HXZ2RO2WG2GR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-36158/">CVE-2020-36158</cve>
	<bugzilla href="https://bugzilla.suse.com/1180559">SUSE bug 1180559</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180562">SUSE bug 1180562</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202036310" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-36310</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-36310" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36310" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-36310" ref_url="https://www.suse.com/security/cve/CVE-2020-36310" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1572-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/018906.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008769.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page faults, aka CID-e72436bc3a52.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-36310/">CVE-2020-36310</cve>
	<bugzilla href="https://bugzilla.suse.com/1184512">SUSE bug 1184512</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202036311" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-36311</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-36311" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36311" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-36311" ref_url="https://www.suse.com/security/cve/CVE-2020-36311" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1248-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires unregistering many encrypted regions), aka CID-7be74942f184.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-36311/">CVE-2020-36311</cve>
	<bugzilla href="https://bugzilla.suse.com/1184511">SUSE bug 1184511</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202036312" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-36312</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-36312" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36312" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-36312" ref_url="https://www.suse.com/security/cve/CVE-2020-36312" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1572-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/018906.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008769.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory leak upon a kmalloc failure, aka CID-f65886606c2d.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-36312/">CVE-2020-36312</cve>
	<bugzilla href="https://bugzilla.suse.com/1184509">SUSE bug 1184509</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202036313" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-36313</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-36313" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36313" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-36313" ref_url="https://www.suse.com/security/cve/CVE-2020-36313" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a deletion, aka CID-0774a964ef56. This affects arch/s390/kvm/kvm-s390.c, include/linux/kvm_host.h, and virt/kvm/kvm_main.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-36313/">CVE-2020-36313</cve>
	<bugzilla href="https://bugzilla.suse.com/1184504">SUSE bug 1184504</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202036322" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-36322</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-36322" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36322" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-36322" ref_url="https://www.suse.com/security/cve/CVE-2020-36322" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1572-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/018906.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008769.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008815.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1724-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008814.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008816.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1865-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008939.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1870-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. fuse_do_getattr() calls make_bad_inode() in inappropriate situations, causing a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-10-11"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.7/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-36322/">CVE-2020-36322</cve>
	<bugzilla href="https://bugzilla.suse.com/1184211">SUSE bug 1184211</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1184952">SUSE bug 1184952</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189302">SUSE bug 1189302</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202036385" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-36385</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-36385" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36385" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-36385" ref_url="https://www.suse.com/security/cve/CVE-2020-36385" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009226.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009239.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009279.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2184-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GJZ4RMNGAPDHTNV6KJGNPSEJH2RUZFKU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/T4PWFRJWECGAGZTBIOYHZ6KUMSA6KC43/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-10-11"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-36385/">CVE-2020-36385</cve>
	<bugzilla href="https://bugzilla.suse.com/1187050">SUSE bug 1187050</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1187052">SUSE bug 1187052</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189302">SUSE bug 1189302</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196174">SUSE bug 1196174</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196810">SUSE bug 1196810</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196914">SUSE bug 1196914</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200084">SUSE bug 1200084</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201734">SUSE bug 1201734</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704907" comment="kernel-default-5.3.18-24.70.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704908" comment="kernel-default-base-5.3.18-24.70.1.9.32.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202036386" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-36386</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-36386" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36386" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-36386" ref_url="https://www.suse.com/security/cve/CVE-2020-36386" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009279.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2644-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009280.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2184-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GJZ4RMNGAPDHTNV6KJGNPSEJH2RUZFKU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/T4PWFRJWECGAGZTBIOYHZ6KUMSA6KC43/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-36386/">CVE-2020-36386</cve>
	<bugzilla href="https://bugzilla.suse.com/1187038">SUSE bug 1187038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192868">SUSE bug 1192868</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704907" comment="kernel-default-5.3.18-24.70.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704908" comment="kernel-default-base-5.3.18-24.70.1.9.32.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624613" comment="kernel-rt-4.12.14-10.49.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202036387" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-36387</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-36387" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36387" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-36387" ref_url="https://www.suse.com/security/cve/CVE-2020-36387" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_func and ctx reference holding, aka CID-6d816e088c35.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-36387/">CVE-2020-36387</cve>
	<bugzilla href="https://bugzilla.suse.com/1187053">SUSE bug 1187053</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202036694" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-36694</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-36694" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36694" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-36694" ref_url="https://www.suse.com/security/cve/CVE-2020-36694" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2023:2502-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2611-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2651-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030079.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet processing context, because the per-CPU sequence count is mishandled during concurrent iptables rules replacement. This could be exploited with the CAP_NET_ADMIN capability in an unprivileged namespace. NOTE: cc00bca was reverted in 5.12.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-36694/">CVE-2020-36694</cve>
	<bugzilla href="https://bugzilla.suse.com/1211596">SUSE bug 1211596</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20203702" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-3702</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-3702" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3702" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-3702" ref_url="https://www.suse.com/security/cve/CVE-2020-3702" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3337-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3389-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-October/020461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3447-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010158.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0292-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0295-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0298-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0327-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010184.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1357-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SS5B6JL55TTUNHHOGTFHK5JQ6EZOF7ZV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1365-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JSK2K2OLYKIFCAMBX4QB7AGV6SKS3BTM/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3338-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H64LCXMISTZ7YB7R4ABO2Y73X23DJFXU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3387-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MHXVHXC6JGHDS7W6EJQF3JKAPVYH3ES5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3447-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IAN74FTXJ7PFHCBV6YMLTPNW7VFYCPFV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &amp; Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, IPQ4019, IPQ8064, MSM8909W, MSM8996AU, QCA9531, QCN5502, QCS405, SDX20, SM6150, SM7150
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-3702/">CVE-2020-3702</cve>
	<bugzilla href="https://bugzilla.suse.com/1191193">SUSE bug 1191193</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191529">SUSE bug 1191529</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704954" comment="kernel-default-5.3.18-24.86.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704955" comment="kernel-default-base-5.3.18-24.86.2.9.40.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651689" comment="kernel-rt-5.3.18-54.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704956" comment="kmod-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704957" comment="kmod-compat-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704958" comment="libkmod2-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704959" comment="perl-Bootloader-0.931-3.5.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20204788" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-4788</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-4788" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-4788" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-4788" ref_url="https://www.suse.com/security/cve/CVE-2020-4788" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0097-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2161-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ICEKZTGIQ6MSKDFOTIOJ2RLWAWJFPSYA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2193-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4YRSQJNKLIOJJTD3P2UKMHRFMCIG3JDN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2260-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZYES3O2NEKKQXQ3R5CZOH5YCWJ3TJSKH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H7EJISS2OPKUSJFJ2BG5ZWHA2Z6H3VQB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-4788/">CVE-2020-4788</cve>
	<bugzilla href="https://bugzilla.suse.com/1177666">SUSE bug 1177666</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181158">SUSE bug 1181158</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20206750" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-6750</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-6750" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6750" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-6750" ref_url="https://www.suse.com/security/cve/CVE-2020-6750" source="SUSE CVE"/>
    <description>
    GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-6750/">CVE-2020-6750</cve>
	<bugzilla href="https://bugzilla.suse.com/1160668">SUSE bug 1160668</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760781" comment="glib2-tools-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760782" comment="libgio-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760783" comment="libglib-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760784" comment="libgmodule-2_0-0-2.62.6-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760785" comment="libgobject-2_0-0-2.62.6-3.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20206829" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-6829</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-6829" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6829" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-6829" ref_url="https://www.suse.com/security/cve/CVE-2020-6829" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
    <description>
    When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox &lt; 80 and Firefox for Android &lt; 80.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-6829/">CVE-2020-6829</cve>
	<bugzilla href="https://bugzilla.suse.com/1174763">SUSE bug 1174763</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1175686">SUSE bug 1175686</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009632956" comment="libfreebl3-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632960" comment="libsoftokn3-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632964" comment="mozilla-nspr-4.32-3.20.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632967" comment="mozilla-nss-3.68-3.56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632969" comment="mozilla-nss-certs-3.68-3.56.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20207039" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-7039</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-7039" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7039" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-7039" ref_url="https://www.suse.com/security/cve/CVE-2020-7039" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:0844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006662.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006664.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006934.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006868.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1523-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006874.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.html" source="SUSE-SU"/>
    <description>
    tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-7039/">CVE-2020-7039</cve>
	<bugzilla href="https://bugzilla.suse.com/1161066">SUSE bug 1161066</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20207216" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-7216</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-7216" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7216" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-7216" ref_url="https://www.suse.com/security/cve/CVE-2020-7216" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-January/006416.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0369-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0410-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006499.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0165-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00005.html" source="SUSE-SU"/>
    <description>
    An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-7216/">CVE-2020-7216</cve>
	<bugzilla href="https://bugzilla.suse.com/1160905">SUSE bug 1160905</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760866" comment="wicked-0.6.64-3.3.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760867" comment="wicked-service-0.6.64-3.3.4 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20207217" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-7217</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-7217" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7217" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-7217" ref_url="https://www.suse.com/security/cve/CVE-2020-7217" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0369-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0410-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006499.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0207-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-02/msg00011.html" source="SUSE-SU"/>
    <description>
    An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets with a different client-id.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-7217/">CVE-2020-7217</cve>
	<bugzilla href="https://bugzilla.suse.com/1160906">SUSE bug 1160906</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760866" comment="wicked-0.6.64-3.3.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760867" comment="wicked-service-0.6.64-3.3.4 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20207595" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-7595</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-7595" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7595" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-7595" ref_url="https://www.suse.com/security/cve/CVE-2020-7595" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007413.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007415.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1299-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007409.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008797.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0681-1" ref_url="https://lists.opensuse.org/opensuse-updates/2020-05/msg00124.html" source="SUSE-SU"/>
    <description>
    xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-7595/">CVE-2020-7595</cve>
	<bugzilla href="https://bugzilla.suse.com/1161517">SUSE bug 1161517</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191860">SUSE bug 1191860</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009628925" comment="libxml2-2-2.9.7-3.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628928" comment="libxml2-tools-2.9.7-3.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20207919" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-7919</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-7919" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7919" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-7919" ref_url="https://www.suse.com/security/cve/CVE-2020-7919" source="SUSE CVE"/>
    <description>
    Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-7919/">CVE-2020-7919</cve>
	<bugzilla href="https://bugzilla.suse.com/1164288">SUSE bug 1164288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334435" comment="docker is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208013" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8013</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8013" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8013" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8013" ref_url="https://www.suse.com/security/cve/CVE-2020-8013" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:121-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:122-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:129-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:165-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006559.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006560.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:81-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-March/014050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:82-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-March/014051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006772.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14304-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006558.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009118.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0302-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1520-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CDE67H3SKCA2N6SED6KU5T3MBX3UVI6N/" source="SUSE-SU"/>
    <description>
    A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers on default systems, so exploitation is difficult. This issue affects: SUSE Linux Enterprise Server 12 permissions versions prior to 2015.09.28.1626-17.27.1. SUSE Linux Enterprise Server 15 permissions versions prior to 20181116-9.23.1. SUSE Linux Enterprise Server 11 permissions versions prior to 2013.1.7-0.6.12.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2020-8013/">CVE-2020-8013</cve>
	<bugzilla href="https://bugzilla.suse.com/1163922">SUSE bug 1163922</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628975" comment="permissions-20181224-23.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208023" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8023</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8023" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8023" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8023" ref_url="https://www.suse.com/security/cve/CVE-2020-8023" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:361-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:363-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14419-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1855-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1856-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007077.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0956-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00019.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0976-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00029.html" source="SUSE-SU"/>
    <description>
    A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 12-SP2, SUSE Linux Enterprise Server for SAP 12-SP3, SUSE Linux Enterprise Server for SAP 15, SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud Crowbar 8; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to escalate privileges from user ldap to root. This issue affects: SUSE Enterprise Storage 5 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Debuginfo 11-SP3 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Debuginfo 11-SP4 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Point of Sale 11-SP3 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Server 11-SECURITY openldap2-client-openssl1 versions prior to 2.4.26-0.74.13.1. SUSE Linux Enterprise Server 11-SP4-LTSS openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Server 12-SP2-BCL openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP2-LTSS openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP3-BCL openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP3-LTSS openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP4 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP5 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.31.1. SUSE Linux Enterprise Server for SAP 12-SP2 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server for SAP 12-SP3 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server for SAP 15 openldap2 versions prior to 2.4.46-9.31.1. SUSE OpenStack Cloud 7 openldap2 versions prior to 2.4.41-18.71.2. SUSE OpenStack Cloud 8 openldap2 versions prior to 2.4.41-18.71.2. SUSE OpenStack Cloud Crowbar 8 openldap2 versions prior to 2.4.41-18.71.2. openSUSE Leap 15.1 openldap2 versions prior to 2.4.46-lp151.10.12.1. openSUSE Leap 15.2 openldap2 versions prior to 2.4.46-lp152.14.3.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-8023/">CVE-2020-8023</cve>
	<bugzilla href="https://bugzilla.suse.com/1172698">SUSE bug 1172698</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190347">SUSE bug 1190347</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208025" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8025</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8025" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8025" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8025" ref_url="https://www.suse.com/security/cve/CVE-2020-8025" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008243.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:45-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008277.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:50-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:51-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008286.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008241.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1873-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011172.html" source="SUSE-SU"/>
    <description>
    A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to unintended settings. This issue affects: SUSE Linux Enterprise Server 12-SP4 permissions versions prior to 20170707-3.24.1. SUSE Linux Enterprise Server 15-LTSS permissions versions prior to 20180125-3.27.1. SUSE Linux Enterprise Server for SAP 15 permissions versions prior to 20180125-3.27.1. openSUSE Leap 15.1 permissions versions prior to 20181116-lp151.4.24.1. openSUSE Tumbleweed permissions versions prior to 20200624.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-8025/">CVE-2020-8025</cve>
	<bugzilla href="https://bugzilla.suse.com/1171883">SUSE bug 1171883</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628975" comment="permissions-20181224-23.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208027" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8027</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8027" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8027" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8027" ref_url="https://www.suse.com/security/cve/CVE-2020-8027" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:500-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007526.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007569.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2712-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007612.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1534-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00092.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1539-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00094.html" source="SUSE-SU"/>
    <description>
    A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.37.1. SUSE Linux Enterprise Server for SAP 15 openldap2 versions prior to 2.4.46-9.37.1. openSUSE Leap 15.1 openldap2 versions prior to 2.4.46-lp151.10.18.1. openSUSE Leap 15.2 openldap2 versions prior to 2.4.46-lp152.14.9.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-8027/">CVE-2020-8027</cve>
	<bugzilla href="https://bugzilla.suse.com/1175568">SUSE bug 1175568</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760815" comment="libldap-2_4-2-2.4.46-9.45.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760816" comment="libldap-data-2.4.46-9.45.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208130" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8130</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8130" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8130" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8130" ref_url="https://www.suse.com/security/cve/CVE-2020-8130" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012195.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0395-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html" source="SUSE-SU"/>
    <description>
    There is an OS command injection vulnerability in Ruby Rake &lt; 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2020-8130/">CVE-2020-8130</cve>
	<bugzilla href="https://bugzilla.suse.com/1164804">SUSE bug 1164804</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009482387" comment="libruby2_5-2_5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482388" comment="ruby2.5-2.5.8-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009482391" comment="ruby2.5-stdlib-2.5.8-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208169" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8169</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8169" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8169" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8169" ref_url="https://www.suse.com/security/cve/CVE-2020-8169" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007021.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0883-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00058.html" source="SUSE-SU"/>
    <description>
    curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-8169/">CVE-2020-8169</cve>
	<bugzilla href="https://bugzilla.suse.com/1173026">SUSE bug 1173026</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186108">SUSE bug 1186108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208177" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8177</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8177" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8177" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8177" ref_url="https://www.suse.com/security/cve/CVE-2020-8177" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007064.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-July/007065.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:389-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:661-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14409-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/007041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0883-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00058.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0908-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-06/msg00072.html" source="SUSE-SU"/>
    <description>
    curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-8177/">CVE-2020-8177</cve>
	<bugzilla href="https://bugzilla.suse.com/1173027">SUSE bug 1173027</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186108">SUSE bug 1186108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208231" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8231</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8231" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8231" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8231" ref_url="https://www.suse.com/security/cve/CVE-2020-8231" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007396.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:530-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007569.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:662-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:665-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008881.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14481-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007328.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2445-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2446-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-September/007327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008879.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1345-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00011.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1359-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00015.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1494-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00069.html" source="SUSE-SU"/>
    <description>
    Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-8231/">CVE-2020-8231</cve>
	<bugzilla href="https://bugzilla.suse.com/1175109">SUSE bug 1175109</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179399">SUSE bug 1179399</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186108">SUSE bug 1186108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208284" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8284</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8284" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8284" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8284" ref_url="https://www.suse.com/security/cve/CVE-2020-8284" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:815-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:20-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008164.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008881.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3739-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008879.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2238-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PRXMLUV5IZ4L22JUMUBU3FUW7BWHV7J7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2249-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7TJUGEIZONXKJD6DWVYASM2KTYWZ6RI/" source="SUSE-SU"/>
    <description>
    A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-8284/">CVE-2020-8284</cve>
	<bugzilla href="https://bugzilla.suse.com/1179398">SUSE bug 1179398</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179399">SUSE bug 1179399</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186108">SUSE bug 1186108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208285" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8285</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8285" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8285" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8285" ref_url="https://www.suse.com/security/cve/CVE-2020-8285" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:815-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:20-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008164.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008881.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3739-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008879.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2238-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PRXMLUV5IZ4L22JUMUBU3FUW7BWHV7J7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2249-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7TJUGEIZONXKJD6DWVYASM2KTYWZ6RI/" source="SUSE-SU"/>
    <description>
    curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-8285/">CVE-2020-8285</cve>
	<bugzilla href="https://bugzilla.suse.com/1179399">SUSE bug 1179399</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186108">SUSE bug 1186108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208286" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8286</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8286" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8286" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8286" ref_url="https://www.suse.com/security/cve/CVE-2020-8286" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:781-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:782-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:787-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:790-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:797-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008002.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:798-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:799-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008009.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008010.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:810-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008016.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:815-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008020.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:816-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008022.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008023.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:818-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008025.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008026.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008027.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:824-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008034.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008037.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:850-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:10-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:11-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:12-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:20-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008164.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008881.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3739-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008879.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2238-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PRXMLUV5IZ4L22JUMUBU3FUW7BWHV7J7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2249-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7TJUGEIZONXKJD6DWVYASM2KTYWZ6RI/" source="SUSE-SU"/>
    <description>
    curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-8286/">CVE-2020-8286</cve>
	<bugzilla href="https://bugzilla.suse.com/1179593">SUSE bug 1179593</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186108">SUSE bug 1186108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760774" comment="curl-7.66.0-4.11.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760775" comment="libcurl4-7.66.0-4.11.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208315" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8315</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8315" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8315" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8315" ref_url="https://www.suse.com/security/cve/CVE-2020-8315" source="SUSE CVE"/>
    <description>
    In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's copy. Windows 8 and later are unaffected.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2020-8315/">CVE-2020-8315</cve>
	<bugzilla href="https://bugzilla.suse.com/1173935">SUSE bug 1173935</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334187" comment="python3 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208428" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8428</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8428" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8428" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8428" ref_url="https://www.suse.com/security/cve/CVE-2020-8428" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0667-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an open system call for a UNIX domain socket, if the socket is being moved to a new parent directory and its old parent directory is being removed.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-8428/">CVE-2020-8428</cve>
	<bugzilla href="https://bugzilla.suse.com/1162109">SUSE bug 1162109</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208492" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8492</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8492" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8492" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8492" ref_url="https://www.suse.com/security/cve/CVE-2020-8492" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2020:110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-October/007571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2020:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:13-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:17-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:18-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:19-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3228-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013165.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3259-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013170.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013231.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3378-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:500-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1144-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1145-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013286.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0467-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0854-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006666.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14306-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006878.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3865-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008081.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013149.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0274-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2332-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S3JTHM6LLDKL7VPNRJUSRPNZAD2FZ25H/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2333-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FLGERALYYFTBIX3ZKPM6EQ2WJVUXLOXY/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-8492/">CVE-2020-8492</cve>
	<bugzilla href="https://bugzilla.suse.com/1162367">SUSE bug 1162367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208608" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8608</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8608" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8608" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8608" ref_url="https://www.suse.com/security/cve/CVE-2020-8608" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006662.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006664.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006934.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006868.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1523-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006874.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2171-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007243.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:2234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-August/007264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008910.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1895-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008990.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0468-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-04/msg00007.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
    <description>
    In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2020-8608/">CVE-2020-8608</cve>
	<bugzilla href="https://bugzilla.suse.com/1163018">SUSE bug 1163018</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1163019">SUSE bug 1163019</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704898" comment="qemu-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499897" comment="qemu-arm-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499905" comment="qemu-ipxe-1.0.0+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499911" comment="qemu-seabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499912" comment="qemu-sgabios-8-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704899" comment="qemu-tools-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499916" comment="qemu-vgabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499917" comment="qemu-x86-4.2.1-11.19.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208647" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8647</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8647" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8647" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8647" ref_url="https://www.suse.com/security/cve/CVE-2020-8647" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1085-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006727.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0388-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.html" source="SUSE-SU"/>
    <description>
    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-8647/">CVE-2020-8647</cve>
	<bugzilla href="https://bugzilla.suse.com/1162929">SUSE bug 1162929</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1164078">SUSE bug 1164078</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208648" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8648</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8648" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8648" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8648" ref_url="https://www.suse.com/security/cve/CVE-2020-8648" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0667-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0688-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006612.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-8648/">CVE-2020-8648</cve>
	<bugzilla href="https://bugzilla.suse.com/1162928">SUSE bug 1162928</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208649" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8649</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8649" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8649" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8649" ref_url="https://www.suse.com/security/cve/CVE-2020-8649" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1085-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006727.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0388-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.html" source="SUSE-SU"/>
    <description>
    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-8649/">CVE-2020-8649</cve>
	<bugzilla href="https://bugzilla.suse.com/1162929">SUSE bug 1162929</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1162931">SUSE bug 1162931</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208694" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8694</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8694" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8694" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8694" ref_url="https://www.suse.com/security/cve/CVE-2020-8694" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:112-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3484-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3651-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3670-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007938.html" source="SUSE-SU"/>
		<reference ref_id="TID000019778" ref_url="https://www.suse.com/support/kb/doc/?id=000019778" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1906-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7MTGDUP74HR4XORTRYN7I7MANTKWCGQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2112-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4EZ6GLHJ7GRNO5SFTV2VI7JJOEEIMD6U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0242-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XOAUJM2XDOB5Y2JL726SBZNXGQBPQC75/" source="SUSE-SU"/>
    <description>
    Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-8694/">CVE-2020-8694</cve>
	<bugzilla href="https://bugzilla.suse.com/1170415">SUSE bug 1170415</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1170446">SUSE bug 1170446</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178591">SUSE bug 1178591</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178700">SUSE bug 1178700</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1179661">SUSE bug 1179661</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208695" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8695</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8695" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8695" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8695" ref_url="https://www.suse.com/security/cve/CVE-2020-8695" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:14540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3271-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-November/016830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007744.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007796.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3457-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/007937.html" source="SUSE-SU"/>
		<reference ref_id="TID000019778" ref_url="https://www.suse.com/support/kb/doc/?id=000019778" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1915-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDFLVEOG7TX6Q4WKP6Q53CLGQ3KKC2GT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L4M7N2LSLXLVXOCOXVRUDWN2YU7CBOGZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JAVL7PXBHMY5MEXAKSQM6PTNW6CHJJC2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2098-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TF4HQIBGSJ2IFTYIDCJW5IFFEG62DCU5/" source="SUSE-SU"/>
    <description>
    Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-8695/">CVE-2020-8695</cve>
	<bugzilla href="https://bugzilla.suse.com/1170415">SUSE bug 1170415</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1170446">SUSE bug 1170446</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1178591">SUSE bug 1178591</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208696" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8696</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8696" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8696" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8696" ref_url="https://www.suse.com/security/cve/CVE-2020-8696" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:14546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007796.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3457-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007857.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JAVL7PXBHMY5MEXAKSQM6PTNW6CHJJC2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2098-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TF4HQIBGSJ2IFTYIDCJW5IFFEG62DCU5/" source="SUSE-SU"/>
    <description>
    Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-8696/">CVE-2020-8696</cve>
	<bugzilla href="https://bugzilla.suse.com/1173592">SUSE bug 1173592</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208698" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8698</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8698" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8698" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8698" ref_url="https://www.suse.com/security/cve/CVE-2020-8698" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2020:14540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3271-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2020-November/016830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007744.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007796.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3457-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:3514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-November/007857.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1915-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDFLVEOG7TX6Q4WKP6Q53CLGQ3KKC2GT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:1923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L4M7N2LSLXLVXOCOXVRUDWN2YU7CBOGZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2075-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JAVL7PXBHMY5MEXAKSQM6PTNW6CHJJC2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:2098-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TF4HQIBGSJ2IFTYIDCJW5IFFEG62DCU5/" source="SUSE-SU"/>
    <description>
    Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-06-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-8698/">CVE-2020-8698</cve>
	<bugzilla href="https://bugzilla.suse.com/1173594">SUSE bug 1173594</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009629040" comment="ucode-intel-20210216-2.19.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208832" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8832</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8832" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8832" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8832" ref_url="https://www.suse.com/security/cve/CVE-2020-8832" source="SUSE CVE"/>
    <description>
    The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-8832/">CVE-2020-8832</cve>
	<bugzilla href="https://bugzilla.suse.com/1165881">SUSE bug 1165881</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208835" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8835</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8835" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8835" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8835" ref_url="https://www.suse.com/security/cve/CVE-2020-8835" source="SUSE CVE"/>
    <description>
    In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2020-8835/">CVE-2020-8835</cve>
	<bugzilla href="https://bugzilla.suse.com/1167722">SUSE bug 1167722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1173755">SUSE bug 1173755</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20208992" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-8992</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-8992" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8992" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-8992" ref_url="https://www.suse.com/security/cve/CVE-2020-8992" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-February/006546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0558-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0667-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0688-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006612.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0336-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html" source="SUSE-SU"/>
    <description>
    ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.1/CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-8992/">CVE-2020-8992</cve>
	<bugzilla href="https://bugzilla.suse.com/1164069">SUSE bug 1164069</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20209327" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-9327</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-9327" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9327" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-9327" ref_url="https://www.suse.com/security/cve/CVE-2020-9327" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009509.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1058-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6Z44NRR3L5O3VXGRWAB7XUKDS4TMFZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2320-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JD4EZ74IZ57MKTDKDVIUAIG6VCAEKMD5/" source="SUSE-SU"/>
    <description>
    In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2020-9327/">CVE-2020-9327</cve>
	<bugzilla href="https://bugzilla.suse.com/1164719">SUSE bug 1164719</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624167" comment="libsqlite3-0-3.36.0-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20209383" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-9383</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-9383" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9383" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-9383" ref_url="https://www.suse.com/security/cve/CVE-2020-9383" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2020:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-December/008059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:0836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-March/006656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1085-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006727.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1119-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-May/006817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:14354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-April/006770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2020:1663-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2020-June/006971.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2020:0388-1" ref_url="https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2020-9383/">CVE-2020-9383</cve>
	<bugzilla href="https://bugzilla.suse.com/1165111">SUSE bug 1165111</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760800" comment="kernel-rt-5.3.18-8.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20209391" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2020-9391</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2020-9391" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9391" source="CVE"/>
    <reference ref_id="SUSE CVE-2020-9391" ref_url="https://www.suse.com/security/cve/CVE-2020-9391" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2020-9391/">CVE-2020-9391</cve>
	<bugzilla href="https://bugzilla.suse.com/1165015">SUSE bug 1165015</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210066" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0066</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0066" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0066" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0066" ref_url="https://www.suse.com/security/cve/CVE-2021-0066" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0066/">CVE-2021-0066</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210072" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0072</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0072" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0072" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0072" ref_url="https://www.suse.com/security/cve/CVE-2021-0072" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-0072/">CVE-2021-0072</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210076" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0076</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0076" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0076" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0076" ref_url="https://www.suse.com/security/cve/CVE-2021-0076" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-0076/">CVE-2021-0076</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210089" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0089</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0089" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0089" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0089" ref_url="https://www.suse.com/security/cve/CVE-2021-0089" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYJVCSKTOQY75TLGWH3HDYZAS33JTOTQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JLC632KAG76ZVELO6CCNNSZVUXPDVXOQ/" source="SUSE-SU"/>
    <description>
    Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-0089/">CVE-2021-0089</cve>
	<bugzilla href="https://bugzilla.suse.com/1186433">SUSE bug 1186433</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632243" comment="xen-libs-4.13.3_02-3.34.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210127" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0127</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0127" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0127" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0127" ref_url="https://www.suse.com/security/cve/CVE-2021-0127" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010310.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0576-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010309.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0574-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7QEMHXA4R2RUIQPQL2RSCQ7TBADKDOH/" source="SUSE-SU"/>
    <description>
    Insufficient control flow management in some Intel(R) Processors may allow an authenticated user to potentially enable a denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-0127/">CVE-2021-0127</cve>
	<bugzilla href="https://bugzilla.suse.com/1195779">SUSE bug 1195779</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667863" comment="ucode-intel-20220207-10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210129" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0129</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0129" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0129" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0129" ref_url="https://www.suse.com/security/cve/CVE-2021-0129" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009123.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3691-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012602.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2184-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GJZ4RMNGAPDHTNV6KJGNPSEJH2RUZFKU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/T4PWFRJWECGAGZTBIOYHZ6KUMSA6KC43/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2291-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FGEHNTYN7DOZBN7IPNNCVSIU2JNPC226/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
    <description>
    Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-0129/">CVE-2021-0129</cve>
	<bugzilla href="https://bugzilla.suse.com/1186463">SUSE bug 1186463</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704907" comment="kernel-default-5.3.18-24.70.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704908" comment="kernel-default-base-5.3.18-24.70.1.9.32.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624613" comment="kernel-rt-4.12.14-10.49.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210145" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0145</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0145" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0145" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0145" ref_url="https://www.suse.com/security/cve/CVE-2021-0145" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010310.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0576-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010309.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0574-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7QEMHXA4R2RUIQPQL2RSCQ7TBADKDOH/" source="SUSE-SU"/>
    <description>
    Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-0145/">CVE-2021-0145</cve>
	<bugzilla href="https://bugzilla.suse.com/1195780">SUSE bug 1195780</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667863" comment="ucode-intel-20220207-10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210146" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0146</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0146" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0146" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0146" ref_url="https://www.suse.com/security/cve/CVE-2021-0146" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010310.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0576-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010309.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0574-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7QEMHXA4R2RUIQPQL2RSCQ7TBADKDOH/" source="SUSE-SU"/>
    <description>
    Hardware allows activation of test or debug logic at runtime for some Intel(R) processors which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-05"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0146/">CVE-2021-0146</cve>
	<bugzilla href="https://bugzilla.suse.com/1192615">SUSE bug 1192615</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193500">SUSE bug 1193500</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200661">SUSE bug 1200661</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200663">SUSE bug 1200663</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205062">SUSE bug 1205062</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667863" comment="ucode-intel-20220207-10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210157" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0157</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0157" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0157" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0157" ref_url="https://www.suse.com/security/cve/CVE-2021-0157" source="SUSE CVE"/>
    <description>
    Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0157/">CVE-2021-0157</cve>
	<bugzilla href="https://bugzilla.suse.com/1192791">SUSE bug 1192791</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338728" comment="ucode-intel is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210158" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0158</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0158" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0158" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0158" ref_url="https://www.suse.com/security/cve/CVE-2021-0158" source="SUSE CVE"/>
    <description>
    Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0158/">CVE-2021-0158</cve>
	<bugzilla href="https://bugzilla.suse.com/1192793">SUSE bug 1192793</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338728" comment="ucode-intel is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210161" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0161</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0161" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0161" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0161" ref_url="https://www.suse.com/security/cve/CVE-2021-0161" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0161/">CVE-2021-0161</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210164" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0164</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0164" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0164" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0164" ref_url="https://www.suse.com/security/cve/CVE-2021-0164" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper access control in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0164/">CVE-2021-0164</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210165" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0165</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0165" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0165" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0165" ref_url="https://www.suse.com/security/cve/CVE-2021-0165" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-0165/">CVE-2021-0165</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210166" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0166</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0166" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0166" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0166" ref_url="https://www.suse.com/security/cve/CVE-2021-0166" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0166/">CVE-2021-0166</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210168" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0168</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0168" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0168" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0168" ref_url="https://www.suse.com/security/cve/CVE-2021-0168" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0168/">CVE-2021-0168</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210170" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0170</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0170" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0170" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0170" ref_url="https://www.suse.com/security/cve/CVE-2021-0170" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow an authenticated user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-0170/">CVE-2021-0170</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210172" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0172</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0172" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0172" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0172" ref_url="https://www.suse.com/security/cve/CVE-2021-0172" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-0172/">CVE-2021-0172</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210173" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0173</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0173" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0173" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0173" ref_url="https://www.suse.com/security/cve/CVE-2021-0173" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper Validation of Consistency within input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a unauthenticated user to potentially enable denial of service via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-0173/">CVE-2021-0173</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210174" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0174</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0174" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0174" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0174" ref_url="https://www.suse.com/security/cve/CVE-2021-0174" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper Use of Validation Framework in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a unauthenticated user to potentially enable denial of service via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-0174/">CVE-2021-0174</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210175" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0175</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0175" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0175" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0175" ref_url="https://www.suse.com/security/cve/CVE-2021-0175" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-0175/">CVE-2021-0175</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210176" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0176</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0176" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0176" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0176" ref_url="https://www.suse.com/security/cve/CVE-2021-0176" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-0176/">CVE-2021-0176</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210183" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0183</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0183" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0183" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0183" ref_url="https://www.suse.com/security/cve/CVE-2021-0183" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper Validation of Specified Index, Position, or Offset in Input in software for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-0183/">CVE-2021-0183</cve>
	<bugzilla href="https://bugzilla.suse.com/1196333">SUSE bug 1196333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210326" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0326</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0326" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0326" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0326" ref_url="https://www.suse.com/security/cve/CVE-2021-0326" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:0443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008328.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008327.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0284-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YI2F4UP2SUM3KDNM2O5RK57I3NEYBJ26/" source="SUSE-SU"/>
    <description>
    In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172937525
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0326/">CVE-2021-0326</cve>
	<bugzilla href="https://bugzilla.suse.com/1181777">SUSE bug 1181777</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760868" comment="wpa_supplicant-2.9-4.23.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210342" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0342</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0342" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0342" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0342" ref_url="https://www.suse.com/security/cve/CVE-2021-0342" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0818-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008502.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0241-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GZRN6BW22C4S3GVCJVPHDT4HHTLVGVZE/" source="SUSE-SU"/>
    <description>
    In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges required. User interaction is not required for exploitation. Product: Android; Versions: Android kernel; Android ID: A-146554327.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0342/">CVE-2021-0342</cve>
	<bugzilla href="https://bugzilla.suse.com/1180812">SUSE bug 1180812</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180859">SUSE bug 1180859</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210512" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0512</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0512" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0512" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0512" ref_url="https://www.suse.com/security/cve/CVE-2021-0512" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2361-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2368-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2377-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2453-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009202.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2305-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BBGE5AIDX3NT46HPS2IYLFESAEFCTG6O/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2352-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2GU2EJMYFONMKDLPFYPCAPSOFXO5ZISM/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
    <description>
    In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0512/">CVE-2021-0512</cve>
	<bugzilla href="https://bugzilla.suse.com/1187595">SUSE bug 1187595</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1187597">SUSE bug 1187597</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704907" comment="kernel-default-5.3.18-24.70.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704908" comment="kernel-default-base-5.3.18-24.70.1.9.32.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624613" comment="kernel-rt-4.12.14-10.49.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210605" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0605</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0605" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0605" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0605" ref_url="https://www.suse.com/security/cve/CVE-2021-0605" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2368-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2377-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2305-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BBGE5AIDX3NT46HPS2IYLFESAEFCTG6O/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2352-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2GU2EJMYFONMKDLPFYPCAPSOFXO5ZISM/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
    <description>
    In pfkey_dump of af_key.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-110373476
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0605/">CVE-2021-0605</cve>
	<bugzilla href="https://bugzilla.suse.com/1187601">SUSE bug 1187601</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1187687">SUSE bug 1187687</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188381">SUSE bug 1188381</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704907" comment="kernel-default-5.3.18-24.70.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704908" comment="kernel-default-base-5.3.18-24.70.1.9.32.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624613" comment="kernel-rt-4.12.14-10.49.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210606" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0606</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0606" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0606" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0606" ref_url="https://www.suse.com/security/cve/CVE-2021-0606" source="SUSE CVE"/>
    <description>
    In drm_syncobj_handle_to_fd of drm_syncobj.c, there is a possible use after free due to incorrect refcounting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168034487
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0606/">CVE-2021-0606</cve>
	<bugzilla href="https://bugzilla.suse.com/1187602">SUSE bug 1187602</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210707" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0707</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0707" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0707" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0707" ref_url="https://www.suse.com/security/cve/CVE-2021-0707" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1669-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011033.html" source="SUSE-SU"/>
    <description>
    In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-155756045References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0707/">CVE-2021-0707</cve>
	<bugzilla href="https://bugzilla.suse.com/1198437">SUSE bug 1198437</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199332">SUSE bug 1199332</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210920" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0920</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0920" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0920" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0920" ref_url="https://www.suse.com/security/cve/CVE-2021-0920" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010319.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010320.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010321.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0660-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0667-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0668-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010328.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0996-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1034-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0920/">CVE-2021-0920</cve>
	<bugzilla href="https://bugzilla.suse.com/1193731">SUSE bug 1193731</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194463">SUSE bug 1194463</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195939">SUSE bug 1195939</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199255">SUSE bug 1199255</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200084">SUSE bug 1200084</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210924" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0924</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0924" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0924" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0924" ref_url="https://www.suse.com/security/cve/CVE-2021-0924" source="SUSE CVE"/>
    <description>
    In xhci_vendor_get_ops of xhci.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194461020References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0924/">CVE-2021-0924</cve>
	<bugzilla href="https://bugzilla.suse.com/1193792">SUSE bug 1193792</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210929" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0929</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0929" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0929" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0929" ref_url="https://www.suse.com/security/cve/CVE-2021-0929" source="SUSE CVE"/>
    <description>
    In ion_dma_buf_end_cpu_access and related functions of ion.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-187527909References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-0929/">CVE-2021-0929</cve>
	<bugzilla href="https://bugzilla.suse.com/1193794">SUSE bug 1193794</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210938" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0938</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0938" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0938" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0938" ref_url="https://www.suse.com/security/cve/CVE-2021-0938" source="SUSE CVE"/>
    <description>
    In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-171418586References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-0938/">CVE-2021-0938</cve>
	<bugzilla href="https://bugzilla.suse.com/1192039">SUSE bug 1192039</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210939" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0939</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0939" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0939" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0939" ref_url="https://www.suse.com/security/cve/CVE-2021-0939" source="SUSE CVE"/>
    <description>
    In set_default_passthru_cfg of passthru.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-186026549References: N/A
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-0939/">CVE-2021-0939</cve>
	<bugzilla href="https://bugzilla.suse.com/1192043">SUSE bug 1192043</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210941" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0941</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0941" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0941" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0941" ref_url="https://www.suse.com/security/cve/CVE-2021-0941" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009774.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3807-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3941-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009873.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3979-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009875.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3992-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4021-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009891.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009894.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009909.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4099-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009913.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1501-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5J6FJF42AOGK3VQ4EFVDHQENHCDEMVT3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3806-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WLGTBAKURNXDJOZBJTW2QLXJEWT66GSC/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3941-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UKZHKAOI6N3ILHMQUWDAPBQQORWN64SU/" source="SUSE-SU"/>
    <description>
    In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154177719References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-0941/">CVE-2021-0941</cve>
	<bugzilla href="https://bugzilla.suse.com/1192045">SUSE bug 1192045</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192048">SUSE bug 1192048</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705000" comment="kernel-default-5.3.18-24.96.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705001" comment="kernel-default-base-5.3.18-24.96.1.9.44.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658974" comment="kernel-rt-5.3.18-62.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20210961" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-0961</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-0961" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0961" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-0961" ref_url="https://www.suse.com/security/cve/CVE-2021-0961" source="SUSE CVE"/>
    <description>
    In quota_proc_write of xt_quota2.c, there is a possible way to read kernel memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196046570References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-0961/">CVE-2021-0961</cve>
	<bugzilla href="https://bugzilla.suse.com/1193790">SUSE bug 1193790</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20211043" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-1043</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-1043" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1043" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-1043" ref_url="https://www.suse.com/security/cve/CVE-2021-1043" source="SUSE CVE"/>
    <description>
    In TBD of TBD, there is a possible downgrade attack due to under utilized anti-rollback protections. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194697257References: N/A
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-13"/>
	<updated date="2023-01-13"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-1043/">CVE-2021-1043</cve>
	<bugzilla href="https://bugzilla.suse.com/1199357">SUSE bug 1199357</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120177" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20177</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20177" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20177" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20177" ref_url="https://www.suse.com/security/cve/CVE-2021-20177" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008354.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0241-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GZRN6BW22C4S3GVCJVPHDT4HHTLVGVZE/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can panic the system. Kernel before kernel 5.5-rc1 is affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-20177/">CVE-2021-20177</cve>
	<bugzilla href="https://bugzilla.suse.com/1180765">SUSE bug 1180765</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120181" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20181</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20181" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20181" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20181" ref_url="https://www.suse.com/security/cve/CVE-2021-20181" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SDUPZEIOIEXWFR2ZTWFFOIO2ZA3AI3VM/" source="SUSE-SU"/>
    <description>
    A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-20181/">CVE-2021-20181</cve>
	<bugzilla href="https://bugzilla.suse.com/1182137">SUSE bug 1182137</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120193" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20193</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20193" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20193" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20193" ref_url="https://www.suse.com/security/cve/CVE-2021-20193" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1096-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1101-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:917-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:919-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:680-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:683-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:689-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0974-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010950.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0494-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XRDSUUE3LUKBDRLPB7GTT5QZRPV5J7O4/" source="SUSE-SU"/>
    <description>
    A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-20193/">CVE-2021-20193</cve>
	<bugzilla href="https://bugzilla.suse.com/1181131">SUSE bug 1181131</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705032" comment="tar-1.34-150000.3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120194" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20194</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20194" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20194" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20194" ref_url="https://www.suse.com/security/cve/CVE-2021-20194" source="SUSE CVE"/>
    <description>
    There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-20194/">CVE-2021-20194</cve>
	<bugzilla href="https://bugzilla.suse.com/1181637">SUSE bug 1181637</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182010">SUSE bug 1182010</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182330">SUSE bug 1182330</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120196" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20196</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20196" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20196" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20196" ref_url="https://www.suse.com/security/cve/CVE-2021-20196" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0177-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-January/021445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0210-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010125.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0210-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010676.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0177-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6XYIZAS6LJG7AX5XUIXPP347424BX5VK/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0210-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ORE7QLMZXD7OV3HIKQUG3SXU2RG6ONFC/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0210-2" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IUV2UU2CMT6KXSJ7THBLFDIVHI27MZFH/" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-20196/">CVE-2021-20196</cve>
	<bugzilla href="https://bugzilla.suse.com/1181361">SUSE bug 1181361</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705033" comment="qemu-4.2.1-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705034" comment="qemu-arm-4.2.1-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667529" comment="qemu-ipxe-1.0.0+-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667533" comment="qemu-seabios-1.12.1+-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667534" comment="qemu-sgabios-8-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705035" comment="qemu-tools-4.2.1-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667539" comment="qemu-vgabios-1.12.1+-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667540" comment="qemu-x86-4.2.1-11.34.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120201" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20201</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20201" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20201" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20201" ref_url="https://www.suse.com/security/cve/CVE-2021-20201" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:14744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1901-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1902-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019243.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1927-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1956-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008998.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2881-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2881-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012041.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0874-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AINSWYQLD5FH4GUOEP5FWWA5CMFHTUDX/" source="SUSE-SU"/>
    <description>
    A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-20201/">CVE-2021-20201</cve>
	<bugzilla href="https://bugzilla.suse.com/1181686">SUSE bug 1181686</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704902" comment="libspice-server1-0.14.2-3.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120203" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20203</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20203" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20203" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20203" ref_url="https://www.suse.com/security/cve/CVE-2021-20203" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SDUPZEIOIEXWFR2ZTWFFOIO2ZA3AI3VM/" source="SUSE-SU"/>
    <description>
    An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-20203/">CVE-2021-20203</cve>
	<bugzilla href="https://bugzilla.suse.com/1181639">SUSE bug 1181639</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120221" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20221</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20221" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20221" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20221" ref_url="https://www.suse.com/security/cve/CVE-2021-20221" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0521-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14774-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008910.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008954.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SDUPZEIOIEXWFR2ZTWFFOIO2ZA3AI3VM/" source="SUSE-SU"/>
    <description>
    An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits wide. It may lead to the said issue while updating controller state fields and their subsequent processing. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-20221/">CVE-2021-20221</cve>
	<bugzilla href="https://bugzilla.suse.com/1181933">SUSE bug 1181933</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760852" comment="qemu-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760853" comment="qemu-arm-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760854" comment="qemu-ipxe-1.0.0+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760855" comment="qemu-ppc-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760856" comment="qemu-s390-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760857" comment="qemu-seabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760858" comment="qemu-sgabios-8-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760859" comment="qemu-tools-4.2.1-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760860" comment="qemu-vgabios-1.12.1+-11.13.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760861" comment="qemu-x86-4.2.1-11.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120226" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20226</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20226" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20226" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20226" ref_url="https://www.suse.com/security/cve/CVE-2021-20226" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of service problem on the system The issue results from the lack of validating the existence of an object prior to performing operations on the object by not incrementing the file reference counter while in use. The highest threat from this vulnerability is to data integrity, confidentiality and system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-20226/">CVE-2021-20226</cve>
	<bugzilla href="https://bugzilla.suse.com/1180564">SUSE bug 1180564</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181846">SUSE bug 1181846</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120231" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20231</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20231" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20231" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20231" ref_url="https://www.suse.com/security/cve/CVE-2021-20231" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0934-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008548.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0470-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LUDG7BXPVVVALM2YUCJ2EKIRBHFXMY75/" source="SUSE-SU"/>
    <description>
    A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-20231/">CVE-2021-20231</cve>
	<bugzilla href="https://bugzilla.suse.com/1183457">SUSE bug 1183457</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705015" comment="libgnutls30-3.6.7-14.10.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120232" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20232</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20232" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20232" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20232" ref_url="https://www.suse.com/security/cve/CVE-2021-20232" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0934-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008548.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0470-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LUDG7BXPVVVALM2YUCJ2EKIRBHFXMY75/" source="SUSE-SU"/>
    <description>
    A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-20232/">CVE-2021-20232</cve>
	<bugzilla href="https://bugzilla.suse.com/1183456">SUSE bug 1183456</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705015" comment="libgnutls30-3.6.7-14.10.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120239" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20239</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20239" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20239" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20239" ref_url="https://www.suse.com/security/cve/CVE-2021-20239" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-20239/">CVE-2021-20239</cve>
	<bugzilla href="https://bugzilla.suse.com/1182010">SUSE bug 1182010</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182330">SUSE bug 1182330</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120255" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20255</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20255" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20255" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20255" ref_url="https://www.suse.com/security/cve/CVE-2021-20255" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2789-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019909.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009332.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3635-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009705.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2789-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UE3MLTPF62745SPUUDQR6ROYVP4GG6DT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2858-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GGOXRRBMGRJGBNXEGPCZ3JFLXCMIM6A3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3614-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/26KPX43RJBRTCX3JER7CN7MAT4QEGAED/" source="SUSE-SU"/>
    <description>
    A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-20255/">CVE-2021-20255</cve>
	<bugzilla href="https://bugzilla.suse.com/1182651">SUSE bug 1182651</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182654">SUSE bug 1182654</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704934" comment="qemu-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630345" comment="qemu-arm-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630353" comment="qemu-ipxe-1.0.0+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630359" comment="qemu-seabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630360" comment="qemu-sgabios-8-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704935" comment="qemu-tools-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630364" comment="qemu-vgabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630365" comment="qemu-x86-4.2.1-11.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120257" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20257</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20257" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20257" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20257" ref_url="https://www.suse.com/security/cve/CVE-2021-20257" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1023-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1251-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008655.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1252-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008660.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14706-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008673.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008910.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1895-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010821.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
    <description>
    An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-20257/">CVE-2021-20257</cve>
	<bugzilla href="https://bugzilla.suse.com/1182577">SUSE bug 1182577</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182846">SUSE bug 1182846</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704898" comment="qemu-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499897" comment="qemu-arm-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499905" comment="qemu-ipxe-1.0.0+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499911" comment="qemu-seabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499912" comment="qemu-sgabios-8-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704899" comment="qemu-tools-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499916" comment="qemu-vgabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499917" comment="qemu-x86-4.2.1-11.19.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120263" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20263</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20263" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20263" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20263" ref_url="https://www.suse.com/security/cve/CVE-2021-20263" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
    <description>
    A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-20263/">CVE-2021-20263</cve>
	<bugzilla href="https://bugzilla.suse.com/1183373">SUSE bug 1183373</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120265" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20265</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20265" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20265" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20265" ref_url="https://www.suse.com/security/cve/CVE-2021-20265" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-20265/">CVE-2021-20265</cve>
	<bugzilla href="https://bugzilla.suse.com/1183089">SUSE bug 1183089</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1214268">SUSE bug 1214268</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120266" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20266</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20266" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20266" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20266" ref_url="https://www.suse.com/security/cve/CVE-2021-20266" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1052-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-May/023165.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2938-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2974-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010661.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:590-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010696.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:592-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010958.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3939-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012871.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WOGLQWSIIR4HYRWXGETEIHB6SM6A2MNK/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2682-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IQDL4MT3J7VM3IS3TI4EMLQJHDPTSZLZ/" source="SUSE-SU"/>
    <description>
    A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-20266/">CVE-2021-20266</cve>
	<bugzilla href="https://bugzilla.suse.com/1183632">SUSE bug 1183632</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704952" comment="python3-rpm-4.14.1-22.4.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704953" comment="rpm-4.14.1-22.4.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120268" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20268</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20268" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20268" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20268" ref_url="https://www.suse.com/security/cve/CVE-2021-20268" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls dev_map_init_map or sock_map_alloc. This flaw allows a local user to crash the system or possibly escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-20268/">CVE-2021-20268</cve>
	<bugzilla href="https://bugzilla.suse.com/1183077">SUSE bug 1183077</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183095">SUSE bug 1183095</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120269" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20269</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20269" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20269" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20269" ref_url="https://www.suse.com/security/cve/CVE-2021-20269" source="SUSE CVE"/>
    <description>
    A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects kexec-tools shipped by Fedora versions prior to 2.0.21-8 and RHEL versions prior to 2.0.20-47.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-20269/">CVE-2021-20269</cve>
	<bugzilla href="https://bugzilla.suse.com/1189468">SUSE bug 1189468</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120271" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20271</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20271" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20271" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20271" ref_url="https://www.suse.com/security/cve/CVE-2021-20271" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1052-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-May/023165.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2938-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2974-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010661.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:590-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010696.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:592-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010958.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3939-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012871.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WOGLQWSIIR4HYRWXGETEIHB6SM6A2MNK/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2682-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IQDL4MT3J7VM3IS3TI4EMLQJHDPTSZLZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2685-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PUJW4L55UGKEL4ROYV7WZNQDNBJXXLLG/" source="SUSE-SU"/>
    <description>
    A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-20271/">CVE-2021-20271</cve>
	<bugzilla href="https://bugzilla.suse.com/1183545">SUSE bug 1183545</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704952" comment="python3-rpm-4.14.1-22.4.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704953" comment="rpm-4.14.1-22.4.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120305" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20305</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20305" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20305" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20305" ref_url="https://www.suse.com/security/cve/CVE-2021-20305" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:127-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008696.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:128-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1399-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008682.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008693.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0635-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JEQQBLTWQPDTYRTWQZSXENUU6TSCBJ5R/" source="SUSE-SU"/>
    <description>
    A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA &amp; ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing an assertion failure or possible validation. The highest threat to this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-20305/">CVE-2021-20305</cve>
	<bugzilla href="https://bugzilla.suse.com/1183835">SUSE bug 1183835</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1184401">SUSE bug 1184401</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009503185" comment="libhogweed4-3.4.1-4.15.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009503187" comment="libnettle6-3.4.1-4.15.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202120322" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-20322</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-20322" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20322" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-20322" ref_url="https://www.suse.com/security/cve/CVE-2021-20322" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009774.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3807-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3941-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009873.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3979-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009875.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3992-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4021-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009891.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009894.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009895.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4075-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009910.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009909.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4099-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009913.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1501-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5J6FJF42AOGK3VQ4EFVDHQENHCDEMVT3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3806-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WLGTBAKURNXDJOZBJTW2QLXJEWT66GSC/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3941-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UKZHKAOI6N3ILHMQUWDAPBQQORWN64SU/" source="SUSE-SU"/>
    <description>
    A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-20322/">CVE-2021-20322</cve>
	<bugzilla href="https://bugzilla.suse.com/1191790">SUSE bug 1191790</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191813">SUSE bug 1191813</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193290">SUSE bug 1193290</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705000" comment="kernel-default-5.3.18-24.96.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705001" comment="kernel-default-base-5.3.18-24.96.1.9.44.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658974" comment="kernel-rt-5.3.18-62.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202121284" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-21284</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-21284" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21284" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-21284" ref_url="https://www.suse.com/security/cve/CVE-2021-21284" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008311.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0445-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008994.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0278-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UGKTLORCQ4MPZPDFGWKJEEPQRXFUTZYZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0878-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/G76UZ7FY6VFG73EC6UUCBE46L3TAKR6G/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1954-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OX775QFGRPXXX7W5FDFKP3V5KCNZYD7F/" source="SUSE-SU"/>
    <description>
    In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has access to the host filesystem they can modify files under "/var/lib/docker/&lt;remapping&gt;" that cause writing files with extended privileges. Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-21284/">CVE-2021-21284</cve>
	<bugzilla href="https://bugzilla.suse.com/1181732">SUSE bug 1181732</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009504109" comment="containerd-1.4.4-5.32.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504110" comment="docker-20.10.6_ce-6.49.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504111" comment="runc-1.0.0~rc93-1.14.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202121285" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-21285</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-21285" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21285" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-21285" ref_url="https://www.suse.com/security/cve/CVE-2021-21285" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008311.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0445-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008318.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008994.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0278-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UGKTLORCQ4MPZPDFGWKJEEPQRXFUTZYZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0878-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/G76UZ7FY6VFG73EC6UUCBE46L3TAKR6G/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1954-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OX775QFGRPXXX7W5FDFKP3V5KCNZYD7F/" source="SUSE-SU"/>
    <description>
    In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-21285/">CVE-2021-21285</cve>
	<bugzilla href="https://bugzilla.suse.com/1181730">SUSE bug 1181730</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009504109" comment="containerd-1.4.4-5.32.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504110" comment="docker-20.10.6_ce-6.49.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504111" comment="runc-1.0.0~rc93-1.14.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202121334" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-21334</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-21334" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21334" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-21334" ref_url="https://www.suse.com/security/cve/CVE-2021-21334" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008994.html" source="SUSE-SU"/>
		<reference ref_id="TID000020328" ref_url="https://www.suse.com/support/kb/doc/?id=000020328" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0878-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/G76UZ7FY6VFG73EC6UUCBE46L3TAKR6G/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1954-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OX775QFGRPXXX7W5FDFKP3V5KCNZYD7F/" source="SUSE-SU"/>
    <description>
    In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may receive incorrect environment variables, including values that are defined for other containers. If the affected containers have different security contexts, this may allow sensitive information to be unintentionally shared. If you are not using containerd's CRI implementation (through one of the mechanisms described above), you are not vulnerable to this issue. If you are not launching multiple containers or Kubernetes pods from the same image which have different environment variables, you are not vulnerable to this issue. If you are not launching multiple containers or Kubernetes pods from the same image in rapid succession, you have reduced likelihood of being vulnerable to this issue This vulnerability has been fixed in containerd 1.3.10 and containerd 1.4.4. Users should update to these versions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-21334/">CVE-2021-21334</cve>
	<bugzilla href="https://bugzilla.suse.com/1183397">SUSE bug 1183397</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009504109" comment="containerd-1.4.4-5.32.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504110" comment="docker-20.10.6_ce-6.49.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504111" comment="runc-1.0.0~rc93-1.14.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202121781" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-21781</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-21781" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21781" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-21781" ref_url="https://www.suse.com/security/cve/CVE-2021-21781" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2645-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009277.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009299.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1142-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BN7VVRY72WW4I46CQCFBKXWN6CBHKRXO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2645-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2WMUIJQF7RUSXDRXECLPMVDE6YOS5WIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2687-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GDBOWLDJQ4K7JKRHIM7AOCKTJO5BY6C5/" source="SUSE-SU"/>
    <description>
    An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An attacker can read a process’s memory at a specific offset to trigger this vulnerability. This was fixed in kernel releases: 4.14.222 4.19.177 5.4.99 5.10.17 5.11
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-21781/">CVE-2021-21781</cve>
	<bugzilla href="https://bugzilla.suse.com/1188445">SUSE bug 1188445</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704932" comment="kernel-default-5.3.18-24.78.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704933" comment="kernel-default-base-5.3.18-24.78.1.9.36.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628046" comment="kernel-rt-5.3.18-48.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202121996" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-21996</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-21996" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21996" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-21996" ref_url="https://www.suse.com/security/cve/CVE-2021-21996" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:14831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009668.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009664.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009666.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009669.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3553-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009665.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009662.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3556-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009673.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009672.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3561-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009667.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3901-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3902-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3903-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3908-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009828.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1443-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YD2NL2DWHZHSXKKSMUAKRRR4DVAXJ6QS/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3557-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/R7B4SF25YMDBZ6THNOFMFVVX33VAXGND/" source="SUSE-SU"/>
    <description>
    An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-21996/">CVE-2021-21996</cve>
	<bugzilla href="https://bugzilla.suse.com/1190265">SUSE bug 1190265</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1210934">SUSE bug 1210934</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704973" comment="python3-salt-3002.2-49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704974" comment="salt-3002.2-49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704975" comment="salt-minion-3002.2-49.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704976" comment="salt-transactional-update-3002.2-49.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122004" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22004</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22004" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22004" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22004" ref_url="https://www.suse.com/security/cve/CVE-2021-22004" source="SUSE CVE"/>
    <description>
    An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-22004/">CVE-2021-22004</cve>
	<bugzilla href="https://bugzilla.suse.com/1196745">SUSE bug 1196745</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009347405" comment="python3-salt is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009347406" comment="salt is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009347413" comment="salt-minion is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009656852" comment="salt-transactional-update is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122543" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22543</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22543" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22543" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22543" ref_url="https://www.suse.com/security/cve/CVE-2021-22543" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009279.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2644-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2645-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009277.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2746-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1142-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BN7VVRY72WW4I46CQCFBKXWN6CBHKRXO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2645-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2WMUIJQF7RUSXDRXECLPMVDE6YOS5WIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2687-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GDBOWLDJQ4K7JKRHIM7AOCKTJO5BY6C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-22543/">CVE-2021-22543</cve>
	<bugzilla href="https://bugzilla.suse.com/1186482">SUSE bug 1186482</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186483">SUSE bug 1186483</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190276">SUSE bug 1190276</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197660">SUSE bug 1197660</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704932" comment="kernel-default-5.3.18-24.78.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704933" comment="kernel-default-base-5.3.18-24.78.1.9.36.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628046" comment="kernel-rt-5.3.18-48.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122555" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22555</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22555" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22555" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22555" ref_url="https://www.suse.com/security/cve/CVE-2021-22555" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009160.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2409-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-July/019639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009170.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009222.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009226.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2559-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-July/019748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009239.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009244.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2599-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009260.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009279.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1076-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WT3TYNEJZ7FKJMTYO3DX3Z7B2YCYPEJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2409-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PZY5AYK3E4EZBBTJOQXWCMRDFFYLM6EB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2415-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VDV3DHS5VRBTZIQXVKQML4UNTSCPJZZA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
    <description>
    A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-22555/">CVE-2021-22555</cve>
	<bugzilla href="https://bugzilla.suse.com/1188116">SUSE bug 1188116</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188117">SUSE bug 1188117</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188411">SUSE bug 1188411</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704910" comment="kernel-default-5.3.18-24.75.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704911" comment="kernel-default-base-5.3.18-24.75.3.9.34.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626892" comment="kernel-rt-5.3.18-45.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122570" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22570</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22570" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22570" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22570" ref_url="https://www.suse.com/security/cve/CVE-2021-22570" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:286-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010468.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:445-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:447-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:454-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:456-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010599.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010601.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:460-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:462-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:464-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:465-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010609.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:466-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010610.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:500-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010643.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010644.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:525-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010658.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010662.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010893.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:871-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010942.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:872-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010943.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2854-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016085.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:3070-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:3073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016268.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:3084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1040-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1040-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-April/022658.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1040-3" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2783-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016228.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0823-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WYCKEL27LS2QTHCEAYFVLKKSZP4MBBJQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1040-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FIWUQWCBEUJG4GQZ33E3U56DPOPU6GGL/" source="SUSE-SU"/>
    <description>
    Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-22570/">CVE-2021-22570</cve>
	<bugzilla href="https://bugzilla.suse.com/1195258">SUSE bug 1195258</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705023" comment="libprotobuf-lite20-3.9.2-4.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122600" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22600</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22600" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22600" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22600" ref_url="https://www.suse.com/security/cve/CVE-2021-22600" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0363-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010216.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010282.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010320.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0660-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010329.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4ZJSATCJ2GMGCX6RSG2TU2YU4DDOMVQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0370-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ASMTCFCDULHGAOBQUFJH4PHVCQSTF7S6/" source="SUSE-SU"/>
    <description>
    A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-22600/">CVE-2021-22600</cve>
	<bugzilla href="https://bugzilla.suse.com/1195184">SUSE bug 1195184</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195307">SUSE bug 1195307</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009667498" comment="kernel-default-5.3.18-24.102.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667499" comment="kernel-default-base-5.3.18-24.102.1.9.48.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009668286" comment="kernel-rt-5.3.18-73.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122876" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22876</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22876" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22876" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22876" ref_url="https://www.suse.com/security/cve/CVE-2021-22876" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:100-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008881.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:228-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008897.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:229-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008898.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1006-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14707-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008879.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0510-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HDAO4Q3JZASM6AK274RF74JN2GJOK5UE/" source="SUSE-SU"/>
    <description>
    curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-22876/">CVE-2021-22876</cve>
	<bugzilla href="https://bugzilla.suse.com/1183933">SUSE bug 1183933</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704853" comment="curl-7.66.0-4.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704854" comment="libcurl4-7.66.0-4.14.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122890" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22890</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22890" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22890" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22890" ref_url="https://www.suse.com/security/cve/CVE-2021-22890" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:100-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1006-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008577.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0510-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HDAO4Q3JZASM6AK274RF74JN2GJOK5UE/" source="SUSE-SU"/>
    <description>
    curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server and then wrongly "short-cut" the host handshake. When confusing the tickets, a HTTPS proxy can trick libcurl to use the wrong session ticket resume for the host and thereby circumvent the server TLS certificate check and make a MITM attack to be possible to perform unnoticed. Note that such a malicious HTTPS proxy needs to provide a certificate that curl will accept for the MITMed server for an attack to work - unless curl has been told to ignore the server certificate check.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-22890/">CVE-2021-22890</cve>
	<bugzilla href="https://bugzilla.suse.com/1183934">SUSE bug 1183934</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704853" comment="curl-7.66.0-4.14.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704854" comment="libcurl4-7.66.0-4.14.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122898" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22898</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22898" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22898" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22898" ref_url="https://www.suse.com/security/cve/CVE-2021-22898" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008847.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:199-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:200-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008881.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:228-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008897.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:229-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008898.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:252-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008846.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008879.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008887.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0808-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3ES6AKURDGLC4PDCDFLHOPWYDQA55NHQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1762-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OBJDOC5P7XCTDSENHRNLNXYRSHFI4CYU/" source="SUSE-SU"/>
    <description>
    curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-22898/">CVE-2021-22898</cve>
	<bugzilla href="https://bugzilla.suse.com/1186114">SUSE bug 1186114</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192450">SUSE bug 1192450</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704879" comment="curl-7.66.0-4.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704880" comment="libcurl4-7.66.0-4.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122922" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22922</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22922" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22922" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22922" ref_url="https://www.suse.com/security/cve/CVE-2021-22922" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:311-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2425-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2462-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009210.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1088-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SZZR7BLPD5OE5IYY5QBKBYQGD4PESB24/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2439-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SZEKWBHHW6CCB43EQZT3OXNG7LXABDJB/" source="SUSE-SU"/>
    <description>
    When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several of them. In a serial orparallel manner.If one of the servers hosting the contents has been breached and the contentsof the specific file on that server is replaced with a modified payload, curlshould detect this when the hash of the file mismatches after a completeddownload. It should remove the contents and instead try getting the contentsfrom another URL. This is not done, and instead such a hash mismatch is onlymentioned in text and the potentially malicious content is kept in the file ondisk.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-22922/">CVE-2021-22922</cve>
	<bugzilla href="https://bugzilla.suse.com/1188217">SUSE bug 1188217</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192447">SUSE bug 1192447</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704912" comment="curl-7.66.0-4.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704913" comment="libcurl4-7.66.0-4.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122923" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22923</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22923" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22923" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22923" ref_url="https://www.suse.com/security/cve/CVE-2021-22923" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:311-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2425-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2462-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009210.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1088-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SZZR7BLPD5OE5IYY5QBKBYQGD4PESB24/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2439-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SZEKWBHHW6CCB43EQZT3OXNG7LXABDJB/" source="SUSE-SU"/>
    <description>
    When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-22923/">CVE-2021-22923</cve>
	<bugzilla href="https://bugzilla.suse.com/1188218">SUSE bug 1188218</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192447">SUSE bug 1192447</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704912" comment="curl-7.66.0-4.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704913" comment="libcurl4-7.66.0-4.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122924" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22924</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22924" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22924" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22924" ref_url="https://www.suse.com/security/cve/CVE-2021-22924" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:311-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2425-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2462-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009210.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1088-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SZZR7BLPD5OE5IYY5QBKBYQGD4PESB24/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2439-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SZEKWBHHW6CCB43EQZT3OXNG7LXABDJB/" source="SUSE-SU"/>
    <description>
    libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-22924/">CVE-2021-22924</cve>
	<bugzilla href="https://bugzilla.suse.com/1188219">SUSE bug 1188219</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192447">SUSE bug 1192447</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200196">SUSE bug 1200196</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704912" comment="curl-7.66.0-4.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704913" comment="libcurl4-7.66.0-4.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122925" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22925</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22925" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22925" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22925" ref_url="https://www.suse.com/security/cve/CVE-2021-22925" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:311-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009195.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2425-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2462-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009210.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1088-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SZZR7BLPD5OE5IYY5QBKBYQGD4PESB24/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2439-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SZEKWBHHW6CCB43EQZT3OXNG7LXABDJB/" source="SUSE-SU"/>
    <description>
    curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-22925/">CVE-2021-22925</cve>
	<bugzilla href="https://bugzilla.suse.com/1188220">SUSE bug 1188220</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192447">SUSE bug 1192447</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200196">SUSE bug 1200196</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704912" comment="curl-7.66.0-4.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704913" comment="libcurl4-7.66.0-4.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122926" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22926</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22926" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22926" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22926" ref_url="https://www.suse.com/security/cve/CVE-2021-22926" source="SUSE CVE"/>
    <description>
    libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask for the client certificate by name or with a file name - using the same option. If the name exists as a file, it will be used instead of by name.If the appliction runs with a current working directory that is writable by other users (like `/tmp`), a malicious user can create a file name with the same name as the app wants to use by name, and thereby trick the application to use the file based cert instead of the one referred to by name making libcurl send the wrong client certificate in the TLS connection handshake.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-22926/">CVE-2021-22926</cve>
	<bugzilla href="https://bugzilla.suse.com/1188510">SUSE bug 1188510</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192447">SUSE bug 1192447</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192757">SUSE bug 1192757</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333977" comment="curl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335173" comment="libcurl4 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122946" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22946</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22946" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22946" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22946" ref_url="https://www.suse.com/security/cve/CVE-2021-22946" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:382-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:384-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:391-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:399-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009586.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009560.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009570.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1384-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YRVRDNRDONYRGYKCIS6D72VODPDQT3AB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3298-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ROJISG4GC22MLBYTQB5THWN4V2IFZC7P/" source="SUSE-SU"/>
    <description>
    A user can tell curl &gt;= 7.20.0 and &lt;= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-22946/">CVE-2021-22946</cve>
	<bugzilla href="https://bugzilla.suse.com/1190373">SUSE bug 1190373</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194948">SUSE bug 1194948</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704950" comment="curl-7.66.0-4.27.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704951" comment="libcurl4-7.66.0-4.27.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202122947" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-22947</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-22947" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22947" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-22947" ref_url="https://www.suse.com/security/cve/CVE-2021-22947" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:382-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:384-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:391-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:399-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009586.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14807-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009560.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009570.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1384-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YRVRDNRDONYRGYKCIS6D72VODPDQT3AB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3298-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ROJISG4GC22MLBYTQB5THWN4V2IFZC7P/" source="SUSE-SU"/>
    <description>
    When curl &gt;= 7.20.0 and &lt;= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-22947/">CVE-2021-22947</cve>
	<bugzilla href="https://bugzilla.suse.com/1190374">SUSE bug 1190374</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704950" comment="curl-7.66.0-4.27.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704951" comment="libcurl4-7.66.0-4.27.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202123134" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-23134</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-23134" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23134" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-23134" ref_url="https://www.suse.com/security/cve/CVE-2021-23134" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2020-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010158.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0327-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010186.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-23134/">CVE-2021-23134</cve>
	<bugzilla href="https://bugzilla.suse.com/1186060">SUSE bug 1186060</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186061">SUSE bug 1186061</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202123239" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-23239</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-23239" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23239" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-23239" ref_url="https://www.suse.com/security/cve/CVE-2021-23239" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0225-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0226-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0227-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008250.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008252.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7OQJUG5Z7K425IKZS5GT4KPIBGTT4JMW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0170-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3O463OUKAXLCUM74AUHUPVMQFXLLVAEH/" source="SUSE-SU"/>
    <description>
    The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-23239/">CVE-2021-23239</cve>
	<bugzilla href="https://bugzilla.suse.com/1171722">SUSE bug 1171722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180684">SUSE bug 1180684</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760863" comment="sudo-1.8.22-4.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202123240" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-23240</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-23240" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23240" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-23240" ref_url="https://www.suse.com/security/cve/CVE-2021-23240" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0225-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0226-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0227-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008250.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7OQJUG5Z7K425IKZS5GT4KPIBGTT4JMW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0170-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3O463OUKAXLCUM74AUHUPVMQFXLLVAEH/" source="SUSE-SU"/>
    <description>
    selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-23240/">CVE-2021-23240</cve>
	<bugzilla href="https://bugzilla.suse.com/1171722">SUSE bug 1171722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1180685">SUSE bug 1180685</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760863" comment="sudo-1.8.22-4.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202123336" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-23336</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-23336" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23336" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-23336" ref_url="https://www.suse.com/security/cve/CVE-2021-23336" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0768-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0794-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0886-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008531.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009001.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2554-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009227.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0435-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LBJTTJNYOY4PWTVR3WGVSEX33BCEYHGD/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2021-23336/">CVE-2021-23336</cve>
	<bugzilla href="https://bugzilla.suse.com/1182179">SUSE bug 1182179</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182379">SUSE bug 1182379</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182433">SUSE bug 1182433</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705016" comment="libpython3_6m1_0-3.6.13-3.78.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705017" comment="python3-3.6.13-3.78.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705018" comment="python3-base-3.6.13-3.78.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202123840" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-23840</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-23840" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23840" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-23840" ref_url="https://www.suse.com/security/cve/CVE-2021-23840" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:62-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008396.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0651-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0673-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008415.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0674-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008416.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0752-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0755-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0939-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14667-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008506.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14670-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008528.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0357-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AVDCMNKQUTQBM7Z7BU2BQ23WG4Y66BOY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0372-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZKKO266WHY2YSFJAVHWNM4DQSX4W7YZG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5XENZGXQLBAUUDBFPY2BZB3VBUOBHXA3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0430-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WKXW7QBBUUWYW6GTJATRSAAWOQW7PBVU/" source="SUSE-SU"/>
    <description>
    Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-08-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2021-23840/">CVE-2021-23840</cve>
	<bugzilla href="https://bugzilla.suse.com/1182333">SUSE bug 1182333</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1187743">SUSE bug 1187743</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1214334">SUSE bug 1214334</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705007" comment="libopenssl1_1-1.1.1d-11.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705008" comment="openssl-1_1-1.1.1d-11.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202123841" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-23841</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-23841" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23841" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-23841" ref_url="https://www.suse.com/security/cve/CVE-2021-23841" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:62-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008583.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008584.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0752-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0755-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0793-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0939-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14667-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008506.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14670-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008528.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5XENZGXQLBAUUDBFPY2BZB3VBUOBHXA3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0430-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WKXW7QBBUUWYW6GTJATRSAAWOQW7PBVU/" source="SUSE-SU"/>
    <description>
    The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-08-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-23841/">CVE-2021-23841</cve>
	<bugzilla href="https://bugzilla.suse.com/1182331">SUSE bug 1182331</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1187743">SUSE bug 1187743</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1214334">SUSE bug 1214334</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705007" comment="libopenssl1_1-1.1.1d-11.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705008" comment="openssl-1_1-1.1.1d-11.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202123981" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-23981</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-23981" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23981" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-23981" ref_url="https://www.suse.com/security/cve/CVE-2021-23981" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0966-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008561.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1007-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1167-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008575.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0487-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FSNSOUV5NJGXTPEDI5OM2FZY66FY5LH2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0580-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/46S264KIM7ZLJMHW66XPM4XKEAJEZUEJ/" source="SUSE-SU"/>
    <description>
    A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR &lt; 78.9, Firefox &lt; 87, and Thunderbird &lt; 78.9.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-23981/">CVE-2021-23981</cve>
	<bugzilla href="https://bugzilla.suse.com/1183942">SUSE bug 1183942</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009503123" comment="mozilla-nspr-4.25.1-3.17.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202123982" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-23982</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-23982" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23982" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-23982" ref_url="https://www.suse.com/security/cve/CVE-2021-23982" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0966-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008561.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1007-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1167-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008575.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0487-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FSNSOUV5NJGXTPEDI5OM2FZY66FY5LH2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0580-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/46S264KIM7ZLJMHW66XPM4XKEAJEZUEJ/" source="SUSE-SU"/>
    <description>
    Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR &lt; 78.9, Firefox &lt; 87, and Thunderbird &lt; 78.9.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-23982/">CVE-2021-23982</cve>
	<bugzilla href="https://bugzilla.suse.com/1183942">SUSE bug 1183942</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009503123" comment="mozilla-nspr-4.25.1-3.17.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202123984" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-23984</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-23984" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23984" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-23984" ref_url="https://www.suse.com/security/cve/CVE-2021-23984" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0966-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008561.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1007-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1167-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008575.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0487-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FSNSOUV5NJGXTPEDI5OM2FZY66FY5LH2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0580-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/46S264KIM7ZLJMHW66XPM4XKEAJEZUEJ/" source="SUSE-SU"/>
    <description>
    A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR &lt; 78.9, Firefox &lt; 87, and Thunderbird &lt; 78.9.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-23984/">CVE-2021-23984</cve>
	<bugzilla href="https://bugzilla.suse.com/1183942">SUSE bug 1183942</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009503123" comment="mozilla-nspr-4.25.1-3.17.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202123987" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-23987</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-23987" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23987" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-23987" ref_url="https://www.suse.com/security/cve/CVE-2021-23987" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0966-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008561.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0999-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1007-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1167-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008575.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0487-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FSNSOUV5NJGXTPEDI5OM2FZY66FY5LH2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0580-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/46S264KIM7ZLJMHW66XPM4XKEAJEZUEJ/" source="SUSE-SU"/>
    <description>
    Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR &lt; 78.9, Firefox &lt; 87, and Thunderbird &lt; 78.9.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-23987/">CVE-2021-23987</cve>
	<bugzilla href="https://bugzilla.suse.com/1183942">SUSE bug 1183942</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009503123" comment="mozilla-nspr-4.25.1-3.17.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202124031" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-24031</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-24031" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24031" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-24031" ref_url="https://www.suse.com/security/cve/CVE-2021-24031" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008553.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0481-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HYCURYHE4SZBA5XWHE6FDNCJ3JJDZS5S/" source="SUSE-SU"/>
    <description>
    In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-24031/">CVE-2021-24031</cve>
	<bugzilla href="https://bugzilla.suse.com/1183371">SUSE bug 1183371</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705019" comment="libzstd1-1.4.4-1.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202124032" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-24032</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-24032" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24032" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-24032" ref_url="https://www.suse.com/security/cve/CVE-2021-24032" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008553.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0481-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HYCURYHE4SZBA5XWHE6FDNCJ3JJDZS5S/" source="SUSE-SU"/>
    <description>
    Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-24032/">CVE-2021-24032</cve>
	<bugzilla href="https://bugzilla.suse.com/1183370">SUSE bug 1183370</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183371">SUSE bug 1183371</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705019" comment="libzstd1-1.4.4-1.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202125281" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-25281</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-25281" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25281" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-25281" ref_url="https://www.suse.com/security/cve/CVE-2021-25281" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14679-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1690-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008813.html" source="SUSE-SU"/>
		<reference ref_id="TID000019887" ref_url="https://www.suse.com/support/kb/doc/?id=000019887" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0347-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CYH7ONK65HNBANHLED5R64OBSM2EORYI/" source="SUSE-SU"/>
    <description>
    An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-25281/">CVE-2021-25281</cve>
	<bugzilla href="https://bugzilla.suse.com/1181550">SUSE bug 1181550</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181559">SUSE bug 1181559</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202125282" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-25282</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-25282" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25282" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-25282" ref_url="https://www.suse.com/security/cve/CVE-2021-25282" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14679-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1690-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008813.html" source="SUSE-SU"/>
		<reference ref_id="TID000019887" ref_url="https://www.suse.com/support/kb/doc/?id=000019887" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0347-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CYH7ONK65HNBANHLED5R64OBSM2EORYI/" source="SUSE-SU"/>
    <description>
    An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-25282/">CVE-2021-25282</cve>
	<bugzilla href="https://bugzilla.suse.com/1181550">SUSE bug 1181550</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181560">SUSE bug 1181560</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202125283" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-25283</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-25283" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25283" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-25283" ref_url="https://www.suse.com/security/cve/CVE-2021-25283" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14679-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1690-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008813.html" source="SUSE-SU"/>
		<reference ref_id="TID000019887" ref_url="https://www.suse.com/support/kb/doc/?id=000019887" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0347-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CYH7ONK65HNBANHLED5R64OBSM2EORYI/" source="SUSE-SU"/>
    <description>
    An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-25283/">CVE-2021-25283</cve>
	<bugzilla href="https://bugzilla.suse.com/1181550">SUSE bug 1181550</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181561">SUSE bug 1181561</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202125284" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-25284</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-25284" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25284" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-25284" ref_url="https://www.suse.com/security/cve/CVE-2021-25284" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14679-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1690-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008813.html" source="SUSE-SU"/>
		<reference ref_id="TID000019887" ref_url="https://www.suse.com/support/kb/doc/?id=000019887" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0347-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CYH7ONK65HNBANHLED5R64OBSM2EORYI/" source="SUSE-SU"/>
    <description>
    An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-25284/">CVE-2021-25284</cve>
	<bugzilla href="https://bugzilla.suse.com/1181550">SUSE bug 1181550</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202125315" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-25315</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-25315" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25315" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-25315" ref_url="https://www.suse.com/security/cve/CVE-2021-25315" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14679-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14755-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009064.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009056.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0899-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6E3YAO2VV3WBUS7PMAT26ZYDS3AXW5VL/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2106-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MU6P3NIODW6ZMC4HZLBROO6ZEOD5KAUX/" source="SUSE-SU"/>
    <description>
    CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-23"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-25315/">CVE-2021-25315</cve>
	<bugzilla href="https://bugzilla.suse.com/1182382">SUSE bug 1182382</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009494057" comment="python3-distro-1.5.0-3.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504114" comment="python3-salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504115" comment="salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504120" comment="salt-minion-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504125" comment="salt-transactional-update-3002.2-37.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202126318" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-26318</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-26318" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26318" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-26318" ref_url="https://www.suse.com/security/cve/CVE-2021-26318" source="SUSE CVE"/>
    <description>
    A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result in leaked kernel address space information.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-26318/">CVE-2021-26318</cve>
	<bugzilla href="https://bugzilla.suse.com/1191653">SUSE bug 1191653</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202126401" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-26401</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-26401" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26401" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-26401" ref_url="https://www.suse.com/security/cve/CVE-2021-26401" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0939-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010506.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0940-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010818.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010836.html" source="SUSE-SU"/>
		<reference ref_id="TID000020607" ref_url="https://www.suse.com/support/kb/doc/?id=000020607" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0940-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NXODJTCX5G5LLTBOEFVBOCIWYKEGYAMP/" source="SUSE-SU"/>
    <description>
    LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-26401/">CVE-2021-26401</cve>
	<bugzilla href="https://bugzilla.suse.com/1191580">SUSE bug 1191580</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196901">SUSE bug 1196901</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209630">SUSE bug 1209630</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680342" comment="xen-libs-4.13.4_08-150200.3.50.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202126708" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-26708</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-26708" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26708" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-26708" ref_url="https://www.suse.com/security/cve/CVE-2021-26708" source="SUSE CVE"/>
    <description>
    A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-transport support.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-26708/">CVE-2021-26708</cve>
	<bugzilla href="https://bugzilla.suse.com/1181806">SUSE bug 1181806</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183298">SUSE bug 1183298</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202126930" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-26930</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-26930" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26930" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-26930" ref_url="https://www.suse.com/security/cve/CVE-2021-26930" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008683.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008687.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0393-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/R5J7TLH5AZYERG7B3PW3ALPYSBMFCGV5/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend, the driver maps grant references provided by the frontend. In this process, errors may be encountered. In one case, an error encountered earlier might be discarded by later processing, resulting in the caller assuming successful mapping, and hence subsequent operations trying to access space that wasn't mapped. In another case, internal state would be insufficiently updated, preventing safe recovery from the error. This affects drivers/block/xen-blkback/blkback.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-26930/">CVE-2021-26930</cve>
	<bugzilla href="https://bugzilla.suse.com/1181843">SUSE bug 1181843</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182294">SUSE bug 1182294</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705005" comment="kernel-default-5.3.18-24.52.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705006" comment="kernel-default-base-5.3.18-24.52.1.9.24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202126931" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-26931</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-26931" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26931" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-26931" ref_url="https://www.suse.com/security/cve/CVE-2021-26931" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008683.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008687.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0393-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/R5J7TLH5AZYERG7B3PW3ALPYSBMFCGV5/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (such as out of memory conditions), it isn't correct to assume a plain bug. Memory allocations potentially causing such crashes occur only when Linux is running in PV mode, though. This affects drivers/block/xen-blkback/blkback.c and drivers/xen/xen-scsiback.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-26931/">CVE-2021-26931</cve>
	<bugzilla href="https://bugzilla.suse.com/1181753">SUSE bug 1181753</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183022">SUSE bug 1183022</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705005" comment="kernel-default-5.3.18-24.52.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705006" comment="kernel-default-base-5.3.18-24.52.1.9.24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202126932" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-26932</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-26932" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26932" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-26932" ref_url="https://www.suse.com/security/cve/CVE-2021-26932" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0740-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0744-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0393-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/R5J7TLH5AZYERG7B3PW3ALPYSBMFCGV5/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failure of each one is reported to the backend driver, and the backend driver then loops over the results, performing follow-up actions based on the success or failure of each operation. Unfortunately, when running in PV mode, the Linux backend drivers mishandle this: Some errors are ignored, effectively implying their success from the success of related batch elements. In other cases, errors resulting from one batch element lead to further batch elements not being inspected, and hence successful ones to not be possible to properly unmap upon error recovery. Only systems with Linux backends running in PV mode are vulnerable. Linux backends run in HVM / PVH modes are not vulnerable. This affects arch/*/xen/p2m.c and drivers/xen/gntdev.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-26932/">CVE-2021-26932</cve>
	<bugzilla href="https://bugzilla.suse.com/1181747">SUSE bug 1181747</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705005" comment="kernel-default-5.3.18-24.52.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705006" comment="kernel-default-base-5.3.18-24.52.1.9.24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202126934" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-26934</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-26934" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26934" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-26934" ref_url="https://www.suse.com/security/cve/CVE-2021-26934" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration, but this wasn't stated accordingly in its support status entry.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-26934/">CVE-2021-26934</cve>
	<bugzilla href="https://bugzilla.suse.com/1181755">SUSE bug 1181755</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1185892">SUSE bug 1185892</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202127218" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-27218</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-27218" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27218" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-27218" ref_url="https://www.suse.com/security/cve/CVE-2021-27218" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008514.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008532.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0406-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CEADQWIHFVNLBWNNAJUQIPQTZZU5U5A4/" source="SUSE-SU"/>
    <description>
    An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-27218/">CVE-2021-27218</cve>
	<bugzilla href="https://bugzilla.suse.com/1182328">SUSE bug 1182328</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182362">SUSE bug 1182362</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705009" comment="glib2-tools-2.62.6-3.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705010" comment="libgio-2_0-0-2.62.6-3.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705011" comment="libglib-2_0-0-2.62.6-3.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705012" comment="libgmodule-2_0-0-2.62.6-3.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705013" comment="libgobject-2_0-0-2.62.6-3.6.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202127219" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-27219</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-27219" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27219" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-27219" ref_url="https://www.suse.com/security/cve/CVE-2021-27219" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008514.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008532.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0406-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CEADQWIHFVNLBWNNAJUQIPQTZZU5U5A4/" source="SUSE-SU"/>
    <description>
    An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2021-27219/">CVE-2021-27219</cve>
	<bugzilla href="https://bugzilla.suse.com/1182362">SUSE bug 1182362</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194015">SUSE bug 1194015</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705009" comment="glib2-tools-2.62.6-3.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705010" comment="libgio-2_0-0-2.62.6-3.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705011" comment="libglib-2_0-0-2.62.6-3.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705012" comment="libgmodule-2_0-0-2.62.6-3.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705013" comment="libgobject-2_0-0-2.62.6-3.6.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202127363" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-27363</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-27363" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27363" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-27363" ref_url="https://www.suse.com/security/cve/CVE-2021-27363" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1046-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1075-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1145-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008612.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at /sys/class/iscsi_transport/$TRANSPORT_NAME/handle. When read, the show_transport_handle function (in drivers/scsi/scsi_transport_iscsi.c) is called, which leaks the handle. This handle is actually the pointer to an iscsi_transport struct in the kernel module's global variables.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-27363/">CVE-2021-27363</cve>
	<bugzilla href="https://bugzilla.suse.com/1182716">SUSE bug 1182716</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182717">SUSE bug 1182717</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183120">SUSE bug 1183120</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200084">SUSE bug 1200084</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202127364" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-27364</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-27364" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27364" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-27364" ref_url="https://www.suse.com/security/cve/CVE-2021-27364" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1046-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1075-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1145-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008612.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-12"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-27364/">CVE-2021-27364</cve>
	<bugzilla href="https://bugzilla.suse.com/1182715">SUSE bug 1182715</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182716">SUSE bug 1182716</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182717">SUSE bug 1182717</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200084">SUSE bug 1200084</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1214268">SUSE bug 1214268</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202127365" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-27365</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-27365" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27365" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-27365" ref_url="https://www.suse.com/security/cve/CVE-2021-27365" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1046-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1075-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1145-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008612.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-27365/">CVE-2021-27365</cve>
	<bugzilla href="https://bugzilla.suse.com/1182712">SUSE bug 1182712</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182715">SUSE bug 1182715</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183491">SUSE bug 1183491</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200084">SUSE bug 1200084</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1214268">SUSE bug 1214268</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202127853" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-27853</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-27853" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27853" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-27853" ref_url="https://www.suse.com/security/cve/CVE-2021-27853" source="SUSE CVE"/>
    <description>
    Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-10"/>
	<updated date="2023-03-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-27853/">CVE-2021-27853</cve>
	<bugzilla href="https://bugzilla.suse.com/1203840">SUSE bug 1203840</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202127854" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-27854</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-27854" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27854" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-27854" ref_url="https://www.suse.com/security/cve/CVE-2021-27854" source="SUSE CVE"/>
    <description>
    Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-10"/>
	<updated date="2023-03-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-27854/">CVE-2021-27854</cve>
	<bugzilla href="https://bugzilla.suse.com/1203839">SUSE bug 1203839</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202127861" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-27861</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-27861" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27861" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-27861" ref_url="https://www.suse.com/security/cve/CVE-2021-27861" source="SUSE CVE"/>
    <description>
    Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers)
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-10"/>
	<updated date="2023-03-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-27861/">CVE-2021-27861</cve>
	<bugzilla href="https://bugzilla.suse.com/1203838">SUSE bug 1203838</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202127862" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-27862</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-27862" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27862" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-27862" ref_url="https://www.suse.com/security/cve/CVE-2021-27862" source="SUSE CVE"/>
    <description>
    Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length and Ethernet to Wifi frame conversion (and optionally VLAN0 headers).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-10"/>
	<updated date="2023-03-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-27862/">CVE-2021-27862</cve>
	<bugzilla href="https://bugzilla.suse.com/1182623">SUSE bug 1182623</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1203837">SUSE bug 1203837</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128038" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28038</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28038" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28038" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28038" ref_url="https://www.suse.com/security/cve/CVE-2021-28038" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a networking frontend driver. NOTE: this issue exists because of an incomplete fix for CVE-2021-26931.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28038/">CVE-2021-28038</cve>
	<bugzilla href="https://bugzilla.suse.com/1183022">SUSE bug 1183022</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183069">SUSE bug 1183069</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128039" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28039</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28039" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28039" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28039" ref_url="https://www.suse.com/security/cve/CVE-2021-28039" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has CONFIG_XEN_UNPOPULATED_ALLOC but not CONFIG_XEN_BALLOON_MEMORY_HOTPLUG.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28039/">CVE-2021-28039</cve>
	<bugzilla href="https://bugzilla.suse.com/1183035">SUSE bug 1183035</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183071">SUSE bug 1183071</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128041" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28041</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28041" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28041" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28041" ref_url="https://www.suse.com/security/cve/CVE-2021-28041" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4153-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009929.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:4153-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YUBQLVRKYJRPQIBMWLSE4P7CEU335GGW/" source="SUSE-SU"/>
    <description>
    ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28041/">CVE-2021-28041</cve>
	<bugzilla href="https://bugzilla.suse.com/1183137">SUSE bug 1183137</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333996" comment="openssh is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128153" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28153</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28153" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28153" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28153" ref_url="https://www.suse.com/security/cve/CVE-2021-28153" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:795-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:804-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010868.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010869.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010870.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:815-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010873.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010874.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010875.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:821-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010876.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010878.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010879.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:833-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-April/022888.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:224-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:225-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013569.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2868-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:500-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:501-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013939.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013942.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013943.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:509-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:510-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013948.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:511-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1455-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1758-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1758-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3535-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016101.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-08"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-28153/">CVE-2021-28153</cve>
	<bugzilla href="https://bugzilla.suse.com/1183533">SUSE bug 1183533</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705027" comment="glib2-tools-2.62.6-150200.3.9.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705028" comment="libgio-2_0-0-2.62.6-150200.3.9.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705029" comment="libglib-2_0-0-2.62.6-150200.3.9.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705030" comment="libgmodule-2_0-0-2.62.6-150200.3.9.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705031" comment="libgobject-2_0-0-2.62.6-150200.3.9.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128375" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28375</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28375" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28375" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28375" ref_url="https://www.suse.com/security/cve/CVE-2021-28375" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28375/">CVE-2021-28375</cve>
	<bugzilla href="https://bugzilla.suse.com/1183596">SUSE bug 1183596</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1184955">SUSE bug 1184955</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128660" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28660</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28660" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28660" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28660" ref_url="https://www.suse.com/security/cve/CVE-2021-28660" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1395-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008686.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the -&gt;ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have situations in which a drivers/staging issue is relevant to their own customer base.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8/CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28660/">CVE-2021-28660</cve>
	<bugzilla href="https://bugzilla.suse.com/1183593">SUSE bug 1183593</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183658">SUSE bug 1183658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128687" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28687</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28687" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28687" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28687" ref_url="https://www.suse.com/security/cve/CVE-2021-28687" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1023-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1028-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008586.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1460-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008718.html" source="SUSE-SU"/>
    <description>
    HVM soft-reset crashes toolstack libxl requires all data structures passed across its public interface to be initialized before use and disposed of afterwards by calling a specific set of functions. Many internal data structures also require this initialize / dispose discipline, but not all of them. When the "soft reset" feature was implemented, the libxl__domain_suspend_state structure didn't require any initialization or disposal. At some point later, an initialization function was introduced for the structure; but the "soft reset" path wasn't refactored to call the initialization function. When a guest nwo initiates a "soft reboot", uninitialized data structure leads to an assert() when later code finds the structure in an unexpected state. The effect of this is to crash the process monitoring the guest. How this affects the system depends on the structure of the toolstack. For xl, this will have no security-relevant effect: every VM has its own independent monitoring process, which contains no state. The domain in question will hang in a crashed state, but can be destroyed by `xl destroy` just like any other non-cooperating domain. For daemon-based toolstacks linked against libxl, such as libvirt, this will crash the toolstack, losing the state of any in-progress operations (localized DoS), and preventing further administrator operations unless the daemon is configured to restart automatically (system-wide DoS). If crashes "leak" resources, then repeated crashes could use up resources, also causing a system-wide DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28687/">CVE-2021-28687</cve>
	<bugzilla href="https://bugzilla.suse.com/1183072">SUSE bug 1183072</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009493665" comment="xen-libs-4.13.2_08-3.25.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128688" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28688</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28688" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28688" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28688" ref_url="https://www.suse.com/security/cve/CVE-2021-28688" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1341-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008683.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008685.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1395-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008686.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2026-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009359.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4052-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009897.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0668-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010328.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1003-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in need of cleaning up. The lack of cleanup would result in leaking persistent grants. The leak in turn would prevent fully cleaning up after a respective guest has died, leaving around zombie domains. All Linux versions having the fix for XSA-365 applied are vulnerable. XSA-365 was classified to affect versions back to at least 3.11.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28688/">CVE-2021-28688</cve>
	<bugzilla href="https://bugzilla.suse.com/1183646">SUSE bug 1183646</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128690" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28690</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28690" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28690" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28690" ref_url="https://www.suse.com/security/cve/CVE-2021-28690" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYJVCSKTOQY75TLGWH3HDYZAS33JTOTQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JLC632KAG76ZVELO6CCNNSZVUXPDVXOQ/" source="SUSE-SU"/>
    <description>
    x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vulnerability. Please see https://xenbits.xen.org/xsa/advisory-305.html for details. Mitigating TAA by disabling TSX (the default and preferred option) requires selecting a non-default setting in MSR_TSX_CTRL. This setting isn't restored after S3 suspend.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-28690/">CVE-2021-28690</cve>
	<bugzilla href="https://bugzilla.suse.com/1186434">SUSE bug 1186434</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632243" comment="xen-libs-4.13.3_02-3.34.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128691" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28691</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28691" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28691" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28691" ref_url="https://www.suse.com/security/cve/CVE-2021-28691" source="SUSE CVE"/>
    <description>
    Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed, as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28691/">CVE-2021-28691</cve>
	<bugzilla href="https://bugzilla.suse.com/1186430">SUSE bug 1186430</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128692" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28692</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28692" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28692" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28692" ref_url="https://www.suse.com/security/cve/CVE-2021-28692" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYJVCSKTOQY75TLGWH3HDYZAS33JTOTQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JLC632KAG76ZVELO6CCNNSZVUXPDVXOQ/" source="SUSE-SU"/>
    <description>
    inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some of these waiting loops try to apply a timeout to fail overly-slow commands. The course of action upon a perceived timeout actually being detected is inappropriate: - on Intel hardware guests which did not originally cause the timeout may be marked as crashed, - on AMD hardware higher layer callers would not be notified of the issue, making them continue as if the IOMMU operation succeeded.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-28692/">CVE-2021-28692</cve>
	<bugzilla href="https://bugzilla.suse.com/1186429">SUSE bug 1186429</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632243" comment="xen-libs-4.13.3_02-3.34.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128693" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28693</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28693" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28693" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28693" ref_url="https://www.suse.com/security/cve/CVE-2021-28693" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009395.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYJVCSKTOQY75TLGWH3HDYZAS33JTOTQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JLC632KAG76ZVELO6CCNNSZVUXPDVXOQ/" source="SUSE-SU"/>
    <description>
    xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. To ensure sensitive data is not leaked from the modules, Xen must "scrub" them before handing the page over to the allocator. Unfortunately, it was discovered that modules will not be scrubbed on Arm.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-28693/">CVE-2021-28693</cve>
	<bugzilla href="https://bugzilla.suse.com/1186428">SUSE bug 1186428</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632243" comment="xen-libs-4.13.3_02-3.34.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128694" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28694</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28694" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28694" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28694" ref_url="https://www.suse.com/security/cve/CVE-2021-28694" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYJVCSKTOQY75TLGWH3HDYZAS33JTOTQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JLC632KAG76ZVELO6CCNNSZVUXPDVXOQ/" source="SUSE-SU"/>
    <description>
    IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these are typically device specific ACPI properties, they can also be specified to apply to a range of devices, or even all devices. On all systems with such regions Xen failed to prevent guests from undoing/replacing such mappings (CVE-2021-28694). On AMD systems, where a discontinuous range is specified by firmware, the supposedly-excluded middle range will also be identity-mapped (CVE-2021-28695). Further, on AMD systems, upon de-assigment of a physical device from a guest, the identity mappings would be left in place, allowing a guest continued access to ranges of memory which it shouldn't have access to anymore (CVE-2021-28696).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28694/">CVE-2021-28694</cve>
	<bugzilla href="https://bugzilla.suse.com/1189373">SUSE bug 1189373</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189980">SUSE bug 1189980</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632243" comment="xen-libs-4.13.3_02-3.34.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128695" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28695</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28695" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28695" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28695" ref_url="https://www.suse.com/security/cve/CVE-2021-28695" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYJVCSKTOQY75TLGWH3HDYZAS33JTOTQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JLC632KAG76ZVELO6CCNNSZVUXPDVXOQ/" source="SUSE-SU"/>
    <description>
    IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these are typically device specific ACPI properties, they can also be specified to apply to a range of devices, or even all devices. On all systems with such regions Xen failed to prevent guests from undoing/replacing such mappings (CVE-2021-28694). On AMD systems, where a discontinuous range is specified by firmware, the supposedly-excluded middle range will also be identity-mapped (CVE-2021-28695). Further, on AMD systems, upon de-assigment of a physical device from a guest, the identity mappings would be left in place, allowing a guest continued access to ranges of memory which it shouldn't have access to anymore (CVE-2021-28696).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28695/">CVE-2021-28695</cve>
	<bugzilla href="https://bugzilla.suse.com/1189373">SUSE bug 1189373</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189980">SUSE bug 1189980</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632243" comment="xen-libs-4.13.3_02-3.34.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128696" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28696</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28696" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28696" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28696" ref_url="https://www.suse.com/security/cve/CVE-2021-28696" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYJVCSKTOQY75TLGWH3HDYZAS33JTOTQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JLC632KAG76ZVELO6CCNNSZVUXPDVXOQ/" source="SUSE-SU"/>
    <description>
    IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these are typically device specific ACPI properties, they can also be specified to apply to a range of devices, or even all devices. On all systems with such regions Xen failed to prevent guests from undoing/replacing such mappings (CVE-2021-28694). On AMD systems, where a discontinuous range is specified by firmware, the supposedly-excluded middle range will also be identity-mapped (CVE-2021-28695). Further, on AMD systems, upon de-assigment of a physical device from a guest, the identity mappings would be left in place, allowing a guest continued access to ranges of memory which it shouldn't have access to anymore (CVE-2021-28696).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28696/">CVE-2021-28696</cve>
	<bugzilla href="https://bugzilla.suse.com/1189373">SUSE bug 1189373</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189980">SUSE bug 1189980</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632243" comment="xen-libs-4.13.3_02-3.34.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128697" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28697</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28697" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28697" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28697" ref_url="https://www.suse.com/security/cve/CVE-2021-28697" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYJVCSKTOQY75TLGWH3HDYZAS33JTOTQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JLC632KAG76ZVELO6CCNNSZVUXPDVXOQ/" source="SUSE-SU"/>
    <description>
    grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, get de-allocated when a guest switched (back) from v2 to v1. The freeing of such pages requires that the hypervisor know where in the guest these pages were mapped. The hypervisor tracks only one use within guest space, but racing requests from the guest to insert mappings of these pages may result in any of them to become mapped in multiple locations. Upon switching back from v2 to v1, the guest would then retain access to a page that was freed and perhaps re-used for other purposes.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28697/">CVE-2021-28697</cve>
	<bugzilla href="https://bugzilla.suse.com/1189376">SUSE bug 1189376</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632243" comment="xen-libs-4.13.3_02-3.34.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128698" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28698</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28698" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28698" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28698" ref_url="https://www.suse.com/security/cve/CVE-2021-28698" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYJVCSKTOQY75TLGWH3HDYZAS33JTOTQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JLC632KAG76ZVELO6CCNNSZVUXPDVXOQ/" source="SUSE-SU"/>
    <description>
    long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the grant mappings a domain may create to map grants offered by other domains. In the process of carrying out certain actions, Xen would iterate over all such entries, including ones which aren't in use anymore and some which may have been created but never used. If the number of entries for a given domain is large enough, this iterating of the entire table may tie up a CPU for too long, starving other domains or causing issues in the hypervisor itself. Note that a domain may map its own grants, i.e. there is no need for multiple domains to be involved here. A pair of "cooperating" guests may, however, cause the effects to be more severe.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28698/">CVE-2021-28698</cve>
	<bugzilla href="https://bugzilla.suse.com/1189378">SUSE bug 1189378</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632243" comment="xen-libs-4.13.3_02-3.34.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128699" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28699</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28699" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28699" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28699" ref_url="https://www.suse.com/security/cve/CVE-2021-28699" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2943-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYJVCSKTOQY75TLGWH3HDYZAS33JTOTQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JLC632KAG76ZVELO6CCNNSZVUXPDVXOQ/" source="SUSE-SU"/>
    <description>
    inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant status. That is, when operating in this mode, a guest has two tables. As a result, guests also need to be able to retrieve the addresses that the new status tracking table can be accessed through. For 32-bit guests on x86, translation of requests has to occur because the interface structure layouts commonly differ between 32- and 64-bit. The translation of the request to obtain the frame numbers of the grant status table involves translating the resulting array of frame numbers. Since the space used to carry out the translation is limited, the translation layer tells the core function the capacity of the array within translation space. Unfortunately the core function then only enforces array bounds to be below 8 times the specified value, and would write past the available space if enough frame numbers needed storing.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28699/">CVE-2021-28699</cve>
	<bugzilla href="https://bugzilla.suse.com/1189380">SUSE bug 1189380</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194306">SUSE bug 1194306</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632243" comment="xen-libs-4.13.3_02-3.34.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128700" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28700</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28700" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28700" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28700" ref_url="https://www.suse.com/security/cve/CVE-2021-28700" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2925-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009395.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1236-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VYJVCSKTOQY75TLGWH3HDYZAS33JTOTQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2923-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JLC632KAG76ZVELO6CCNNSZVUXPDVXOQ/" source="SUSE-SU"/>
    <description>
    xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond what an administrator originally configured.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28700/">CVE-2021-28700</cve>
	<bugzilla href="https://bugzilla.suse.com/1189381">SUSE bug 1189381</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009632243" comment="xen-libs-4.13.3_02-3.34.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128701" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28701</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28701" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28701" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28701" ref_url="https://www.suse.com/security/cve/CVE-2021-28701" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009464.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3140-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009643.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009874.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1301-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YOWOZIQD7FWDNFL7CQF3WO5KZFKYYTDP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3140-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W4HJ2XF2SFYPRBAICENTSEBE5KO7OY2G/" source="SUSE-SU"/>
    <description>
    Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, are de-allocated when a guest switches (back) from v2 to v1. Freeing such pages requires that the hypervisor enforce that no parallel request can result in the addition of a mapping of such a page to a guest. That enforcement was missing, allowing guests to retain access to pages that were freed and perhaps re-used for other purposes. Unfortunately, when XSA-379 was being prepared, this similar issue was not noticed.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28701/">CVE-2021-28701</cve>
	<bugzilla href="https://bugzilla.suse.com/1189632">SUSE bug 1189632</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633428" comment="xen-libs-4.13.3_04-3.37.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128702" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28702</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28702" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28702" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28702" ref_url="https://www.suse.com/security/cve/CVE-2021-28702" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009796.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3968-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009870.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009874.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1543-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HUTTCXZ3RCSXYS25JPMTEXNGYRSDKJ26/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3968-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ELAKLWY4EZXSLS4BS47VPF2URIP3BLNK/" source="SUSE-SU"/>
    <description>
    PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR"). These are typically used for platform tasks such as legacy USB emulation. If such a device is passed through to a guest, then on guest shutdown the device is not properly deassigned. The IOMMU configuration for these devices which are not properly deassigned ends up pointing to a freed data structure, including the IO Pagetables. Subsequent DMA or interrupts from the device will have unpredictable behaviour, ranging from IOMMU faults to memory corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28702/">CVE-2021-28702</cve>
	<bugzilla href="https://bugzilla.suse.com/1191363">SUSE bug 1191363</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658528" comment="xen-libs-4.13.4_02-3.40.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128703" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28703</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28703" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28703" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28703" ref_url="https://www.suse.com/security/cve/CVE-2021-28703" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
    <description>
    grant table v2 status pages may remain accessible after de-allocation (take two) Guest get permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, get de-allocated when a guest switched (back) from v2 to v1. The freeing of such pages requires that the hypervisor know where in the guest these pages were mapped. The hypervisor tracks only one use within guest space, but racing requests from the guest to insert mappings of these pages may result in any of them to become mapped in multiple locations. Upon switching back from v2 to v1, the guest would then retain access to a page that was freed and perhaps re-used for other purposes. This bug was fortuitously fixed by code cleanup in Xen 4.14, and backported to security-supported Xen branches as a prerequisite of the fix for XSA-378.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28703/">CVE-2021-28703</cve>
	<bugzilla href="https://bugzilla.suse.com/1192555">SUSE bug 1192555</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128704" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28704</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28704" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28704" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28704" ref_url="https://www.suse.com/security/cve/CVE-2021-28704" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009783.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009796.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3968-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009870.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009874.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1543-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HUTTCXZ3RCSXYS25JPMTEXNGYRSDKJ26/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3968-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ELAKLWY4EZXSLS4BS47VPF2URIP3BLNK/" source="SUSE-SU"/>
    <description>
    PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). The implementation of some of these hypercalls for PoD does not enforce the base page frame number to be suitably aligned for the specified order, yet some code involved in PoD handling actually makes such an assumption. These operations are XENMEM_decrease_reservation (CVE-2021-28704) and XENMEM_populate_physmap (CVE-2021-28707), the latter usable only by domains controlling the guest, i.e. a de-privileged qemu or a stub domain. (Patch 1, combining the fix to both these two issues.) In addition handling of XENMEM_decrease_reservation can also trigger a host crash when the specified page order is neither 4k nor 2M nor 1G (CVE-2021-28708, patch 2).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28704/">CVE-2021-28704</cve>
	<bugzilla href="https://bugzilla.suse.com/1192557">SUSE bug 1192557</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658528" comment="xen-libs-4.13.4_02-3.40.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128705" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28705</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28705" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28705" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28705" ref_url="https://www.suse.com/security/cve/CVE-2021-28705" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009783.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009796.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3968-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009870.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009874.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1543-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HUTTCXZ3RCSXYS25JPMTEXNGYRSDKJ26/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3968-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ELAKLWY4EZXSLS4BS47VPF2URIP3BLNK/" source="SUSE-SU"/>
    <description>
    issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). In some cases the hypervisor carries out the requests by splitting them into smaller chunks. Error handling in certain PoD cases has been insufficient in that in particular partial success of some operations was not properly accounted for. There are two code paths affected - page removal (CVE-2021-28705) and insertion of new pages (CVE-2021-28709). (We provide one patch which combines the fix to both issues.)
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28705/">CVE-2021-28705</cve>
	<bugzilla href="https://bugzilla.suse.com/1192559">SUSE bug 1192559</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658528" comment="xen-libs-4.13.4_02-3.40.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128706" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28706</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28706" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28706" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28706" ref_url="https://www.suse.com/security/cve/CVE-2021-28706" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009783.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009796.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3968-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009870.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009874.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1543-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HUTTCXZ3RCSXYS25JPMTEXNGYRSDKJ26/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3968-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ELAKLWY4EZXSLS4BS47VPF2URIP3BLNK/" source="SUSE-SU"/>
    <description>
    guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28706/">CVE-2021-28706</cve>
	<bugzilla href="https://bugzilla.suse.com/1192554">SUSE bug 1192554</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658528" comment="xen-libs-4.13.4_02-3.40.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128707" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28707</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28707" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28707" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28707" ref_url="https://www.suse.com/security/cve/CVE-2021-28707" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009783.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009796.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3968-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009870.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009874.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1543-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HUTTCXZ3RCSXYS25JPMTEXNGYRSDKJ26/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3968-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ELAKLWY4EZXSLS4BS47VPF2URIP3BLNK/" source="SUSE-SU"/>
    <description>
    PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). The implementation of some of these hypercalls for PoD does not enforce the base page frame number to be suitably aligned for the specified order, yet some code involved in PoD handling actually makes such an assumption. These operations are XENMEM_decrease_reservation (CVE-2021-28704) and XENMEM_populate_physmap (CVE-2021-28707), the latter usable only by domains controlling the guest, i.e. a de-privileged qemu or a stub domain. (Patch 1, combining the fix to both these two issues.) In addition handling of XENMEM_decrease_reservation can also trigger a host crash when the specified page order is neither 4k nor 2M nor 1G (CVE-2021-28708, patch 2).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28707/">CVE-2021-28707</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658528" comment="xen-libs-4.13.4_02-3.40.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128708" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28708</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28708" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28708" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28708" ref_url="https://www.suse.com/security/cve/CVE-2021-28708" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009783.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009796.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3968-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009870.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009874.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1543-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HUTTCXZ3RCSXYS25JPMTEXNGYRSDKJ26/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3968-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ELAKLWY4EZXSLS4BS47VPF2URIP3BLNK/" source="SUSE-SU"/>
    <description>
    PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). The implementation of some of these hypercalls for PoD does not enforce the base page frame number to be suitably aligned for the specified order, yet some code involved in PoD handling actually makes such an assumption. These operations are XENMEM_decrease_reservation (CVE-2021-28704) and XENMEM_populate_physmap (CVE-2021-28707), the latter usable only by domains controlling the guest, i.e. a de-privileged qemu or a stub domain. (Patch 1, combining the fix to both these two issues.) In addition handling of XENMEM_decrease_reservation can also trigger a host crash when the specified page order is neither 4k nor 2M nor 1G (CVE-2021-28708, patch 2).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28708/">CVE-2021-28708</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658528" comment="xen-libs-4.13.4_02-3.40.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128709" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28709</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28709" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28709" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28709" ref_url="https://www.suse.com/security/cve/CVE-2021-28709" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009794.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009783.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009796.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3968-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009870.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009874.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1543-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HUTTCXZ3RCSXYS25JPMTEXNGYRSDKJ26/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3968-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ELAKLWY4EZXSLS4BS47VPF2URIP3BLNK/" source="SUSE-SU"/>
    <description>
    issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). In some cases the hypervisor carries out the requests by splitting them into smaller chunks. Error handling in certain PoD cases has been insufficient in that in particular partial success of some operations was not properly accounted for. There are two code paths affected - page removal (CVE-2021-28705) and insertion of new pages (CVE-2021-28709). (We provide one patch which combines the fix to both issues.)
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28709/">CVE-2021-28709</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658528" comment="xen-libs-4.13.4_02-3.40.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128710" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28710</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28710" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28710" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28710" ref_url="https://www.suse.com/security/cve/CVE-2021-28710" source="SUSE CVE"/>
    <description>
    certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on suitable hardware, by default will) be shared between CPUs, for second-level translation (EPT), and IOMMUs. These page tables are presently set up to always be 4 levels deep. However, an IOMMU may require the use of just 3 page table levels. In such a configuration the lop level table needs to be stripped before inserting the root table's address into the hardware pagetable base register. When sharing page tables, Xen erroneously skipped this stripping. Consequently, the guest is able to write to leaf page table entries.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28710/">CVE-2021-28710</cve>
	<bugzilla href="https://bugzilla.suse.com/1192888">SUSE bug 1192888</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128711" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28711</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28711" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28711" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28711" ref_url="https://www.suse.com/security/cve/CVE-2021-28711" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one primary security advantage: if a driver domain gets compromised, it doesn't have the privileges to take over the system. However, a malicious driver domain could try to attack other guests via sending events at a high frequency leading to a Denial of Service in the guest due to trying to service interrupts for elongated amounts of time. There are three affected backends: * blkfront patch 1, CVE-2021-28711 * netfront patch 2, CVE-2021-28712 * hvc_xen (console) patch 3, CVE-2021-28713
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28711/">CVE-2021-28711</cve>
	<bugzilla href="https://bugzilla.suse.com/1193440">SUSE bug 1193440</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658985" comment="kernel-rt-5.3.18-65.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128712" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28712</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28712" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28712" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28712" ref_url="https://www.suse.com/security/cve/CVE-2021-28712" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one primary security advantage: if a driver domain gets compromised, it doesn't have the privileges to take over the system. However, a malicious driver domain could try to attack other guests via sending events at a high frequency leading to a Denial of Service in the guest due to trying to service interrupts for elongated amounts of time. There are three affected backends: * blkfront patch 1, CVE-2021-28711 * netfront patch 2, CVE-2021-28712 * hvc_xen (console) patch 3, CVE-2021-28713
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28712/">CVE-2021-28712</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658985" comment="kernel-rt-5.3.18-65.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128713" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28713</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28713" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28713" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28713" ref_url="https://www.suse.com/security/cve/CVE-2021-28713" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one primary security advantage: if a driver domain gets compromised, it doesn't have the privileges to take over the system. However, a malicious driver domain could try to attack other guests via sending events at a high frequency leading to a Denial of Service in the guest due to trying to service interrupts for elongated amounts of time. There are three affected backends: * blkfront patch 1, CVE-2021-28711 * netfront patch 2, CVE-2021-28712 * hvc_xen (console) patch 3, CVE-2021-28713
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28713/">CVE-2021-28713</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658985" comment="kernel-rt-5.3.18-65.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128714" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28714</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28714" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28714" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28714" ref_url="https://www.suse.com/security/cve/CVE-2021-28714" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's netback driver are buffered until the guest is ready to process them. There are some measures taken for avoiding to pile up too much data, but those can be bypassed by the guest: There is a timeout how long the client side of an interface can stop consuming new packets before it is assumed to have stalled, but this timeout is rather long (60 seconds by default). Using a UDP connection on a fast interface can easily accumulate gigabytes of data in that time. (CVE-2021-28715) The timeout could even never trigger if the guest manages to have only one free slot in its RX queue ring page and the next package would require more than one free slot, which may be the case when using GSO, XDP, or software hashing. (CVE-2021-28714)
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28714/">CVE-2021-28714</cve>
	<bugzilla href="https://bugzilla.suse.com/1193442">SUSE bug 1193442</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658985" comment="kernel-rt-5.3.18-65.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128715" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28715</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28715" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28715" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28715" ref_url="https://www.suse.com/security/cve/CVE-2021-28715" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's netback driver are buffered until the guest is ready to process them. There are some measures taken for avoiding to pile up too much data, but those can be bypassed by the guest: There is a timeout how long the client side of an interface can stop consuming new packets before it is assumed to have stalled, but this timeout is rather long (60 seconds by default). Using a UDP connection on a fast interface can easily accumulate gigabytes of data in that time. (CVE-2021-28715) The timeout could even never trigger if the guest manages to have only one free slot in its RX queue ring page and the next package would require more than one free slot, which may be the case when using GSO, XDP, or software hashing. (CVE-2021-28714)
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28715/">CVE-2021-28715</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658985" comment="kernel-rt-5.3.18-65.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128950" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28950</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28950" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28950" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28950" ref_url="https://www.suse.com/security/cve/CVE-2021-28950" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1572-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/018906.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008769.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28950/">CVE-2021-28950</cve>
	<bugzilla href="https://bugzilla.suse.com/1184194">SUSE bug 1184194</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1184211">SUSE bug 1184211</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128951" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28951</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28951" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28951" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28951" ref_url="https://www.suse.com/security/cve/CVE-2021-28951" source="SUSE CVE"/>
    <description>
    An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread, but concurrently that SQPOLL thread is waiting for a signal to start, aka CID-3ebba796fa25.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28951/">CVE-2021-28951</cve>
	<bugzilla href="https://bugzilla.suse.com/1184195">SUSE bug 1184195</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128952" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28952</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28952" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28952" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28952" ref_url="https://www.suse.com/security/cve/CVE-2021-28952" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28952/">CVE-2021-28952</cve>
	<bugzilla href="https://bugzilla.suse.com/1184197">SUSE bug 1184197</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1184199">SUSE bug 1184199</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128964" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28964</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28964" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28964" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28964" ref_url="https://www.suse.com/security/cve/CVE-2021-28964" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28964/">CVE-2021-28964</cve>
	<bugzilla href="https://bugzilla.suse.com/1184193">SUSE bug 1184193</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128965" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28965</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28965" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28965" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28965" ref_url="https://www.suse.com/security/cve/CVE-2021-28965" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008665.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0607-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CMW3G6JZK6A7ZRJZ7VOMELHWOQBYPIOY/" source="SUSE-SU"/>
    <description>
    The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-28965/">CVE-2021-28965</cve>
	<bugzilla href="https://bugzilla.suse.com/1184644">SUSE bug 1184644</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704861" comment="libruby2_5-2_5-2.5.9-4.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704862" comment="ruby2.5-2.5.9-4.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704863" comment="ruby2.5-stdlib-2.5.9-4.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128971" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28971</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28971" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28971" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28971" ref_url="https://www.suse.com/security/cve/CVE-2021-28971" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-28971/">CVE-2021-28971</cve>
	<bugzilla href="https://bugzilla.suse.com/1184196">SUSE bug 1184196</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202128972" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-28972</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-28972" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28972" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-28972" ref_url="https://www.suse.com/security/cve/CVE-2021-28972" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination, aka CID-cc7a0bb058b8.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-28972/">CVE-2021-28972</cve>
	<bugzilla href="https://bugzilla.suse.com/1184198">SUSE bug 1184198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202129154" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-29154</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-29154" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29154" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-29154" ref_url="https://www.suse.com/security/cve/CVE-2021-29154" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1248-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1715-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008815.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1724-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008814.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1865-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008939.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1870-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-29154/">CVE-2021-29154</cve>
	<bugzilla href="https://bugzilla.suse.com/1184391">SUSE bug 1184391</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1184710">SUSE bug 1184710</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186408">SUSE bug 1186408</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202129155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-29155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-29155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29155" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-29155" ref_url="https://www.suse.com/security/cve/CVE-2021-29155" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1571-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1572-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/018906.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008767.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008769.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1622-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0716-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VDF7UBOVWJVCBDNJIGAY445AXZJU4OOD/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0873-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/THW3Z3CCX5HRFD2KJ3A4TDO27FGBEKNN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory. Specifically, for sequences of pointer arithmetic operations, the pointer modification performed by the first operation is not correctly accounted for when restricting subsequent operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-29155/">CVE-2021-29155</cve>
	<bugzilla href="https://bugzilla.suse.com/1184942">SUSE bug 1184942</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704870" comment="kernel-default-5.3.18-24.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704871" comment="kernel-default-base-5.3.18-24.64.1.9.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498544" comment="kernel-rt-5.3.18-8.10.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202129264" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-29264</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-29264" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29264" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-29264" ref_url="https://www.suse.com/security/cve/CVE-2021-29264" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.11.10. drivers/net/ethernet/freescale/gianfar.c in the Freescale Gianfar Ethernet driver allows attackers to cause a system crash because a negative fragment size is calculated in situations involving an rx queue overrun when jumbo packets are used and NAPI is enabled, aka CID-d8861bab48b6.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-29264/">CVE-2021-29264</cve>
	<bugzilla href="https://bugzilla.suse.com/1184168">SUSE bug 1184168</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202129265" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-29265</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-29265" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29265" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-29265" ref_url="https://www.suse.com/security/cve/CVE-2021-29265" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.11.7. usbip_sockfd_store in drivers/usb/usbip/stub_dev.c allows attackers to cause a denial of service (GPF) because the stub-up sequence has race conditions during an update of the local and shared status, aka CID-9380afd6df70.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-29265/">CVE-2021-29265</cve>
	<bugzilla href="https://bugzilla.suse.com/1184167">SUSE bug 1184167</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202129266" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-29266</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-29266" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29266" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-29266" ref_url="https://www.suse.com/security/cve/CVE-2021-29266" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v-&gt;config_ctx has an invalid value upon re-opening a character device, aka CID-f6bbf0010ba0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-29266/">CVE-2021-29266</cve>
	<bugzilla href="https://bugzilla.suse.com/1184166">SUSE bug 1184166</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202129646" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-29646</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-29646" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29646" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-29646" ref_url="https://www.suse.com/security/cve/CVE-2021-29646" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly validate certain data sizes, aka CID-0217ed2848e8.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-29646/">CVE-2021-29646</cve>
	<bugzilla href="https://bugzilla.suse.com/1184191">SUSE bug 1184191</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202129647" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-29647</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-29647" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29647" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-29647" ref_url="https://www.suse.com/security/cve/CVE-2021-29647" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-29647/">CVE-2021-29647</cve>
	<bugzilla href="https://bugzilla.suse.com/1184192">SUSE bug 1184192</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202129648" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-29648</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-29648" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29648" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-29648" ref_url="https://www.suse.com/security/cve/CVE-2021-29648" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in the vmlinux BPF Type Format (BTF), which can cause a system crash upon an unexpected access attempt (in map_create in kernel/bpf/syscall.c or check_btf_info in kernel/bpf/verifier.c), aka CID-350a5c4dd245.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-29648/">CVE-2021-29648</cve>
	<bugzilla href="https://bugzilla.suse.com/1184200">SUSE bug 1184200</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202129649" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-29649</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-29649" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29649" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-29649" ref_url="https://www.suse.com/security/cve/CVE-2021-29649" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak, related to a lack of cleanup steps in kernel/usermode_driver.c and kernel/bpf/preload/bpf_preload_kern.c, aka CID-f60a85cad677.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-29649/">CVE-2021-29649</cve>
	<bugzilla href="https://bugzilla.suse.com/1184205">SUSE bug 1184205</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202129650" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-29650</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-29650" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29650" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-29650" ref_url="https://www.suse.com/security/cve/CVE-2021-29650" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1571-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1572-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/018906.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008767.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008769.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008775.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1622-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008971.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2611-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2651-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030079.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0716-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VDF7UBOVWJVCBDNJIGAY445AXZJU4OOD/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0873-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/THW3Z3CCX5HRFD2KJ3A4TDO27FGBEKNN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assignment of a new table value, aka CID-175e476b8cdf.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-29650/">CVE-2021-29650</cve>
	<bugzilla href="https://bugzilla.suse.com/1184208">SUSE bug 1184208</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704870" comment="kernel-default-5.3.18-24.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704871" comment="kernel-default-base-5.3.18-24.64.1.9.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498544" comment="kernel-rt-5.3.18-8.10.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202129657" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-29657</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-29657" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29657" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-29657" ref_url="https://www.suse.com/security/cve/CVE-2021-29657" source="SUSE CVE"/>
    <description>
    arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass access control on host OS MSRs when there are nested guests, aka CID-a58d9166a756. This occurs because of a TOCTOU race condition associated with a VMCB12 double fetch in nested_svm_vmrun.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-29657/">CVE-2021-29657</cve>
	<bugzilla href="https://bugzilla.suse.com/1188637">SUSE bug 1188637</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202130002" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-30002</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-30002" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30002" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-30002" ref_url="https://www.suse.com/security/cve/CVE-2021-30002" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1248-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-30002/">CVE-2021-30002</cve>
	<bugzilla href="https://bugzilla.suse.com/1184120">SUSE bug 1184120</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202130004" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-30004</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-30004" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30004" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-30004" ref_url="https://www.suse.com/security/cve/CVE-2021-30004" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:1125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008610.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1166-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008618.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0519-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EXT3Y5NEGCCPGZ7FTYURPUBTHNNJA6MF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0545-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7GHTARPJSUMITH7M3ESWRIZUIYW5UAM6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0563-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4XPNZHCXJ32COQGQ62HNGD6DHPO5E552/" source="SUSE-SU"/>
    <description>
    In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-30004/">CVE-2021-30004</cve>
	<bugzilla href="https://bugzilla.suse.com/1184348">SUSE bug 1184348</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704856" comment="wpa_supplicant-2.9-4.29.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202130178" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-30178</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-30178" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30178" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-30178" ref_url="https://www.suse.com/security/cve/CVE-2021-30178" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context, aka CID-919f4ebc5987.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-30178/">CVE-2021-30178</cve>
	<bugzilla href="https://bugzilla.suse.com/1184499">SUSE bug 1184499</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202130465" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-30465</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-30465" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30465" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-30465" ref_url="https://www.suse.com/security/cve/CVE-2021-30465" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1885-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009645.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0878-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/G76UZ7FY6VFG73EC6UUCBE46L3TAKR6G/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1404-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L7ADRJZ4HKOCVZC5ZKIM4MD6EZEHBNB3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1954-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OX775QFGRPXXX7W5FDFKP3V5KCNZYD7F/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3506-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NP4XGHFKECRFSI6UYXER53KXVGP66EHQ/" source="SUSE-SU"/>
    <description>
    runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-30465/">CVE-2021-30465</cve>
	<bugzilla href="https://bugzilla.suse.com/1185405">SUSE bug 1185405</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189161">SUSE bug 1189161</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009651737" comment="containerd-1.4.11-56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651738" comment="docker-20.10.9_ce-156.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651739" comment="runc-1.0.2-23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213144" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3144</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3144" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3144" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3144" ref_url="https://www.suse.com/security/cve/CVE-2021-3144" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14679-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1690-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008813.html" source="SUSE-SU"/>
		<reference ref_id="TID000019887" ref_url="https://www.suse.com/support/kb/doc/?id=000019887" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0347-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CYH7ONK65HNBANHLED5R64OBSM2EORYI/" source="SUSE-SU"/>
    <description>
    In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-3144/">CVE-2021-3144</cve>
	<bugzilla href="https://bugzilla.suse.com/1181550">SUSE bug 1181550</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181562">SUSE bug 1181562</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202131440" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-31440</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-31440" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31440" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-31440" ref_url="https://www.suse.com/security/cve/CVE-2021-31440" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:3360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009578.html" source="SUSE-SU"/>
    <description>
    This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs prior to executing them. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-13661.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-31440/">CVE-2021-31440</cve>
	<bugzilla href="https://bugzilla.suse.com/1190126">SUSE bug 1190126</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190127">SUSE bug 1190127</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213148" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3148</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3148" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3148" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3148" ref_url="https://www.suse.com/security/cve/CVE-2021-3148" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14679-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1690-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008813.html" source="SUSE-SU"/>
		<reference ref_id="TID000019887" ref_url="https://www.suse.com/support/kb/doc/?id=000019887" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0347-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CYH7ONK65HNBANHLED5R64OBSM2EORYI/" source="SUSE-SU"/>
    <description>
    An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3148/">CVE-2021-3148</cve>
	<bugzilla href="https://bugzilla.suse.com/1181550">SUSE bug 1181550</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181558">SUSE bug 1181558</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202131535" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-31535</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-31535" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31535" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-31535" ref_url="https://www.suse.com/security/cve/CVE-2021-31535" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009017.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008845.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008960.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0807-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IHKZVFIFHF623NYTHXHM7GHY5WE7LCHT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0857-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6WUBWGS6GPACWAIGOVLE7UDHZ4HSXZVC/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1897-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3TE4MZKP3FOYVRFOKL6QQUC77PHP2K76/" source="SUSE-SU"/>
    <description>
    LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the maximum size allowed by the protocol (and also longer than the maximum packet size for normal-sized packets). The user-controlled data exceeding the maximum size is then interpreted by the server as additional X protocol requests and executed, e.g., to disable X server authorization completely. For example, if the victim encounters malicious terminal control sequences for color codes, then the attacker may be able to take full control of the running graphical session.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-05"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-31535/">CVE-2021-31535</cve>
	<bugzilla href="https://bugzilla.suse.com/1182506">SUSE bug 1182506</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191879">SUSE bug 1191879</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205051">SUSE bug 1205051</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009503414" comment="libX11-6-1.6.5-3.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009494026" comment="libX11-data-1.6.5-3.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009503416" comment="libX11-xcb1-1.6.5-3.21.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213156" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3156</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3156" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3156" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3156" ref_url="https://www.suse.com/security/cve/CVE-2021-3156" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008675.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:4-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:6-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:7-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0225-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0226-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008249.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0227-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008250.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-January/008252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0928-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008540.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1274-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008662.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008661.html" source="SUSE-SU"/>
		<reference ref_id="TID000019841" ref_url="https://www.suse.com/support/kb/doc/?id=000019841" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7OQJUG5Z7K425IKZS5GT4KPIBGTT4JMW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0170-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3O463OUKAXLCUM74AUHUPVMQFXLLVAEH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0602-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JTRDPRKO2NDRVSH5UJJKLBDYJXGUBK6P/" source="SUSE-SU"/>
    <description>
    Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3156/">CVE-2021-3156</cve>
	<bugzilla href="https://bugzilla.suse.com/1180684">SUSE bug 1180684</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181090">SUSE bug 1181090</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181506">SUSE bug 1181506</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181657">SUSE bug 1181657</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183936">SUSE bug 1183936</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009503164" comment="sudo-1.8.22-4.18.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202131607" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-31607</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-31607" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31607" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-31607" ref_url="https://www.suse.com/security/cve/CVE-2021-31607" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008811.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14755-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009064.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1688-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1690-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1693-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008807.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008813.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1951-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2114-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009062.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0899-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6E3YAO2VV3WBUS7PMAT26ZYDS3AXW5VL/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1951-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BSSCTPCNB3RDCWJ6DOALIIRKDXUAVGPB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2106-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MU6P3NIODW6ZMC4HZLBROO6ZEOD5KAUX/" source="SUSE-SU"/>
    <description>
    In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function (which executes popen unsafely).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-31607/">CVE-2021-31607</cve>
	<bugzilla href="https://bugzilla.suse.com/1185281">SUSE bug 1185281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1210934">SUSE bug 1210934</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009494057" comment="python3-distro-1.5.0-3.5.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504114" comment="python3-salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504115" comment="salt-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504120" comment="salt-minion-3002.2-37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504125" comment="salt-transactional-update-3002.2-37.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213177" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3177</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3177" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3177" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3177" ref_url="https://www.suse.com/security/cve/CVE-2021-3177" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008476.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008291.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0428-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008303.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0432-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008310.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0529-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008350.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0270-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WUT6BSX5663NCXU3Y4KR3RA3RQHJMCFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0331-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3AKEBUCTPHZWXJGF6EWK7HBTO726SP2Y/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3177/">CVE-2021-3177</cve>
	<bugzilla href="https://bugzilla.suse.com/1181126">SUSE bug 1181126</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760824" comment="libpython3_6m1_0-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760825" comment="python3-3.6.12-3.75.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760826" comment="python3-base-3.6.12-3.75.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202131795" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-31795</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-31795" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31795" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-31795" ref_url="https://www.suse.com/security/cve/CVE-2021-31795" source="SUSE CVE"/>
    <description>
    The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allows attackers to overwrite heap memory via PhysmemNewRamBackedPMR.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-31795/">CVE-2021-31795</cve>
	<bugzilla href="https://bugzilla.suse.com/1185354">SUSE bug 1185354</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202131799" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-31799</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-31799" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31799" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-31799" ref_url="https://www.suse.com/security/cve/CVE-2021-31799" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:862-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009790.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010920.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1535-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SFO6LZPCK3BJ6OA3FTD3UWQI47BKDQBA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3838-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3CHM25JITRX6N3UKVDBKNLWS6MYWFY3M/" source="SUSE-SU"/>
    <description>
    In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-31799/">CVE-2021-31799</cve>
	<bugzilla href="https://bugzilla.suse.com/1190375">SUSE bug 1190375</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196771">SUSE bug 1196771</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009680329" comment="libruby2_5-2_5-2.5.9-150000.4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680330" comment="ruby2.5-2.5.9-150000.4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680333" comment="ruby2.5-stdlib-2.5.9-150000.4.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202131810" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-31810</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-31810" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31810" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-31810" ref_url="https://www.suse.com/security/cve/CVE-2021-31810" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:862-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009790.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:15034-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010920.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1535-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SFO6LZPCK3BJ6OA3FTD3UWQI47BKDQBA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3838-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3CHM25JITRX6N3UKVDBKNLWS6MYWFY3M/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-31810/">CVE-2021-31810</cve>
	<bugzilla href="https://bugzilla.suse.com/1188161">SUSE bug 1188161</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193383">SUSE bug 1193383</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205053">SUSE bug 1205053</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009680329" comment="libruby2_5-2_5-2.5.9-150000.4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680330" comment="ruby2.5-2.5.9-150000.4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680333" comment="ruby2.5-stdlib-2.5.9-150000.4.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202131829" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-31829</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-31829" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31829" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-31829" ref_url="https://www.suse.com/security/cve/CVE-2021-31829" source="SUSE CVE"/>
    <description>
    kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-31829/">CVE-2021-31829</cve>
	<bugzilla href="https://bugzilla.suse.com/1188561">SUSE bug 1188561</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213185" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3185</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3185" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3185" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3185" ref_url="https://www.suse.com/security/cve/CVE-2021-3185" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:1819-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008904.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1873-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008942.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1944-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008991.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0822-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WTUD7F7CVHXB4OCLI7OT4AVJTO6T64TM/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1012-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2B2UD46YGBOYO64SOPMOM6DQAL6FGCHZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1819-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4DDS7NLC6D7UVP25OVRWIRK6Y44WZKCU/" source="SUSE-SU"/>
    <description>
    A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3185/">CVE-2021-3185</cve>
	<bugzilla href="https://bugzilla.suse.com/1181255">SUSE bug 1181255</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704883" comment="gstreamer-1.16.3-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704884" comment="gstreamer-plugins-base-1.16.3-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704885" comment="libgstallocators-1_0-0-1.16.3-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704886" comment="libgstapp-1_0-0-1.16.3-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704887" comment="libgstaudio-1_0-0-1.16.3-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704888" comment="libgstgl-1_0-0-1.16.3-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704889" comment="libgstpbutils-1_0-0-1.16.3-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704890" comment="libgstreamer-1_0-0-1.16.3-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704891" comment="libgstriff-1_0-0-1.16.3-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704892" comment="libgsttag-1_0-0-1.16.3-4.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704893" comment="libgstvideo-1_0-0-1.16.3-4.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202131916" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-31916</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-31916" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31916" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-31916" ref_url="https://www.suse.com/security/cve/CVE-2021-31916" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009774.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3807-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3941-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009873.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3979-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009875.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3992-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009877.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1501-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5J6FJF42AOGK3VQ4EFVDHQENHCDEMVT3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3806-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WLGTBAKURNXDJOZBJTW2QLXJEWT66GSC/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3941-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UKZHKAOI6N3ILHMQUWDAPBQQORWN64SU/" source="SUSE-SU"/>
    <description>
    An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-31916/">CVE-2021-31916</cve>
	<bugzilla href="https://bugzilla.suse.com/1192781">SUSE bug 1192781</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705000" comment="kernel-default-5.3.18-24.96.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705001" comment="kernel-default-base-5.3.18-24.96.1.9.44.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658974" comment="kernel-rt-5.3.18-62.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213197" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3197</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3197" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3197" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3197" ref_url="https://www.suse.com/security/cve/CVE-2021-3197" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0626-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0914-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14650-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008380.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14679-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008808.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14734-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008809.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1690-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/019028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008813.html" source="SUSE-SU"/>
		<reference ref_id="TID000019887" ref_url="https://www.suse.com/support/kb/doc/?id=000019887" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0347-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CYH7ONK65HNBANHLED5R64OBSM2EORYI/" source="SUSE-SU"/>
    <description>
    An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3197/">CVE-2021-3197</cve>
	<bugzilla href="https://bugzilla.suse.com/1181550">SUSE bug 1181550</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181564">SUSE bug 1181564</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009760848" comment="python3-salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760849" comment="salt-3000-24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760850" comment="salt-minion-3000-24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202132066" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-32066</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-32066" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32066" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-32066" ref_url="https://www.suse.com/security/cve/CVE-2021-32066" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:862-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009790.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:15034-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010920.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1535-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SFO6LZPCK3BJ6OA3FTD3UWQI47BKDQBA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3838-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3CHM25JITRX6N3UKVDBKNLWS6MYWFY3M/" source="SUSE-SU"/>
    <description>
    An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-32066/">CVE-2021-32066</cve>
	<bugzilla href="https://bugzilla.suse.com/1188160">SUSE bug 1188160</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196771">SUSE bug 1196771</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205053">SUSE bug 1205053</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009680329" comment="libruby2_5-2_5-2.5.9-150000.4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680330" comment="ruby2.5-2.5.9-150000.4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680333" comment="ruby2.5-stdlib-2.5.9-150000.4.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202132078" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-32078</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-32078" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32078" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-32078" ref_url="https://www.suse.com/security/cve/CVE-2021-32078" source="SUSE CVE"/>
    <description>
    An Out-of-Bounds Read was discovered in arch/arm/mach-footbridge/personal-pci.c in the Linux kernel through 5.12.11 because of the lack of a check for a value that shouldn't be negative, e.g., access to element -2 of an array, aka CID-298a58e165e4.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-32078/">CVE-2021-32078</cve>
	<bugzilla href="https://bugzilla.suse.com/1187489">SUSE bug 1187489</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202132399" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-32399</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-32399" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32399" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-32399" ref_url="https://www.suse.com/security/cve/CVE-2021-32399" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2020-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2025-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2042-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2060-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-32399/">CVE-2021-32399</cve>
	<bugzilla href="https://bugzilla.suse.com/1184611">SUSE bug 1184611</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1185898">SUSE bug 1185898</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1185899">SUSE bug 1185899</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196174">SUSE bug 1196174</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200084">SUSE bug 1200084</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201734">SUSE bug 1201734</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202132606" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-32606</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-32606" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32606" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-32606" ref_url="https://www.suse.com/security/cve/CVE-2021-32606" source="SUSE CVE"/>
    <description>
    In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.)
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-32606/">CVE-2021-32606</cve>
	<bugzilla href="https://bugzilla.suse.com/1185953">SUSE bug 1185953</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202132760" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-32760</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-32760" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32760" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-32760" ref_url="https://www.suse.com/security/cve/CVE-2021-32760" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009645.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1081-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOFB4OTX7BGTKOBQF2ZTPBP4VJT54IQS/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1404-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L7ADRJZ4HKOCVZC5ZKIM4MD6EZEHBNB3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2412-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KOVJMTDKAFMTONFNVO7Z327OFE52V7FK/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3506-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NP4XGHFKECRFSI6UYXER53KXVGP66EHQ/" source="SUSE-SU"/>
    <description>
    containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in containerd 1.5.4 and 1.4.8. As a workaround, ensure that users only pull images from trusted sources. Linux security modules (LSMs) like SELinux and AppArmor can limit the files potentially affected by this bug through policies and profiles that prevent containerd from interacting with specific files.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-27"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-32760/">CVE-2021-32760</cve>
	<bugzilla href="https://bugzilla.suse.com/1188282">SUSE bug 1188282</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009651737" comment="containerd-1.4.11-56.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651738" comment="docker-20.10.9_ce-156.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651739" comment="runc-1.0.2-23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133034" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33034</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33034" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33034" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33034" ref_url="https://www.suse.com/security/cve/CVE-2021-33034" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2020-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2025-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2026-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009045.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2042-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009041.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2060-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.7/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-33034/">CVE-2021-33034</cve>
	<bugzilla href="https://bugzilla.suse.com/1186111">SUSE bug 1186111</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186285">SUSE bug 1186285</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213308" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3308</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3308" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3308" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3308" ref_url="https://www.suse.com/security/cve/CVE-2021-3308" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1023-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1028-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008586.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1460-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocation of all IDT vectors on the system by rebooting itself with MSI or MSI-X capabilities enabled and entries setup. Such reboots will leak any vectors used by the MSI(-X) entries that the guest might had enabled, and hence will lead to vector exhaustion on the system, not allowing further PCI pass through devices to work properly. HVM guests with PCI pass through devices can mount a Denial of Service (DoS) attack affecting the pass through of PCI devices to other guests or the hardware domain. In the latter case, this would affect the entire host.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3308/">CVE-2021-3308</cve>
	<bugzilla href="https://bugzilla.suse.com/1181254">SUSE bug 1181254</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009493665" comment="xen-libs-4.13.2_08-3.25.3 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133098" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33098</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33098" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33098" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33098" ref_url="https://www.suse.com/security/cve/CVE-2021-33098" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    Improper input validation in the Intel(R) Ethernet ixgbe driver for Linux before version 3.17.3 may allow an authenticated user to potentially enable denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-33098/">CVE-2021-33098</cve>
	<bugzilla href="https://bugzilla.suse.com/1192877">SUSE bug 1192877</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658985" comment="kernel-rt-5.3.18-65.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133120" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33120</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33120" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33120" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33120" ref_url="https://www.suse.com/security/cve/CVE-2021-33120" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0502-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010310.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0576-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010309.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0574-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W7QEMHXA4R2RUIQPQL2RSCQ7TBADKDOH/" source="SUSE-SU"/>
    <description>
    Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-04"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-33120/">CVE-2021-33120</cve>
	<bugzilla href="https://bugzilla.suse.com/1195781">SUSE bug 1195781</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667863" comment="ucode-intel-20220207-10.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133135" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33135</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33135" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33135" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33135" ref_url="https://www.suse.com/security/cve/CVE-2021-33135" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:2342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-33135/">CVE-2021-33135</cve>
	<bugzilla href="https://bugzilla.suse.com/1199515">SUSE bug 1199515</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133139" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33139</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33139" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33139" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33139" ref_url="https://www.suse.com/security/cve/CVE-2021-33139" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010488.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010500.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011226.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper conditions check in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.100 may allow an authenticated user to potentially enable denial of service via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-33139/">CVE-2021-33139</cve>
	<bugzilla href="https://bugzilla.suse.com/1195786">SUSE bug 1195786</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33155" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33155" ref_url="https://www.suse.com/security/cve/CVE-2021-33155" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010356.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010488.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010500.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010613.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011226.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1065-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QNS2QRVZ2MWL6BB6UKZX6H5IFTGR7LZ2/" source="SUSE-SU"/>
    <description>
    Improper input validation in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.100 may allow an authenticated user to potentially enable denial of service via adjacent access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-33155/">CVE-2021-33155</cve>
	<bugzilla href="https://bugzilla.suse.com/1195786">SUSE bug 1195786</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669993" comment="kernel-firmware-20200107-3.26.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669994" comment="ucode-amd-20200107-3.26.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133200" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33200</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33200" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33200" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33200" ref_url="https://www.suse.com/security/cve/CVE-2021-33200" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2020-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2027-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
    <description>
    kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege escalation to root. In particular, there is a corner case where the off reg causes a masking direction change, which then results in an incorrect final aux-&gt;alu_limit.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-33200/">CVE-2021-33200</cve>
	<bugzilla href="https://bugzilla.suse.com/1186484">SUSE bug 1186484</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186498">SUSE bug 1186498</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213347" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3347</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3347" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3347" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3347" ref_url="https://www.suse.com/security/cve/CVE-2021-3347" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0818-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-March/018289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0823-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008500.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008509.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0840-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008510.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008502.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0868-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0870-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008335.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0241-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GZRN6BW22C4S3GVCJVPHDT4HHTLVGVZE/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3347/">CVE-2021-3347</cve>
	<bugzilla href="https://bugzilla.suse.com/1181349">SUSE bug 1181349</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181553">SUSE bug 1181553</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190859">SUSE bug 1190859</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213348" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3348</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3348" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3348" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3348" ref_url="https://www.suse.com/security/cve/CVE-2021-3348" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:412-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:413-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008305.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0532-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-February/008354.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0739-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008460.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0241-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GZRN6BW22C4S3GVCJVPHDT4HHTLVGVZE/" source="SUSE-SU"/>
    <description>
    nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID-b98e762e3d71.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-05-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3348/">CVE-2021-3348</cve>
	<bugzilla href="https://bugzilla.suse.com/1181504">SUSE bug 1181504</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1181645">SUSE bug 1181645</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009760798" comment="kernel-default-5.3.18-24.49.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133560" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33560</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33560" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33560" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33560" ref_url="https://www.suse.com/security/cve/CVE-2021-33560" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2155-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2157-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009085.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0919-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PPALT4SBPXXPFJVTZN5FQCXMNVH4GXCU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2157-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AOWBBOB3KB4MSVNKBUGK3UIYPYWCHNLS/" source="SUSE-SU"/>
    <description>
    Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-33560/">CVE-2021-33560</cve>
	<bugzilla href="https://bugzilla.suse.com/1187212">SUSE bug 1187212</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189854">SUSE bug 1189854</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199664">SUSE bug 1199664</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009504140" comment="libgcrypt20-1.8.2-8.39.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133574" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33574</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33574" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33574" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33574" ref_url="https://www.suse.com/security/cve/CVE-2021-33574" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009550.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:384-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:390-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009562.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:391-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009563.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:397-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:400-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:403-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009532.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3290-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009543.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009539.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009579.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1374-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YZGEXWUJCYCGR3DHTHHZAJYSGQP2SHMN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3291-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TYMYANBGPUFKQ7SIIB3PZLAAR35QYXOR/" source="SUSE-SU"/>
    <description>
    The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-33574/">CVE-2021-33574</cve>
	<bugzilla href="https://bugzilla.suse.com/1186489">SUSE bug 1186489</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189426">SUSE bug 1189426</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192788">SUSE bug 1192788</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196766">SUSE bug 1196766</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009634576" comment="glibc-2.26-13.59.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009634580" comment="glibc-locale-2.26-13.59.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009634581" comment="glibc-locale-base-2.26-13.59.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133624" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33624</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33624" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33624" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33624" ref_url="https://www.suse.com/security/cve/CVE-2021-33624" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009188.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2305-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BBGE5AIDX3NT46HPS2IYLFESAEFCTG6O/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2352-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2GU2EJMYFONMKDLPFYPCAPSOFXO5ZISM/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
    <description>
    In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-33624/">CVE-2021-33624</cve>
	<bugzilla href="https://bugzilla.suse.com/1187554">SUSE bug 1187554</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704907" comment="kernel-default-5.3.18-24.70.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704908" comment="kernel-default-base-5.3.18-24.70.1.9.32.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624613" comment="kernel-rt-4.12.14-10.49.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133805" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33805</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33805" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33805" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33805" ref_url="https://www.suse.com/security/cve/CVE-2021-33805" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10906. Reason: This candidate is a duplicate of CVE-2018-10906. Notes: All CVE users should reference CVE-2018-10906 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-33805/">CVE-2021-33805</cve>
	<bugzilla href="https://bugzilla.suse.com/1186801">SUSE bug 1186801</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009477296" comment="libfuse3-3 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133909" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33909</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33909" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33909" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33909" ref_url="https://www.suse.com/security/cve/CVE-2021-33909" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009160.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2409-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-July/019639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009170.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2487-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009222.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009221.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009226.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2559-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-July/019748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2584-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009239.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009279.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="TID000020341" ref_url="https://www.suse.com/support/kb/doc/?id=000020341" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1076-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WT3TYNEJZ7FKJMTYO3DX3Z7B2YCYPEJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2409-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PZY5AYK3E4EZBBTJOQXWCMRDFFYLM6EB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2415-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VDV3DHS5VRBTZIQXVKQML4UNTSCPJZZA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-10-11"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-33909/">CVE-2021-33909</cve>
	<bugzilla href="https://bugzilla.suse.com/1188062">SUSE bug 1188062</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188063">SUSE bug 1188063</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188257">SUSE bug 1188257</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189302">SUSE bug 1189302</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190859">SUSE bug 1190859</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704910" comment="kernel-default-5.3.18-24.75.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704911" comment="kernel-default-base-5.3.18-24.75.3.9.34.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628046" comment="kernel-rt-5.3.18-48.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213392" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3392</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3392" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3392" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3392" ref_url="https://www.suse.com/security/cve/CVE-2021-3392" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3392/">CVE-2021-3392</cve>
	<bugzilla href="https://bugzilla.suse.com/1189236">SUSE bug 1189236</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133928" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33928</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33928" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33928" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33928" ref_url="https://www.suse.com/security/cve/CVE-2021-33928" source="SUSE CVE"/>
    <description>
    Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="0/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-33928/">CVE-2021-33928</cve>
	<bugzilla href="https://bugzilla.suse.com/1190148">SUSE bug 1190148</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133929" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33929</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33929" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33929" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33929" ref_url="https://www.suse.com/security/cve/CVE-2021-33929" source="SUSE CVE"/>
    <description>
    Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="0/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-33929/">CVE-2021-33929</cve>
	<bugzilla href="https://bugzilla.suse.com/1190149">SUSE bug 1190149</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133930" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33930</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33930" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33930" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33930" ref_url="https://www.suse.com/security/cve/CVE-2021-33930" source="SUSE CVE"/>
    <description>
    Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="0/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-33930/">CVE-2021-33930</cve>
	<bugzilla href="https://bugzilla.suse.com/1190150">SUSE bug 1190150</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202133938" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-33938</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-33938" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33938" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-33938" ref_url="https://www.suse.com/security/cve/CVE-2021-33938" source="SUSE CVE"/>
    <description>
    Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="0/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-33938/">CVE-2021-33938</cve>
	<bugzilla href="https://bugzilla.suse.com/1190147">SUSE bug 1190147</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213409" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3409</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3409" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3409" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3409" ref_url="https://www.suse.com/security/cve/CVE-2021-3409" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3594-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014067.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
    <description>
    The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-3409/">CVE-2021-3409</cve>
	<bugzilla href="https://bugzilla.suse.com/1182282">SUSE bug 1182282</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213411" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3411</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3411" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3411" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3411" ref_url="https://www.suse.com/security/cve/CVE-2021-3411" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linking state. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3411/">CVE-2021-3411</cve>
	<bugzilla href="https://bugzilla.suse.com/1182498">SUSE bug 1182498</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213416" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3416</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3416" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3416" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3416" ref_url="https://www.suse.com/security/cve/CVE-2021-3416" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008649.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008646.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008650.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008671.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14774-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0600-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ATYM36RK6JXDXZ33F2KFHZHDZ3F3YD24/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
    <description>
    A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3416/">CVE-2021-3416</cve>
	<bugzilla href="https://bugzilla.suse.com/1182968">SUSE bug 1182968</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186473">SUSE bug 1186473</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704859" comment="qemu-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499829" comment="qemu-arm-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499837" comment="qemu-ipxe-1.0.0+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499843" comment="qemu-seabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499844" comment="qemu-sgabios-8-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704860" comment="qemu-tools-4.2.1-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499848" comment="qemu-vgabios-1.12.1+-11.16.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499849" comment="qemu-x86-4.2.1-11.16.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213419" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3419</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3419" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3419" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3419" ref_url="https://www.suse.com/security/cve/CVE-2021-3419" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008910.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008949.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1895-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1918-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008990.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1942-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IEKBDJBTGKO53MSKM3SRYVUQDWIJ2N5I/" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3419/">CVE-2021-3419</cve>
	<bugzilla href="https://bugzilla.suse.com/1182968">SUSE bug 1182968</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1182975">SUSE bug 1182975</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704898" comment="qemu-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499897" comment="qemu-arm-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499905" comment="qemu-ipxe-1.0.0+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499911" comment="qemu-seabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499912" comment="qemu-sgabios-8-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704899" comment="qemu-tools-4.2.1-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499916" comment="qemu-vgabios-1.12.1+-11.19.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499917" comment="qemu-x86-4.2.1-11.19.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213421" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3421</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3421" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3421" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3421" ref_url="https://www.suse.com/security/cve/CVE-2021-3421" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009600.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1052-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-May/023165.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2938-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2974-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010661.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:590-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010696.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:592-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010958.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009598.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3939-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012871.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WOGLQWSIIR4HYRWXGETEIHB6SM6A2MNK/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2682-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IQDL4MT3J7VM3IS3TI4EMLQJHDPTSZLZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2685-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PUJW4L55UGKEL4ROYV7WZNQDNBJXXLLG/" source="SUSE-SU"/>
    <description>
    A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-3421/">CVE-2021-3421</cve>
	<bugzilla href="https://bugzilla.suse.com/1183543">SUSE bug 1183543</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704952" comment="python3-rpm-4.14.1-22.4.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704953" comment="rpm-4.14.1-22.4.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213426" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3426</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3426" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3426" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3426" ref_url="https://www.suse.com/security/cve/CVE-2021-3426" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:35-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1490-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009890.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4015-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009914.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:4104-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KYXM7YGLJSNOU4FYI3M2QXACCQ4SO3AE/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3426/">CVE-2021-3426</cve>
	<bugzilla href="https://bugzilla.suse.com/1183374">SUSE bug 1183374</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009660091" comment="libpython3_6m1_0-3.6.15-3.91.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009660092" comment="python3-3.6.15-3.91.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009660093" comment="python3-base-3.6.15-3.91.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213428" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3428</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3428" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3428" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3428" ref_url="https://www.suse.com/security/cve/CVE-2021-3428" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel. A denial of service problem is identified if an extent tree is corrupted in a crafted ext4 filesystem in fs/ext4/extents.c in ext4_es_cache_extent. Fabricating an integer overflow, A local attacker with a special user privilege may cause a system crash problem which can lead to an availability threat.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3428/">CVE-2021-3428</cve>
	<bugzilla href="https://bugzilla.suse.com/1173485">SUSE bug 1173485</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1183509">SUSE bug 1183509</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202134401" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-34401</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-34401" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34401" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-34401" ref_url="https://www.suse.com/security/cve/CVE-2021-34401" source="SUSE CVE"/>
    <description>
    NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to code execution, compromised integrity, or denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-34401/">CVE-2021-34401</cve>
	<bugzilla href="https://bugzilla.suse.com/1194896">SUSE bug 1194896</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202134402" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-34402</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-34402" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34402" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-34402" ref_url="https://www.suse.com/security/cve/CVE-2021-34402" source="SUSE CVE"/>
    <description>
    NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service, Information disclosure, loss of Integrity, or possible escalation of privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-34402/">CVE-2021-34402</cve>
	<bugzilla href="https://bugzilla.suse.com/1194894">SUSE bug 1194894</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202134403" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-34403</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-34403" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34403" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-34403" ref_url="https://www.suse.com/security/cve/CVE-2021-34403" source="SUSE CVE"/>
    <description>
    NVIDIA Linux distributions contain a vulnerability in nvmap ioctl, which allows any user with a local account to exploit a use-after-free condition, leading to code privilege escalation, loss of confidentiality and integrity, or denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-34403/">CVE-2021-34403</cve>
	<bugzilla href="https://bugzilla.suse.com/1194897">SUSE bug 1194897</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202134406" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-34406</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-34406" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34406" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-34406" ref_url="https://www.suse.com/security/cve/CVE-2021-34406" source="SUSE CVE"/>
    <description>
    NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointer dereference, which may lead to a system reboot.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-34406/">CVE-2021-34406</cve>
	<bugzilla href="https://bugzilla.suse.com/1194893">SUSE bug 1194893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213444" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3444</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3444" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3444" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3444" ref_url="https://www.suse.com/security/cve/CVE-2021-3444" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008683.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008685.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1395-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008686.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008769.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008816.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009234.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0532-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZC652CKFCHQCNNU7MZKBTO27OZE22Q5U/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly out-of-bounds writes that could potentially lead to code execution. This issue was addressed in the upstream kernel in commit 9b00f1b78809 ("bpf: Fix truncation handling for mod32 dst reg wrt zero") and in Linux stable kernels 5.11.2, 5.10.19, and 5.4.101.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3444/">CVE-2021-3444</cve>
	<bugzilla href="https://bugzilla.suse.com/1184170">SUSE bug 1184170</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1184171">SUSE bug 1184171</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213448" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3448</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3448" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3448" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3448" ref_url="https://www.suse.com/security/cve/CVE-2021-3448" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14940-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010783.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14941-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010787.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1426-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q5SXZU2UVUXVIVOLI6OT32WIQ6OJBE5E/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3530-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2DP73HQCB6UNPUB54KPOZEMBUQDVN6M6/" source="SUSE-SU"/>
    <description>
    A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the random transmission ID to forge a reply and get it accepted by dnsmasq. This flaw makes a DNS Cache Poisoning attack much easier. The highest threat from this vulnerability is to data integrity.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-3448/">CVE-2021-3448</cve>
	<bugzilla href="https://bugzilla.suse.com/1183709">SUSE bug 1183709</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009653320" comment="dnsmasq-2.86-7.14.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213449" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3449</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3449" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3449" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3449" ref_url="https://www.suse.com/security/cve/CVE-2021-3449" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:87-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008603.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:99-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008602.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008558.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-March/008559.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:0955-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011541.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2327-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009145.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0476-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YRCNDGXHP3DJBJKDGVACNKEWGRZDKQRJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZO2DR7PIGZWRPXIGYAZCAL4X64BSDZJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1061-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SR22RRAXGLDTLSDJRAQ4O3Q67G2PNEGJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2327-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OFQOZ4RLN343RY5DDFVA2KWFMZHZD2KS/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2353-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVLFLECFVPSHO4SQBVWDO2CBAU5LB7IS/" source="SUSE-SU"/>
    <description>
    An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3449/">CVE-2021-3449</cve>
	<bugzilla href="https://bugzilla.suse.com/1183852">SUSE bug 1183852</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705020" comment="libopenssl1_1-1.1.1d-11.20.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705021" comment="openssl-1_1-1.1.1d-11.20.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202134556" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-34556</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-34556" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34556" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-34556" ref_url="https://www.suse.com/security/cve/CVE-2021-34556" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-34556/">CVE-2021-34556</cve>
	<bugzilla href="https://bugzilla.suse.com/1188983">SUSE bug 1188983</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202134693" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-34693</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-34693" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34693" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-34693" ref_url="https://www.suse.com/security/cve/CVE-2021-34693" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2305-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BBGE5AIDX3NT46HPS2IYLFESAEFCTG6O/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2352-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2GU2EJMYFONMKDLPFYPCAPSOFXO5ZISM/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
    <description>
    net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-34693/">CVE-2021-34693</cve>
	<bugzilla href="https://bugzilla.suse.com/1187452">SUSE bug 1187452</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192868">SUSE bug 1192868</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704907" comment="kernel-default-5.3.18-24.70.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704908" comment="kernel-default-base-5.3.18-24.70.1.9.32.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624613" comment="kernel-rt-4.12.14-10.49.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213483" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3483</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3483" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3483" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3483" ref_url="https://www.suse.com/security/cve/CVE-2021-3483" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1210-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1211-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1248-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-April/018606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1301-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-April/008670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14724-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008770.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1624-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008782.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0579-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6PH44XSVUZTRLJSGALUUATIQLKQWL4C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0758-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BUQVIATUWQNZFSV6IFJENJSRWJSP2QHF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. Versions before kernel 5.12-rc6 are affected
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3483/">CVE-2021-3483</cve>
	<bugzilla href="https://bugzilla.suse.com/1184393">SUSE bug 1184393</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704857" comment="kernel-default-5.3.18-24.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704858" comment="kernel-default-base-5.3.18-24.61.1.9.26.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009620089" comment="kernel-rt-5.3.18-8.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202134866" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-34866</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-34866" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34866" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-34866" ref_url="https://www.suse.com/security/cve/CVE-2021-34866" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009753.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
    <description>
    This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs, which can result in a type confusion condition. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-14689.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-34866/">CVE-2021-34866</cve>
	<bugzilla href="https://bugzilla.suse.com/1191645">SUSE bug 1191645</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191646">SUSE bug 1191646</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213489" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3489</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3489" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3489" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3489" ref_url="https://www.suse.com/security/cve/CVE-2021-3489" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009102.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via commit 4b81ccebaeee ("bpf, ringbuf: Deny reserve of buffers larger than ringbuf") (v5.13-rc4) and backported to the stable kernels in v5.12.4, v5.11.21, and v5.10.37. It was introduced via 457f44363a88 ("bpf: Implement BPF ring buffer and verifier support for it") (v5.8-rc1).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3489/">CVE-2021-3489</cve>
	<bugzilla href="https://bugzilla.suse.com/1185640">SUSE bug 1185640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1185856">SUSE bug 1185856</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213490" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3490</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3490" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3490" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3490" ref_url="https://www.suse.com/security/cve/CVE-2021-3490" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009102.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue was fixed via commit 049c4e13714e ("bpf: Fix alu32 const subreg bound tracking on bitwise operations") (v5.13-rc4) and backported to the stable kernels in v5.12.4, v5.11.21, and v5.10.37. The AND/OR issues were introduced by commit 3f50f132d840 ("bpf: Verifier, do explicit ALU32 bounds tracking") (5.7-rc1) and the XOR variant was introduced by 2921c90d4718 ("bpf:Fix a verifier failure with xor") ( 5.10-rc1).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3490/">CVE-2021-3490</cve>
	<bugzilla href="https://bugzilla.suse.com/1185641">SUSE bug 1185641</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1185796">SUSE bug 1185796</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213491" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3491</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3491" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3491" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3491" ref_url="https://www.suse.com/security/cve/CVE-2021-3491" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1888-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008950.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1890-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1899-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1913-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1975-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QHZZYSYX2W3FJK73UGT72F2DQ37IKCJY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0947-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M3WU4VH2HXVC3VLST5RWUW7LUFNSUEIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1975-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/42KHRU57J2OGM24I4AOZ7JW6VV2BOPCV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1977-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YMMFY2OXW23MB2M73JXBDJKJD5G5YCOX/" source="SUSE-SU"/>
    <description>
    The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc/&lt;PID&gt;/mem. This could be used to create a heap overflow leading to arbitrary code execution in the kernel. It was addressed via commit d1f82808877b ("io_uring: truncate lengths larger than MAX_RW_COUNT on provide buffers") (v5.13-rc1) and backported to the stable kernels in v5.12.4, v5.11.21, and v5.10.37. It was introduced in ddf0322db79c ("io_uring: add IORING_OP_PROVIDE_BUFFERS") (v5.7-rc1).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3491/">CVE-2021-3491</cve>
	<bugzilla href="https://bugzilla.suse.com/1185642">SUSE bug 1185642</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1187090">SUSE bug 1187090</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704896" comment="kernel-default-5.3.18-24.67.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704897" comment="kernel-default-base-5.3.18-24.67.3.9.30.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009498554" comment="kernel-rt-5.3.18-8.13.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213492" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3492</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3492" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3492" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3492" ref_url="https://www.suse.com/security/cve/CVE-2021-3492" source="SUSE CVE"/>
    <description>
    Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing arbitrary code. AKA ZDI-CAN-13562.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3492/">CVE-2021-3492</cve>
	<bugzilla href="https://bugzilla.suse.com/1184944">SUSE bug 1184944</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213493" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3493</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3493" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3493" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3493" ref_url="https://www.suse.com/security/cve/CVE-2021-3493" source="SUSE CVE"/>
    <description>
    The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3493/">CVE-2021-3493</cve>
	<bugzilla href="https://bugzilla.suse.com/1184900">SUSE bug 1184900</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202134981" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-34981</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-34981" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34981" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-34981" ref_url="https://www.suse.com/security/cve/CVE-2021-34981" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009774.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3807-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3941-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009873.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3979-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009875.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3992-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009877.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013765.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1501-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5J6FJF42AOGK3VQ4EFVDHQENHCDEMVT3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3806-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WLGTBAKURNXDJOZBJTW2QLXJEWT66GSC/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3941-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UKZHKAOI6N3ILHMQUWDAPBQQORWN64SU/" source="SUSE-SU"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-34981/">CVE-2021-34981</cve>
	<bugzilla href="https://bugzilla.suse.com/1191961">SUSE bug 1191961</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192595">SUSE bug 1192595</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196722">SUSE bug 1196722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1212298">SUSE bug 1212298</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705000" comment="kernel-default-5.3.18-24.96.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705001" comment="kernel-default-base-5.3.18-24.96.1.9.44.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658974" comment="kernel-rt-5.3.18-62.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213501" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3501</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3501" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3501" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3501" ref_url="https://www.suse.com/security/cve/CVE-2021-3501" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3501/">CVE-2021-3501</cve>
	<bugzilla href="https://bugzilla.suse.com/1185380">SUSE bug 1185380</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202135039" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-35039</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-35039" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35039" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-35039" ref_url="https://www.suse.com/security/cve/CVE-2021-35039" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009160.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009244.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2599-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009260.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2645-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009292.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1076-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WT3TYNEJZ7FKJMTYO3DX3Z7B2YCYPEJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2645-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2WMUIJQF7RUSXDRXECLPMVDE6YOS5WIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2687-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GDBOWLDJQ4K7JKRHIM7AOCKTJO5BY6C5/" source="SUSE-SU"/>
    <description>
    kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.sig_enforce=1 command-line argument.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-35039/">CVE-2021-35039</cve>
	<bugzilla href="https://bugzilla.suse.com/1188080">SUSE bug 1188080</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188126">SUSE bug 1188126</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704910" comment="kernel-default-5.3.18-24.75.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704911" comment="kernel-default-base-5.3.18-24.75.3.9.34.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626892" comment="kernel-rt-5.3.18-45.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213504" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3504</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3504" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3504" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3504" ref_url="https://www.suse.com/security/cve/CVE-2021-3504" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:1760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008840.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0806-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CSGIA2DN2ELWOW2J5TFWNTMLKQDBQAH5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1761-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q55SWQQWWFLTPBSSMBPSJOSFUIHSY6H6/" source="SUSE-SU"/>
    <description>
    A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3504/">CVE-2021-3504</cve>
	<bugzilla href="https://bugzilla.suse.com/1185013">SUSE bug 1185013</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704877" comment="libhivex0-1.3.14-5.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704878" comment="perl-Win-Hivex-1.3.14-5.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213506" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3506</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3506" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3506" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3506" ref_url="https://www.suse.com/security/cve/CVE-2021-3506" source="SUSE CVE"/>
    <description>
    An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3506/">CVE-2021-3506</cve>
	<bugzilla href="https://bugzilla.suse.com/1184999">SUSE bug 1184999</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213509" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3509</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3509" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3509" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3509" ref_url="https://www.suse.com/security/cve/CVE-2021-3509" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008915.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008918.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0833-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVZR2UDWM64LU6NNFZNHXJWWFA6W2ZDV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1834-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OD76XLAQUNHRCX53LARPKA7IODR5MCPO/" source="SUSE-SU"/>
    <description>
    A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to an httpOnly cookie. However, token cookies are used in the body of the HTTP response for the documentation, which again makes it available to XSS.The greatest threat to the system is for confidentiality, integrity, and availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3509/">CVE-2021-3509</cve>
	<bugzilla href="https://bugzilla.suse.com/1186021">SUSE bug 1186021</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009601181" comment="librados2-15.2.12.83+g528da226523-3.25.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009601182" comment="librbd1-15.2.12.83+g528da226523-3.25.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213516" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3516</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3516" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3516" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3516" ref_url="https://www.suse.com/security/cve/CVE-2021-3516" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008744.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008750.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008801.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:170-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008802.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:171-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008805.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008806.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:252-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1523-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1654-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008798.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0692-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HLCJPB5W3FKJ7HO6DH6UVA3GP6IVZ37L/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0764-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/32MGTWHTQRUPYHYIAVT6OVBDWQDI36DX/" source="SUSE-SU"/>
    <description>
    There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3516/">CVE-2021-3516</cve>
	<bugzilla href="https://bugzilla.suse.com/1185409">SUSE bug 1185409</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191860">SUSE bug 1191860</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704874" comment="libxml2-2-2.9.7-3.34.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704875" comment="libxml2-tools-2.9.7-3.34.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213517" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3517</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3517" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3517" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3517" ref_url="https://www.suse.com/security/cve/CVE-2021-3517" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008744.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008750.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008801.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:170-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008802.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:171-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008805.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008806.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:252-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1523-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1654-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008798.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0692-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HLCJPB5W3FKJ7HO6DH6UVA3GP6IVZ37L/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0764-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/32MGTWHTQRUPYHYIAVT6OVBDWQDI36DX/" source="SUSE-SU"/>
    <description>
    There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.6/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2021-3517/">CVE-2021-3517</cve>
	<bugzilla href="https://bugzilla.suse.com/1185410">SUSE bug 1185410</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191860">SUSE bug 1191860</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194438">SUSE bug 1194438</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196383">SUSE bug 1196383</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704874" comment="libxml2-2-2.9.7-3.34.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704875" comment="libxml2-tools-2.9.7-3.34.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213518" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3518</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3518" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3518" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3518" ref_url="https://www.suse.com/security/cve/CVE-2021-3518" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008744.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008750.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008801.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:170-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008802.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:171-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008805.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008806.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:252-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1523-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1654-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008798.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0692-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HLCJPB5W3FKJ7HO6DH6UVA3GP6IVZ37L/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0764-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/32MGTWHTQRUPYHYIAVT6OVBDWQDI36DX/" source="SUSE-SU"/>
    <description>
    There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3518/">CVE-2021-3518</cve>
	<bugzilla href="https://bugzilla.suse.com/1185408">SUSE bug 1185408</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191860">SUSE bug 1191860</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704874" comment="libxml2-2-2.9.7-3.34.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704875" comment="libxml2-tools-2.9.7-3.34.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213520" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3520</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3520" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3520" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3520" ref_url="https://www.suse.com/security/cve/CVE-2021-3520" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:167-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008801.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:170-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008802.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:252-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008776.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1647-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-May/018981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008909.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0760-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Y6JSYGHG2J4E7C5MDUDUDEILIMZKTM7H/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1825-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MA4LQPPDXUEKHDKVDM24RJVHSV2EC67P/" source="SUSE-SU"/>
    <description>
    There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.6/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2021-3520/">CVE-2021-3520</cve>
	<bugzilla href="https://bugzilla.suse.com/1185438">SUSE bug 1185438</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009503309" comment="liblz4-1-1.8.0-3.8.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213524" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3524</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3524" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3524" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3524" ref_url="https://www.suse.com/security/cve/CVE-2021-3524" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008915.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008918.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0833-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVZR2UDWM64LU6NNFZNHXJWWFA6W2ZDV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1834-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OD76XLAQUNHRCX53LARPKA7IODR5MCPO/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-3524/">CVE-2021-3524</cve>
	<bugzilla href="https://bugzilla.suse.com/1185619">SUSE bug 1185619</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009601181" comment="librados2-15.2.12.83+g528da226523-3.25.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009601182" comment="librbd1-15.2.12.83+g528da226523-3.25.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213527" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3527</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3527" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3527" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3527" ref_url="https://www.suse.com/security/cve/CVE-2021-3527" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2789-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019909.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009332.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3635-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009705.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2789-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UE3MLTPF62745SPUUDQR6ROYVP4GG6DT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2858-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GGOXRRBMGRJGBNXEGPCZ3JFLXCMIM6A3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3614-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/26KPX43RJBRTCX3JER7CN7MAT4QEGAED/" source="SUSE-SU"/>
    <description>
    A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically allocate a variable length array (VLA) on the stack without proper validation. Since the total size is not bounded, a malicious guest could use this flaw to influence the array length and cause the QEMU process to perform an excessive allocation on the stack, resulting in a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3527/">CVE-2021-3527</cve>
	<bugzilla href="https://bugzilla.suse.com/1186012">SUSE bug 1186012</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704934" comment="qemu-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630345" comment="qemu-arm-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630353" comment="qemu-ipxe-1.0.0+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630359" comment="qemu-seabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630360" comment="qemu-sgabios-8-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704935" comment="qemu-tools-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630364" comment="qemu-vgabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630365" comment="qemu-x86-4.2.1-11.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213531" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3531</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3531" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3531" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3531" ref_url="https://www.suse.com/security/cve/CVE-2021-3531" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008915.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008918.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0833-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVZR2UDWM64LU6NNFZNHXJWWFA6W2ZDV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1834-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OD76XLAQUNHRCX53LARPKA7IODR5MCPO/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3531/">CVE-2021-3531</cve>
	<bugzilla href="https://bugzilla.suse.com/1186020">SUSE bug 1186020</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009601181" comment="librados2-15.2.12.83+g528da226523-3.25.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009601182" comment="librbd1-15.2.12.83+g528da226523-3.25.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213537" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3537</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3537" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3537" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3537" ref_url="https://www.suse.com/security/cve/CVE-2021-3537" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:168-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008800.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008801.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:170-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008802.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:171-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008805.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008806.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008819.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:184-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:185-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:188-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:190-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:202-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008852.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:203-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008853.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008855.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008858.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:209-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008860.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:218-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008884.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008901.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:233-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:235-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008919.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008920.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:240-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008924.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:252-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1654-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-May/008798.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0764-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/32MGTWHTQRUPYHYIAVT6OVBDWQDI36DX/" source="SUSE-SU"/>
    <description>
    A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3537/">CVE-2021-3537</cve>
	<bugzilla href="https://bugzilla.suse.com/1185698">SUSE bug 1185698</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704874" comment="libxml2-2-2.9.7-3.34.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704875" comment="libxml2-tools-2.9.7-3.34.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213541" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3541</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3541" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3541" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3541" ref_url="https://www.suse.com/security/cve/CVE-2021-3541" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:247-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:249-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009012.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:250-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:251-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:252-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009021.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009269.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1307-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014631.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1308-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014664.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1341-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014665.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1458-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1459-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1460-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014750.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1462-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1464-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1465-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1466-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1467-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1840-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008996.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:537-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-June/019290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1917-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2016-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014596.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0886-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/A7LMMGD465XPYHREX4OT47UCNFPO6QTF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1917-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AR6HBOC5J6QPVBH5GMPTQIK63SAT3C5S/" source="SUSE-SU"/>
    <description>
    A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3541/">CVE-2021-3541</cve>
	<bugzilla href="https://bugzilla.suse.com/1186015">SUSE bug 1186015</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704900" comment="libxml2-2-2.9.7-3.37.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704901" comment="libxml2-tools-2.9.7-3.37.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213542" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3542</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3542" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3542" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3542" ref_url="https://www.suse.com/security/cve/CVE-2021-3542" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42739. Reason: This candidate is a reservation duplicate of CVE-2021-42739. Notes: All CVE users should reference CVE-2021-42739 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3542/">CVE-2021-3542</cve>
	<bugzilla href="https://bugzilla.suse.com/1184673">SUSE bug 1184673</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1186063">SUSE bug 1186063</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704995" comment="kernel-default-5.3.18-24.93.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704996" comment="kernel-default-base-5.3.18-24.93.1.9.42.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651700" comment="kernel-rt-5.3.18-57.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213543" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3543</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3543" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3543" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3543" ref_url="https://www.suse.com/security/cve/CVE-2021-3543" source="SUSE CVE"/>
    <description>
    A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3543/">CVE-2021-3543</cve>
	<bugzilla href="https://bugzilla.suse.com/1185091">SUSE bug 1185091</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213544" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3544</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3544" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3544" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3544" ref_url="https://www.suse.com/security/cve/CVE-2021-3544" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:2212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009107.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2213-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UIASIXLUG5DPOL6IUP6OEGC7XFEJQSHY/" source="SUSE-SU"/>
    <description>
    Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3544/">CVE-2021-3544</cve>
	<bugzilla href="https://bugzilla.suse.com/1186010">SUSE bug 1186010</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704905" comment="qemu-4.2.1-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499926" comment="qemu-arm-4.2.1-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499934" comment="qemu-ipxe-1.0.0+-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499940" comment="qemu-seabios-1.12.1+-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499941" comment="qemu-sgabios-8-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704906" comment="qemu-tools-4.2.1-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499945" comment="qemu-vgabios-1.12.1+-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499946" comment="qemu-x86-4.2.1-11.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213545" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3545</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3545" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3545" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3545" ref_url="https://www.suse.com/security/cve/CVE-2021-3545" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:2212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009107.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2213-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UIASIXLUG5DPOL6IUP6OEGC7XFEJQSHY/" source="SUSE-SU"/>
    <description>
    An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due to the read of uninitialized memory. A malicious guest could exploit this issue to leak memory from the host.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3545/">CVE-2021-3545</cve>
	<bugzilla href="https://bugzilla.suse.com/1185990">SUSE bug 1185990</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704905" comment="qemu-4.2.1-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499926" comment="qemu-arm-4.2.1-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499934" comment="qemu-ipxe-1.0.0+-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499940" comment="qemu-seabios-1.12.1+-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499941" comment="qemu-sgabios-8-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704906" comment="qemu-tools-4.2.1-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499945" comment="qemu-vgabios-1.12.1+-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499946" comment="qemu-x86-4.2.1-11.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213546" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3546</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3546" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3546" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3546" ref_url="https://www.suse.com/security/cve/CVE-2021-3546" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:2212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009107.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SVDDMT7IUGYOEFTYO3UWD73PJMJL4FSY/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2213-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UIASIXLUG5DPOL6IUP6OEGC7XFEJQSHY/" source="SUSE-SU"/>
    <description>
    An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw occurs while processing the 'VIRTIO_GPU_CMD_GET_CAPSET' command from the guest. It could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service condition, or potential code execution with the privileges of the QEMU process.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3546/">CVE-2021-3546</cve>
	<bugzilla href="https://bugzilla.suse.com/1185981">SUSE bug 1185981</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704905" comment="qemu-4.2.1-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499926" comment="qemu-arm-4.2.1-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499934" comment="qemu-ipxe-1.0.0+-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499940" comment="qemu-seabios-1.12.1+-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499941" comment="qemu-sgabios-8-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704906" comment="qemu-tools-4.2.1-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499945" comment="qemu-vgabios-1.12.1+-11.22.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009499946" comment="qemu-x86-4.2.1-11.22.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202135477" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-35477</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-35477" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35477" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-35477" ref_url="https://www.suse.com/security/cve/CVE-2021-35477" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a store operation that has an attacker-controlled value.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-35477/">CVE-2021-35477</cve>
	<bugzilla href="https://bugzilla.suse.com/1188985">SUSE bug 1188985</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213556" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3556</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3556" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3556" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3556" ref_url="https://www.suse.com/security/cve/CVE-2021-3556" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: Assigned but a duplicate for CVE-2021-3559.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3556/">CVE-2021-3556</cve>
	<bugzilla href="https://bugzilla.suse.com/1191542">SUSE bug 1191542</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334933" comment="libvirt-daemon is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334936" comment="libvirt-daemon-driver-interface is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334939" comment="libvirt-daemon-driver-network is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334940" comment="libvirt-daemon-driver-nodedev is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334941" comment="libvirt-daemon-driver-nwfilter is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334942" comment="libvirt-daemon-driver-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334943" comment="libvirt-daemon-driver-secret is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334944" comment="libvirt-daemon-driver-storage is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336191" comment="libvirt-daemon-driver-storage-core is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336192" comment="libvirt-daemon-driver-storage-disk is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336193" comment="libvirt-daemon-driver-storage-iscsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336194" comment="libvirt-daemon-driver-storage-logical is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336195" comment="libvirt-daemon-driver-storage-mpath is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336196" comment="libvirt-daemon-driver-storage-rbd is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336197" comment="libvirt-daemon-driver-storage-scsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334946" comment="libvirt-daemon-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336198" comment="libvirt-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213559" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3559</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3559" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3559" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3559" ref_url="https://www.suse.com/security/cve/CVE-2021-3559" source="SUSE CVE"/>
    <description>
    A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3559/">CVE-2021-3559</cve>
	<bugzilla href="https://bugzilla.suse.com/1191542">SUSE bug 1191542</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334933" comment="libvirt-daemon is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334936" comment="libvirt-daemon-driver-interface is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334939" comment="libvirt-daemon-driver-network is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334940" comment="libvirt-daemon-driver-nodedev is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334941" comment="libvirt-daemon-driver-nwfilter is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334942" comment="libvirt-daemon-driver-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334943" comment="libvirt-daemon-driver-secret is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334944" comment="libvirt-daemon-driver-storage is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336191" comment="libvirt-daemon-driver-storage-core is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336192" comment="libvirt-daemon-driver-storage-disk is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336193" comment="libvirt-daemon-driver-storage-iscsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336194" comment="libvirt-daemon-driver-storage-logical is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336195" comment="libvirt-daemon-driver-storage-mpath is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336196" comment="libvirt-daemon-driver-storage-rbd is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336197" comment="libvirt-daemon-driver-storage-scsi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334946" comment="libvirt-daemon-qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336198" comment="libvirt-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213560" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3560</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3560" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3560" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3560" ref_url="https://www.suse.com/security/cve/CVE-2021-3560" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:1842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008927.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008928.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:1844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/008926.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0838-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ABSE3IWWQYLOHOVCNFCOZVXFZAYMJYN4/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1843-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2NCYKG2YTUVFTW5R7DJWWWJGLDWU7XE5/" source="SUSE-SU"/>
    <description>
    It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3560/">CVE-2021-3560</cve>
	<bugzilla href="https://bugzilla.suse.com/1186497">SUSE bug 1186497</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704894" comment="libpolkit0-0.116-3.3.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704895" comment="polkit-0.116-3.3.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213573" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3573</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3573" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3573" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3573" ref_url="https://www.suse.com/security/cve/CVE-2021-3573" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009127.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2305-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009578.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3361-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3401-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3459-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009606.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2305-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BBGE5AIDX3NT46HPS2IYLFESAEFCTG6O/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2352-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2GU2EJMYFONMKDLPFYPCAPSOFXO5ZISM/" source="SUSE-SU"/>
    <description>
    A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR or other way triggers race condition of the call hci_unregister_dev() together with one of the calls hci_sock_blacklist_add(), hci_sock_blacklist_del(), hci_get_conn_info(), hci_get_auth_info(). A privileged local user could use this flaw to crash the system or escalate their privileges on the system. This flaw affects the Linux kernel versions prior to 5.13-rc5.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3573/">CVE-2021-3573</cve>
	<bugzilla href="https://bugzilla.suse.com/1186666">SUSE bug 1186666</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1187054">SUSE bug 1187054</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188172">SUSE bug 1188172</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704907" comment="kernel-default-5.3.18-24.70.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704908" comment="kernel-default-base-5.3.18-24.70.1.9.32.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213580" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3580</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3580" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3580" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3580" ref_url="https://www.suse.com/security/cve/CVE-2021-3580" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:265-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009174.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:271-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009181.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2135-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-June/009079.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:0906-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/D4XGPKTRWLOEATNJNZGQZCO6BZTKIKJ6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2143-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OZAR7UXBYGOSW57CMLBEWIM7KTCVMXFZ/" source="SUSE-SU"/>
    <description>
    A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3580/">CVE-2021-3580</cve>
	<bugzilla href="https://bugzilla.suse.com/1187060">SUSE bug 1187060</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1187892">SUSE bug 1187892</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009503543" comment="libhogweed4-3.4.1-4.18.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009503545" comment="libnettle6-3.4.1-4.18.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213582" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3582</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3582" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3582" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3582" ref_url="https://www.suse.com/security/cve/CVE-2021-3582" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009193.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009241.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2442-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ER233YMIXQ2HKJ4RY4ISGXE5VKXBEVPA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2474-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LOEJDVTTKRPTW4JLAPXEN46YAGYFJMDT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2591-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W3DOLLXJN6UCIAFW2F6437T6CGXJTVQO/" source="SUSE-SU"/>
    <description>
    A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRDMA_CMD_CREATE_MR" command due to improper memory remapping (mremap). This flaw allows a malicious guest to crash the QEMU process on the host. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3582/">CVE-2021-3582</cve>
	<bugzilla href="https://bugzilla.suse.com/1187499">SUSE bug 1187499</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704930" comment="qemu-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626240" comment="qemu-arm-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626248" comment="qemu-ipxe-1.0.0+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626254" comment="qemu-seabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626255" comment="qemu-sgabios-8-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704931" comment="qemu-tools-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626259" comment="qemu-vgabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626260" comment="qemu-x86-4.2.1-11.25.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213588" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3588</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3588" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3588" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3588" ref_url="https://www.suse.com/security/cve/CVE-2021-3588" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:2459-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009204.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2459-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FD7KE3RMFCUKN7TQCYXDCNJGFVIORKJL/" source="SUSE-SU"/>
    <description>
    The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3588/">CVE-2021-3588</cve>
	<bugzilla href="https://bugzilla.suse.com/1187165">SUSE bug 1187165</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336474" comment="libbluetooth3 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213592" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3592</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3592" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3592" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3592" ref_url="https://www.suse.com/security/cve/CVE-2021-3592" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1101-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2958-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14774-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2428-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009225.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009241.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1465-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010895.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011076.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2474-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LOEJDVTTKRPTW4JLAPXEN46YAGYFJMDT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2591-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W3DOLLXJN6UCIAFW2F6437T6CGXJTVQO/" source="SUSE-SU"/>
    <description>
    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3592/">CVE-2021-3592</cve>
	<bugzilla href="https://bugzilla.suse.com/1187364">SUSE bug 1187364</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1187369">SUSE bug 1187369</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704930" comment="qemu-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626240" comment="qemu-arm-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626248" comment="qemu-ipxe-1.0.0+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626254" comment="qemu-seabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626255" comment="qemu-sgabios-8-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704931" comment="qemu-tools-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626259" comment="qemu-vgabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626260" comment="qemu-x86-4.2.1-11.25.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213593" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3593</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3593" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3593" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3593" ref_url="https://www.suse.com/security/cve/CVE-2021-3593" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:2278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012265.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2958-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2428-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009225.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009241.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2941-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/012010.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2474-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LOEJDVTTKRPTW4JLAPXEN46YAGYFJMDT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2591-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W3DOLLXJN6UCIAFW2F6437T6CGXJTVQO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:2941-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3NSGF4F642R2SF6X757XAA52XDMHLLL3/" source="SUSE-SU"/>
    <description>
    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3593/">CVE-2021-3593</cve>
	<bugzilla href="https://bugzilla.suse.com/1187365">SUSE bug 1187365</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704930" comment="qemu-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626240" comment="qemu-arm-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626248" comment="qemu-ipxe-1.0.0+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626254" comment="qemu-seabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626255" comment="qemu-sgabios-8-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704931" comment="qemu-tools-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626259" comment="qemu-vgabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626260" comment="qemu-x86-4.2.1-11.25.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213594" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3594</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3594" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3594" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3594" ref_url="https://www.suse.com/security/cve/CVE-2021-3594" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1101-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2958-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14774-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019812.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2428-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009225.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009241.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1465-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010895.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011076.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2474-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LOEJDVTTKRPTW4JLAPXEN46YAGYFJMDT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2591-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W3DOLLXJN6UCIAFW2F6437T6CGXJTVQO/" source="SUSE-SU"/>
    <description>
    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3594/">CVE-2021-3594</cve>
	<bugzilla href="https://bugzilla.suse.com/1187367">SUSE bug 1187367</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704930" comment="qemu-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626240" comment="qemu-arm-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626248" comment="qemu-ipxe-1.0.0+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626254" comment="qemu-seabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626255" comment="qemu-sgabios-8-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704931" comment="qemu-tools-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626259" comment="qemu-vgabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626260" comment="qemu-x86-4.2.1-11.25.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202135942" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-35942</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-35942" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35942" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-35942" ref_url="https://www.suse.com/security/cve/CVE-2021-35942" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009550.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:384-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:397-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:400-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:403-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009588.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009532.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009539.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009579.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1374-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YZGEXWUJCYCGR3DHTHHZAJYSGQP2SHMN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3291-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TYMYANBGPUFKQ7SIIB3PZLAAR35QYXOR/" source="SUSE-SU"/>
    <description>
    The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-35942/">CVE-2021-35942</cve>
	<bugzilla href="https://bugzilla.suse.com/1187911">SUSE bug 1187911</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192788">SUSE bug 1192788</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009634576" comment="glibc-2.26-13.59.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009634580" comment="glibc-locale-2.26-13.59.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009634581" comment="glibc-locale-base-2.26-13.59.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213595" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3595</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3595" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3595" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3595" ref_url="https://www.suse.com/security/cve/CVE-2021-3595" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1101-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2958-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:2962-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2428-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009225.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009241.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009406.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2957-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009414.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010804.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1465-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010895.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011076.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2474-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LOEJDVTTKRPTW4JLAPXEN46YAGYFJMDT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2591-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W3DOLLXJN6UCIAFW2F6437T6CGXJTVQO/" source="SUSE-SU"/>
    <description>
    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-09-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3595/">CVE-2021-3595</cve>
	<bugzilla href="https://bugzilla.suse.com/1187366">SUSE bug 1187366</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1187376">SUSE bug 1187376</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704930" comment="qemu-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626240" comment="qemu-arm-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626248" comment="qemu-ipxe-1.0.0+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626254" comment="qemu-seabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626255" comment="qemu-sgabios-8-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704931" comment="qemu-tools-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626259" comment="qemu-vgabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626260" comment="qemu-x86-4.2.1-11.25.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213601" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3601</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3601" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3601" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3601" ref_url="https://www.suse.com/security/cve/CVE-2021-3601" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. OpenSSL does not class this issue as a security vulnerability. The trusted CA store should not contain anything that the user does not trust to issue other certificates. Notes: https://github.com/openssl/openssl/issues/5236#issuecomment-1196460611
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-3601/">CVE-2021-3601</cve>
	<bugzilla href="https://bugzilla.suse.com/1189259">SUSE bug 1189259</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334866" comment="libopenssl1_1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333944" comment="openssl-1_1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213607" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3607</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3607" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3607" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3607" ref_url="https://www.suse.com/security/cve/CVE-2021-3607" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009193.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009241.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2442-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ER233YMIXQ2HKJ4RY4ISGXE5VKXBEVPA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2474-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LOEJDVTTKRPTW4JLAPXEN46YAGYFJMDT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2591-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W3DOLLXJN6UCIAFW2F6437T6CGXJTVQO/" source="SUSE-SU"/>
    <description>
    An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3607/">CVE-2021-3607</cve>
	<bugzilla href="https://bugzilla.suse.com/1187539">SUSE bug 1187539</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704930" comment="qemu-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626240" comment="qemu-arm-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626248" comment="qemu-ipxe-1.0.0+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626254" comment="qemu-seabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626255" comment="qemu-sgabios-8-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704931" comment="qemu-tools-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626259" comment="qemu-vgabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626260" comment="qemu-x86-4.2.1-11.25.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213608" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3608</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3608" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3608" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3608" ref_url="https://www.suse.com/security/cve/CVE-2021-3608" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009193.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009241.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2442-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ER233YMIXQ2HKJ4RY4ISGXE5VKXBEVPA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2474-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LOEJDVTTKRPTW4JLAPXEN46YAGYFJMDT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2591-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W3DOLLXJN6UCIAFW2F6437T6CGXJTVQO/" source="SUSE-SU"/>
    <description>
    A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3608/">CVE-2021-3608</cve>
	<bugzilla href="https://bugzilla.suse.com/1187538">SUSE bug 1187538</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704930" comment="qemu-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626240" comment="qemu-arm-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626248" comment="qemu-ipxe-1.0.0+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626254" comment="qemu-seabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626255" comment="qemu-sgabios-8-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704931" comment="qemu-tools-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626259" comment="qemu-vgabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626260" comment="qemu-x86-4.2.1-11.25.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213609" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3609</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3609" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3609" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3609" ref_url="https://www.suse.com/security/cve/CVE-2021-3609" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009160.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009244.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2599-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009260.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009279.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2645-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2746-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009357.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1076-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WT3TYNEJZ7FKJMTYO3DX3Z7B2YCYPEJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2427-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HJIMD6XIKYMKE35TUYXKKYPX4737LEVU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2645-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2WMUIJQF7RUSXDRXECLPMVDE6YOS5WIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2687-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GDBOWLDJQ4K7JKRHIM7AOCKTJO5BY6C5/" source="SUSE-SU"/>
    <description>
    .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3609/">CVE-2021-3609</cve>
	<bugzilla href="https://bugzilla.suse.com/1187215">SUSE bug 1187215</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188323">SUSE bug 1188323</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188720">SUSE bug 1188720</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190276">SUSE bug 1190276</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196810">SUSE bug 1196810</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704910" comment="kernel-default-5.3.18-24.75.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704911" comment="kernel-default-base-5.3.18-24.75.3.9.34.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626892" comment="kernel-rt-5.3.18-45.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213611" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3611</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3611" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3611" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3611" ref_url="https://www.suse.com/security/cve/CVE-2021-3611" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2428-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009193.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2546-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009225.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2563-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009241.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2442-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ER233YMIXQ2HKJ4RY4ISGXE5VKXBEVPA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2474-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LOEJDVTTKRPTW4JLAPXEN46YAGYFJMDT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2591-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/W3DOLLXJN6UCIAFW2F6437T6CGXJTVQO/" source="SUSE-SU"/>
    <description>
    A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability. This flaw affects QEMU versions prior to 7.0.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3611/">CVE-2021-3611</cve>
	<bugzilla href="https://bugzilla.suse.com/1187529">SUSE bug 1187529</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193914">SUSE bug 1193914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704930" comment="qemu-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626240" comment="qemu-arm-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626248" comment="qemu-ipxe-1.0.0+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626254" comment="qemu-seabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626255" comment="qemu-sgabios-8-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704931" comment="qemu-tools-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626259" comment="qemu-vgabios-1.12.1+-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626260" comment="qemu-x86-4.2.1-11.25.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213612" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3612</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3612" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3612" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3612" ref_url="https://www.suse.com/security/cve/CVE-2021-3612" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:598-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009212.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009160.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009244.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2599-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009260.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009279.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2645-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009292.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1076-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WT3TYNEJZ7FKJMTYO3DX3Z7B2YCYPEJZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2645-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2WMUIJQF7RUSXDRXECLPMVDE6YOS5WIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2687-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GDBOWLDJQ4K7JKRHIM7AOCKTJO5BY6C5/" source="SUSE-SU"/>
    <description>
    An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3612/">CVE-2021-3612</cve>
	<bugzilla href="https://bugzilla.suse.com/1187585">SUSE bug 1187585</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704910" comment="kernel-default-5.3.18-24.75.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704911" comment="kernel-default-base-5.3.18-24.75.3.9.34.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626892" comment="kernel-rt-5.3.18-45.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213622" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3622</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3622" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3622" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3622" ref_url="https://www.suse.com/security/cve/CVE-2021-3622" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3201-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3201-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3210-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009502.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1319-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZUSEK4W6EWPU4TCOU42FNZFNKGMKOJLZ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3201-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5FC5F3EO3ROUN3SV32U3TNFWTKZ6B6TA/" source="SUSE-SU"/>
    <description>
    A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3622/">CVE-2021-3622</cve>
	<bugzilla href="https://bugzilla.suse.com/1189060">SUSE bug 1189060</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704946" comment="libhivex0-1.3.14-5.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704947" comment="perl-Win-Hivex-1.3.14-5.6.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202136222" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-36222</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-36222" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36222" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-36222" ref_url="https://www.suse.com/security/cve/CVE-2021-36222" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:292-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010166.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2800-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4428-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013220.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4439-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013221.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1182-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5YD36VO3UYG3QGTYXP2IABP7W52ZZE6X/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2800-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/22SNDEWZFK4UZGGV35YI72FNLVIRJTIF/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0283-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/72ZRNFZ3DE3TJA7HFCVV476YJN6I4B5M/" source="SUSE-SU"/>
    <description>
    ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-36222/">CVE-2021-36222</cve>
	<bugzilla href="https://bugzilla.suse.com/1188571">SUSE bug 1188571</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009626718" comment="krb5-1.16.3-3.21.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213631" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3631</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3631" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3631" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3631" ref_url="https://www.suse.com/security/cve/CVE-2021-3631" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:2471-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-July/009217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009329.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1119-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H5E4Y5JNZAR2C5I2WQMIIPVYTGLK5SBC/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2812-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4QAQWSVV2PRNPOI4R3VBPRTRXS5NLQ5/" source="SUSE-SU"/>
    <description>
    A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3631/">CVE-2021-3631</cve>
	<bugzilla href="https://bugzilla.suse.com/1187871">SUSE bug 1187871</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704914" comment="libvirt-daemon-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704915" comment="libvirt-daemon-driver-interface-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704916" comment="libvirt-daemon-driver-network-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704917" comment="libvirt-daemon-driver-nodedev-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704918" comment="libvirt-daemon-driver-nwfilter-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704919" comment="libvirt-daemon-driver-qemu-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704920" comment="libvirt-daemon-driver-secret-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704921" comment="libvirt-daemon-driver-storage-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704922" comment="libvirt-daemon-driver-storage-core-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704923" comment="libvirt-daemon-driver-storage-disk-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704924" comment="libvirt-daemon-driver-storage-iscsi-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704925" comment="libvirt-daemon-driver-storage-logical-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704926" comment="libvirt-daemon-driver-storage-mpath-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624910" comment="libvirt-daemon-driver-storage-rbd-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704927" comment="libvirt-daemon-driver-storage-scsi-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704928" comment="libvirt-daemon-qemu-6.0.0-13.16.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704929" comment="libvirt-libs-6.0.0-13.16.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213634" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3634</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3634" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3634" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3634" ref_url="https://www.suse.com/security/cve/CVE-2021-3634" source="SUSE CVE"/>
    <description>
    A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically, both of these buffers had shared length variable, which worked as long as these buffers were same. But the key re-exchange operation can also change the key exchange method, which can be based on hash of different size, eventually creating "secret_hash" of different size than the session_id has. This becomes an issue when the session_id memory is zeroed or when it is used again during second key re-exchange.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-04"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3634/">CVE-2021-3634</cve>
	<bugzilla href="https://bugzilla.suse.com/1189608">SUSE bug 1189608</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194948">SUSE bug 1194948</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336436" comment="libssh4 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213635" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3635</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3635" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3635" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3635" ref_url="https://www.suse.com/security/cve/CVE-2021-3635" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.1/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3635/">CVE-2021-3635</cve>
	<bugzilla href="https://bugzilla.suse.com/1189169">SUSE bug 1189169</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213640" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3640</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3640" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3640" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3640" ref_url="https://www.suse.com/security/cve/CVE-2021-3640" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009578.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3361-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3401-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3459-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3640/">CVE-2021-3640</cve>
	<bugzilla href="https://bugzilla.suse.com/1188172">SUSE bug 1188172</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188613">SUSE bug 1188613</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191530">SUSE bug 1191530</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196810">SUSE bug 1196810</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196914">SUSE bug 1196914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213653" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3653</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3653" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3653" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3653" ref_url="https://www.suse.com/security/cve/CVE-2021-3653" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" field, this issue could allow a malicious L1 to enable AVIC support (Advanced Virtual Interrupt Controller) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape. This flaw affects Linux kernel versions prior to 5.14-rc7.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3653/">CVE-2021-3653</cve>
	<bugzilla href="https://bugzilla.suse.com/1189399">SUSE bug 1189399</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189420">SUSE bug 1189420</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196914">SUSE bug 1196914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213655" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3655</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3655" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3655" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3655" ref_url="https://www.suse.com/security/cve/CVE-2021-3655" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3655/">CVE-2021-3655</cve>
	<bugzilla href="https://bugzilla.suse.com/1188563">SUSE bug 1188563</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704995" comment="kernel-default-5.3.18-24.93.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704996" comment="kernel-default-base-5.3.18-24.93.1.9.42.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651700" comment="kernel-rt-5.3.18-57.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213656" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3656</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3656" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3656" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3656" ref_url="https://www.suse.com/security/cve/CVE-2021-3656" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3656/">CVE-2021-3656</cve>
	<bugzilla href="https://bugzilla.suse.com/1189400">SUSE bug 1189400</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189418">SUSE bug 1189418</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213659" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3659</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3659" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3659" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3659" ref_url="https://www.suse.com/security/cve/CVE-2021-3659" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009279.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2644-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2645-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009277.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1142-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BN7VVRY72WW4I46CQCFBKXWN6CBHKRXO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2645-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2WMUIJQF7RUSXDRXECLPMVDE6YOS5WIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2687-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GDBOWLDJQ4K7JKRHIM7AOCKTJO5BY6C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3659/">CVE-2021-3659</cve>
	<bugzilla href="https://bugzilla.suse.com/1188876">SUSE bug 1188876</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704932" comment="kernel-default-5.3.18-24.78.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704933" comment="kernel-default-base-5.3.18-24.78.1.9.36.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628046" comment="kernel-rt-5.3.18-48.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213667" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3667</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3667" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3667" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3667" ref_url="https://www.suse.com/security/cve/CVE-2021-3667" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:2812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3540-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009661.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3586-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009684.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1451-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2CVWPLSZA7CNFAIOW3HV4ZWDNXKWJDSE/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2812-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4QAQWSVV2PRNPOI4R3VBPRTRXS5NLQ5/" source="SUSE-SU"/>
    <description>
    An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3667/">CVE-2021-3667</cve>
	<bugzilla href="https://bugzilla.suse.com/1188843">SUSE bug 1188843</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704977" comment="libvirt-daemon-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704978" comment="libvirt-daemon-driver-interface-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704979" comment="libvirt-daemon-driver-network-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704980" comment="libvirt-daemon-driver-nodedev-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704981" comment="libvirt-daemon-driver-nwfilter-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704982" comment="libvirt-daemon-driver-qemu-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704983" comment="libvirt-daemon-driver-secret-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704984" comment="libvirt-daemon-driver-storage-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704985" comment="libvirt-daemon-driver-storage-core-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704986" comment="libvirt-daemon-driver-storage-disk-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704987" comment="libvirt-daemon-driver-storage-iscsi-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704988" comment="libvirt-daemon-driver-storage-logical-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704989" comment="libvirt-daemon-driver-storage-mpath-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652326" comment="libvirt-daemon-driver-storage-rbd-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704990" comment="libvirt-daemon-driver-storage-scsi-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704991" comment="libvirt-daemon-qemu-6.0.0-13.21.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704992" comment="libvirt-libs-6.0.0-13.21.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213669" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3669</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3669" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3669" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3669" ref_url="https://www.suse.com/security/cve/CVE-2021-3669" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3337-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3447-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009597.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1357-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SS5B6JL55TTUNHHOGTFHK5JQ6EZOF7ZV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1365-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JSK2K2OLYKIFCAMBX4QB7AGV6SKS3BTM/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3338-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H64LCXMISTZ7YB7R4ABO2Y73X23DJFXU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3387-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MHXVHXC6JGHDS7W6EJQF3JKAPVYH3ES5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3447-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IAN74FTXJ7PFHCBV6YMLTPNW7VFYCPFV/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3669/">CVE-2021-3669</cve>
	<bugzilla href="https://bugzilla.suse.com/1188986">SUSE bug 1188986</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704954" comment="kernel-default-5.3.18-24.86.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704955" comment="kernel-default-base-5.3.18-24.86.2.9.40.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651689" comment="kernel-rt-5.3.18-54.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704956" comment="kmod-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704957" comment="kmod-compat-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704958" comment="libkmod2-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704959" comment="perl-Bootloader-0.931-3.5.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202136770" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-36770</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-36770" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36770" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-36770" ref_url="https://www.suse.com/security/cve/CVE-2021-36770" source="SUSE CVE"/>
    <description>
    Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-36770/">CVE-2021-36770</cve>
	<bugzilla href="https://bugzilla.suse.com/1188467">SUSE bug 1188467</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334114" comment="perl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336057" comment="perl-base is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213679" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3679</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3679" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3679" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3679" ref_url="https://www.suse.com/security/cve/CVE-2021-3679" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1142-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BN7VVRY72WW4I46CQCFBKXWN6CBHKRXO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve the resources causing denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3679/">CVE-2021-3679</cve>
	<bugzilla href="https://bugzilla.suse.com/1189057">SUSE bug 1189057</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213682" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3682</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3682" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3682" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3682" ref_url="https://www.suse.com/security/cve/CVE-2021-3682" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2789-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-August/019909.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009332.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009365.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3635-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009705.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1202-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7XTOHNMISPT4N5NUXQJPKV5LQNNGSMFI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2789-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UE3MLTPF62745SPUUDQR6ROYVP4GG6DT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2858-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GGOXRRBMGRJGBNXEGPCZ3JFLXCMIM6A3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3614-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/26KPX43RJBRTCX3JER7CN7MAT4QEGAED/" source="SUSE-SU"/>
    <description>
    A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-3682/">CVE-2021-3682</cve>
	<bugzilla href="https://bugzilla.suse.com/1189145">SUSE bug 1189145</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704934" comment="qemu-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630345" comment="qemu-arm-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630353" comment="qemu-ipxe-1.0.0+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630359" comment="qemu-seabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630360" comment="qemu-sgabios-8-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704935" comment="qemu-tools-4.2.1-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630364" comment="qemu-vgabios-1.12.1+-11.28.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009630365" comment="qemu-x86-4.2.1-11.28.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213711" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3711</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3711" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3711" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3711" ref_url="https://www.suse.com/security/cve/CVE-2021-3711" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:299-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009412.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:304-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009413.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010822.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4428-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013218.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013220.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4439-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013221.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1188-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YXBKWFNVQ5GSDMIZHMMOGHRWWUOWZMJE/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2830-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YOUNRN5SCBRRVEIYDG3G3PFLGVRXKDPG/" source="SUSE-SU"/>
    <description>
    In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-02"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3711/">CVE-2021-3711</cve>
	<bugzilla href="https://bugzilla.suse.com/1189520">SUSE bug 1189520</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190129">SUSE bug 1190129</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192100">SUSE bug 1192100</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205663">SUSE bug 1205663</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704941" comment="libopenssl1_1-1.1.1d-11.27.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704942" comment="openssl-1_1-1.1.1d-11.27.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213712" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3712</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3712" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3712" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3712" ref_url="https://www.suse.com/security/cve/CVE-2021-3712" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009407.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009408.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009409.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:297-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009410.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:298-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009411.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:299-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009412.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:304-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009413.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009435.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009487.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009488.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14791-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14792-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009347.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14801-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14802-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2825-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2826-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2827-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2829-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2833-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2966-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009420.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2966-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2967-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009418.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2968-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009417.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2994-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009429.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2995-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009423.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2996-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009425.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3019-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009433.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3144-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009467.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1188-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YXBKWFNVQ5GSDMIZHMMOGHRWWUOWZMJE/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1189-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JJMNXN2ETVF67Q4UKMXBSCF2LIA5HVUH/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1248-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BTAMI3TGUD3BTSIO4MHIHCP2H4HJWRWI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1261-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UE6BERTPDDZTU2D7PHOS5VANHEPO7VG4/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2827-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZXNTTGRCRZBMWGGU4UK4PHVAAZAFABI2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2830-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YOUNRN5SCBRRVEIYDG3G3PFLGVRXKDPG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2966-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZZPO3HVVYNS6WITBZKOQFXIVLJOK24MR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2994-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/O65IINGUXDYQLSV7GD7SXFUKFY5WYUTA/" source="SUSE-SU"/>
    <description>
    ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own "d2i" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the "data" and "length" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the "data" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3712/">CVE-2021-3712</cve>
	<bugzilla href="https://bugzilla.suse.com/1189521">SUSE bug 1189521</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190129">SUSE bug 1190129</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191640">SUSE bug 1191640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192100">SUSE bug 1192100</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192787">SUSE bug 1192787</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194948">SUSE bug 1194948</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704943" comment="libopenssl1_1-1.1.1d-11.30.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704944" comment="openssl-1_1-1.1.1d-11.30.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213713" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3713</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3713" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3713" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3713" ref_url="https://www.suse.com/security/cve/CVE-2021-3713" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:35-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3519-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3635-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3653-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020738.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1461-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6ANWCSILNO3HSV5PUK6VESGM76PNM5ND/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3604-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VSD5Q5DPWCTYJNLRUS2DHTA3G6VDKLMV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3605-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/POCCYWA7A3O442ZTZU3JW7O7VFGCLOEA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3614-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/26KPX43RJBRTCX3JER7CN7MAT4QEGAED/" source="SUSE-SU"/>
    <description>
    An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice-&gt;data3 and UASDevice-&gt;status3 fields. A malicious guest user could use this flaw to crash QEMU or potentially achieve code execution with the privileges of the QEMU process on the host.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3713/">CVE-2021-3713</cve>
	<bugzilla href="https://bugzilla.suse.com/1189702">SUSE bug 1189702</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704993" comment="qemu-4.2.1-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652933" comment="qemu-arm-4.2.1-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652941" comment="qemu-ipxe-1.0.0+-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652947" comment="qemu-seabios-1.12.1+-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652948" comment="qemu-sgabios-8-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704994" comment="qemu-tools-4.2.1-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652952" comment="qemu-vgabios-1.12.1+-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652953" comment="qemu-x86-4.2.1-11.31.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213715" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3715</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3715" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3715" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3715" ref_url="https://www.suse.com/security/cve/CVE-2021-3715" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3401-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3459-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3715/">CVE-2021-3715</cve>
	<bugzilla href="https://bugzilla.suse.com/1190349">SUSE bug 1190349</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190350">SUSE bug 1190350</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196722">SUSE bug 1196722</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704995" comment="kernel-default-5.3.18-24.93.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704996" comment="kernel-default-base-5.3.18-24.93.1.9.42.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651700" comment="kernel-rt-5.3.18-57.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202137159" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-37159</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-37159" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37159" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-37159" ref_url="https://www.suse.com/security/cve/CVE-2021-37159" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009774.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3807-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009873.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1501-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5J6FJF42AOGK3VQ4EFVDHQENHCDEMVT3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3806-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WLGTBAKURNXDJOZBJTW2QLXJEWT66GSC/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-37159/">CVE-2021-37159</cve>
	<bugzilla href="https://bugzilla.suse.com/1188601">SUSE bug 1188601</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705000" comment="kernel-default-5.3.18-24.96.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705001" comment="kernel-default-base-5.3.18-24.96.1.9.44.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658974" comment="kernel-rt-5.3.18-62.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213732" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3732</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3732" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3732" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3732" ref_url="https://www.suse.com/security/cve/CVE-2021-3732" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-01"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3732/">CVE-2021-3732</cve>
	<bugzilla href="https://bugzilla.suse.com/1189706">SUSE bug 1189706</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213733" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3733</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3733" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3733" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3733" ref_url="https://www.suse.com/security/cve/CVE-2021-3733" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:35-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009628.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009651.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009890.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4015-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009914.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010906.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1418-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7AF3KRDWJVTDRPTV5WLKDBFKVCOCN3FB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3489-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WU6W7MZS6RUFRYSZTBDYHTA2EBBSY2QJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:4104-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KYXM7YGLJSNOU4FYI3M2QXACCQ4SO3AE/" source="SUSE-SU"/>
    <description>
    There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3733/">CVE-2021-3733</cve>
	<bugzilla href="https://bugzilla.suse.com/1189287">SUSE bug 1189287</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009660091" comment="libpython3_6m1_0-3.6.15-3.91.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009660092" comment="python3-3.6.15-3.91.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009660093" comment="python3-base-3.6.15-3.91.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213735" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3735</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3735" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3735" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3735" ref_url="https://www.suse.com/security/cve/CVE-2021-3735" source="SUSE CVE"/>
    <description>
    A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while handling a host-to-device Register FIS (Frame Information Structure) packet from the guest. A privileged user inside the guest could use this flaw to hang the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3735/">CVE-2021-3735</cve>
	<bugzilla href="https://bugzilla.suse.com/1189886">SUSE bug 1189886</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213736" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3736</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3736" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3736" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3736" ref_url="https://www.suse.com/security/cve/CVE-2021-3736" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Mediated devices. This flaw could allow a local attacker to leak internal kernel information.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3736/">CVE-2021-3736</cve>
	<bugzilla href="https://bugzilla.suse.com/1192345">SUSE bug 1192345</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213737" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3737</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3737" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3737" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3737" ref_url="https://www.suse.com/security/cve/CVE-2021-3737" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:35-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009628.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009651.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4015-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009890.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4015-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009914.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010906.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1418-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7AF3KRDWJVTDRPTV5WLKDBFKVCOCN3FB/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3489-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WU6W7MZS6RUFRYSZTBDYHTA2EBBSY2QJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:4104-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KYXM7YGLJSNOU4FYI3M2QXACCQ4SO3AE/" source="SUSE-SU"/>
    <description>
    A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3737/">CVE-2021-3737</cve>
	<bugzilla href="https://bugzilla.suse.com/1189241">SUSE bug 1189241</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009660091" comment="libpython3_6m1_0-3.6.15-3.91.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009660092" comment="python3-3.6.15-3.91.4 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009660093" comment="python3-base-3.6.15-3.91.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213739" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3739</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3739" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3739" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3739" ref_url="https://www.suse.com/security/cve/CVE-2021-3739" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3739/">CVE-2021-3739</cve>
	<bugzilla href="https://bugzilla.suse.com/1189832">SUSE bug 1189832</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213743" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3743</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3743" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3743" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3743" ref_url="https://www.suse.com/security/cve/CVE-2021-3743" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
    <description>
    An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3743/">CVE-2021-3743</cve>
	<bugzilla href="https://bugzilla.suse.com/1189883">SUSE bug 1189883</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213744" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3744</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3744" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3744" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3744" ref_url="https://www.suse.com/security/cve/CVE-2021-3744" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3337-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3389-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-October/020461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3447-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1357-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SS5B6JL55TTUNHHOGTFHK5JQ6EZOF7ZV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1365-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JSK2K2OLYKIFCAMBX4QB7AGV6SKS3BTM/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3338-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H64LCXMISTZ7YB7R4ABO2Y73X23DJFXU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3387-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MHXVHXC6JGHDS7W6EJQF3JKAPVYH3ES5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3447-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IAN74FTXJ7PFHCBV6YMLTPNW7VFYCPFV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3744/">CVE-2021-3744</cve>
	<bugzilla href="https://bugzilla.suse.com/1189884">SUSE bug 1189884</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190534">SUSE bug 1190534</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704954" comment="kernel-default-5.3.18-24.86.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704955" comment="kernel-default-base-5.3.18-24.86.2.9.40.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651689" comment="kernel-rt-5.3.18-54.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704956" comment="kmod-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704957" comment="kmod-compat-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704958" comment="libkmod2-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704959" comment="perl-Bootloader-0.931-3.5.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213748" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3748</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3748" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3748" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3748" ref_url="https://www.suse.com/security/cve/CVE-2021-3748" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:35-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3519-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009697.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3635-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3653-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020738.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1461-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6ANWCSILNO3HSV5PUK6VESGM76PNM5ND/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3604-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VSD5Q5DPWCTYJNLRUS2DHTA3G6VDKLMV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3605-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/POCCYWA7A3O442ZTZU3JW7O7VFGCLOEA/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3614-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/26KPX43RJBRTCX3JER7CN7MAT4QEGAED/" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3748/">CVE-2021-3748</cve>
	<bugzilla href="https://bugzilla.suse.com/1189938">SUSE bug 1189938</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704993" comment="qemu-4.2.1-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652933" comment="qemu-arm-4.2.1-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652941" comment="qemu-ipxe-1.0.0+-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652947" comment="qemu-seabios-1.12.1+-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652948" comment="qemu-sgabios-8-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704994" comment="qemu-tools-4.2.1-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652952" comment="qemu-vgabios-1.12.1+-11.31.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009652953" comment="qemu-x86-4.2.1-11.31.3 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213752" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3752</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3752" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3752" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3752" ref_url="https://www.suse.com/security/cve/CVE-2021-3752" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3337-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3389-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-October/020461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3447-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3684-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1357-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SS5B6JL55TTUNHHOGTFHK5JQ6EZOF7ZV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1365-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JSK2K2OLYKIFCAMBX4QB7AGV6SKS3BTM/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3338-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H64LCXMISTZ7YB7R4ABO2Y73X23DJFXU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3387-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MHXVHXC6JGHDS7W6EJQF3JKAPVYH3ES5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3447-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IAN74FTXJ7PFHCBV6YMLTPNW7VFYCPFV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3752/">CVE-2021-3752</cve>
	<bugzilla href="https://bugzilla.suse.com/1190023">SUSE bug 1190023</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190432">SUSE bug 1190432</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704954" comment="kernel-default-5.3.18-24.86.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704955" comment="kernel-default-base-5.3.18-24.86.2.9.40.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651689" comment="kernel-rt-5.3.18-54.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704956" comment="kmod-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704957" comment="kmod-compat-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704958" comment="libkmod2-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704959" comment="perl-Bootloader-0.931-3.5.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213753" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3753</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3753" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3753" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3753" ref_url="https://www.suse.com/security/cve/CVE-2021-3753" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010396.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data confidentiality.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3753/">CVE-2021-3753</cve>
	<bugzilla href="https://bugzilla.suse.com/1190025">SUSE bug 1190025</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202137576" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-37576</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-37576" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37576" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-37576" ref_url="https://www.suse.com/security/cve/CVE-2021-37576" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2643-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009279.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2644-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2645-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2646-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009277.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2746-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009357.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009359.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1142-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BN7VVRY72WW4I46CQCFBKXWN6CBHKRXO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2645-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2WMUIJQF7RUSXDRXECLPMVDE6YOS5WIN/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2687-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GDBOWLDJQ4K7JKRHIM7AOCKTJO5BY6C5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-37576/">CVE-2021-37576</cve>
	<bugzilla href="https://bugzilla.suse.com/1188838">SUSE bug 1188838</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1188842">SUSE bug 1188842</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190276">SUSE bug 1190276</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704932" comment="kernel-default-5.3.18-24.78.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704933" comment="kernel-default-base-5.3.18-24.78.1.9.36.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009628046" comment="kernel-rt-5.3.18-48.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213759" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3759</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3759" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3759" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3759" ref_url="https://www.suse.com/security/cve/CVE-2021-3759" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3387-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MHXVHXC6JGHDS7W6EJQF3JKAPVYH3ES5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3759/">CVE-2021-3759</cve>
	<bugzilla href="https://bugzilla.suse.com/1190115">SUSE bug 1190115</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213760" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3760</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3760" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3760" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3760" ref_url="https://www.suse.com/security/cve/CVE-2021-3760" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3760/">CVE-2021-3760</cve>
	<bugzilla href="https://bugzilla.suse.com/1190067">SUSE bug 1190067</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704995" comment="kernel-default-5.3.18-24.93.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704996" comment="kernel-default-base-5.3.18-24.93.1.9.42.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651700" comment="kernel-rt-5.3.18-57.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202137600" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-37600</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-37600" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37600" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-37600" ref_url="https://www.suse.com/security/cve/CVE-2021-37600" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:420-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009615.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:428-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:447-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009641.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:467-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009655.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:469-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:35-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:508-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010655.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009610.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3475-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3523-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010651.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1440-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/O37YZAXFT5P25MP6HADS7PSL7LUNUR45/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3474-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KLPFQQ775XYJFXYC4GI3EPDN5KR7OLG7/" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-37600/">CVE-2021-37600</cve>
	<bugzilla href="https://bugzilla.suse.com/1188921">SUSE bug 1188921</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704965" comment="libblkid1-2.33.2-4.16.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704966" comment="libfdisk1-2.33.2-4.16.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704967" comment="libmount1-2.33.2-4.16.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704968" comment="libsmartcols1-2.33.2-4.16.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704969" comment="libuuid1-2.33.2-4.16.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704970" comment="util-linux-2.33.2-4.16.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704971" comment="util-linux-systemd-2.33.2-4.16.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213764" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3764</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3764" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3764" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3764" ref_url="https://www.suse.com/security/cve/CVE-2021-3764" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3337-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3389-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-October/020461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3447-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1357-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SS5B6JL55TTUNHHOGTFHK5JQ6EZOF7ZV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1365-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JSK2K2OLYKIFCAMBX4QB7AGV6SKS3BTM/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3338-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H64LCXMISTZ7YB7R4ABO2Y73X23DJFXU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3387-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MHXVHXC6JGHDS7W6EJQF3JKAPVYH3ES5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3447-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IAN74FTXJ7PFHCBV6YMLTPNW7VFYCPFV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from this vulnerability is to system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3764/">CVE-2021-3764</cve>
	<bugzilla href="https://bugzilla.suse.com/1190534">SUSE bug 1190534</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194518">SUSE bug 1194518</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704954" comment="kernel-default-5.3.18-24.86.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704955" comment="kernel-default-base-5.3.18-24.86.2.9.40.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651689" comment="kernel-rt-5.3.18-54.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704956" comment="kmod-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704957" comment="kmod-compat-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704958" comment="libkmod2-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704959" comment="perl-Bootloader-0.931-3.5.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213772" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3772</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3772" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3772" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3772" ref_url="https://www.suse.com/security/cve/CVE-2021-3772" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3772/">CVE-2021-3772</cve>
	<bugzilla href="https://bugzilla.suse.com/1190351">SUSE bug 1190351</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704995" comment="kernel-default-5.3.18-24.93.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704996" comment="kernel-default-base-5.3.18-24.93.1.9.42.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651700" comment="kernel-rt-5.3.18-57.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202137750" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-37750</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-37750" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37750" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-37750" ref_url="https://www.suse.com/security/cve/CVE-2021-37750" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009607.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:417-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009608.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:419-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009609.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3454-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3454-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009862.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4154-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013053.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1411-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MHCRV6M5JSBYECPOLQFCUXBYMZFVXKCU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3454-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4LN5FUC4TZVB7GKLTDOBR7UQD6W4262A/" source="SUSE-SU"/>
    <description>
    The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-37750/">CVE-2021-37750</cve>
	<bugzilla href="https://bugzilla.suse.com/1189929">SUSE bug 1189929</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704960" comment="krb5-1.16.3-3.24.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213778" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3778</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3778" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3778" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3778" ref_url="https://www.suse.com/security/cve/CVE-2021-3778" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Heap-based Buffer Overflow
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-3778/">CVE-2021-3778</cve>
	<bugzilla href="https://bugzilla.suse.com/1190533">SUSE bug 1190533</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213796" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3796</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3796" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3796" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3796" ref_url="https://www.suse.com/security/cve/CVE-2021-3796" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Use After Free
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-3796/">CVE-2021-3796</cve>
	<bugzilla href="https://bugzilla.suse.com/1190570">SUSE bug 1190570</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213800" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3800</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3800" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3800" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3800" ref_url="https://www.suse.com/security/cve/CVE-2021-3800" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0828-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010435.html" source="SUSE-SU"/>
    <description>
    A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3800/">CVE-2021-3800</cve>
	<bugzilla href="https://bugzilla.suse.com/1191489">SUSE bug 1191489</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009336707" comment="glib2-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336708" comment="libgio-2_0-0 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336711" comment="libglib-2_0-0 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336713" comment="libgmodule-2_0-0 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336715" comment="libgobject-2_0-0 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138160" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38160</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38160" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38160" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38160" ref_url="https://www.suse.com/security/cve/CVE-2021-38160" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009578.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3401-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009594.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3459-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    ** DISPUTED ** In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf-&gt;len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-38160/">CVE-2021-38160</cve>
	<bugzilla href="https://bugzilla.suse.com/1190117">SUSE bug 1190117</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1190118">SUSE bug 1190118</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196914">SUSE bug 1196914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138166" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38166</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38166" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38166" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38166" ref_url="https://www.suse.com/security/cve/CVE-2021-38166" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
    <description>
    In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-38166/">CVE-2021-38166</cve>
	<bugzilla href="https://bugzilla.suse.com/1189233">SUSE bug 1189233</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138185" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38185</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38185" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38185" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38185" ref_url="https://www.suse.com/security/cve/CVE-2021-38185" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009348.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009349.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:286-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009350.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009351.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:290-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009360.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:292-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009441.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009489.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:354-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:355-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:385-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:387-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:660-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14777-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009282.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009331.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2686-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009291.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2689-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:2808-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-August/009333.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:2689-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XORUFH2I27QQWZXGSRUKWLXW5NX5KLXA/" source="SUSE-SU"/>
		<reference ref_id="unknown" ref_url="https://lists.suse.com/archive/suse-security-announce/2007-Jun/0001.html" source="SUSE-SU"/>
    <description>
    GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-38185/">CVE-2021-38185</cve>
	<bugzilla href="https://bugzilla.suse.com/1189206">SUSE bug 1189206</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189486">SUSE bug 1189486</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192364">SUSE bug 1192364</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193391">SUSE bug 1193391</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200733">SUSE bug 1200733</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009631310" comment="cpio-2.12-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138198" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38198</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38198" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38198" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38198" ref_url="https://www.suse.com/security/cve/CVE-2021-38198" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009497.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-38198/">CVE-2021-38198</cve>
	<bugzilla href="https://bugzilla.suse.com/1189262">SUSE bug 1189262</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1189278">SUSE bug 1189278</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196914">SUSE bug 1196914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138199" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38199</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38199" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38199" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38199" ref_url="https://www.suse.com/security/cve/CVE-2021-38199" source="SUSE CVE"/>
    <description>
    fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-38199/">CVE-2021-38199</cve>
	<bugzilla href="https://bugzilla.suse.com/1189265">SUSE bug 1189265</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138200" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38200</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38200" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38200" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38200" ref_url="https://www.suse.com/security/cve/CVE-2021-38200" source="SUSE CVE"/>
    <description>
    arch/powerpc/perf/core-book3s.c in the Linux kernel before 5.12.13, on systems with perf_event_paranoid=-1 and no specific PMU driver support registered, allows local users to cause a denial of service (perf_instruction_pointer NULL pointer dereference and OOPS) via a "perf record" command.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-38200/">CVE-2021-38200</cve>
	<bugzilla href="https://bugzilla.suse.com/1189276">SUSE bug 1189276</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138201" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38201</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38201" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38201" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38201" ref_url="https://www.suse.com/security/cve/CVE-2021-38201" source="SUSE CVE"/>
    <description>
    net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-38201/">CVE-2021-38201</cve>
	<bugzilla href="https://bugzilla.suse.com/1189288">SUSE bug 1189288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138202" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38202</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38202" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38202" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38202" ref_url="https://www.suse.com/security/cve/CVE-2021-38202" source="SUSE CVE"/>
    <description>
    fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-38202/">CVE-2021-38202</cve>
	<bugzilla href="https://bugzilla.suse.com/1189289">SUSE bug 1189289</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138203" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38203</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38203" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38203" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38203" ref_url="https://www.suse.com/security/cve/CVE-2021-38203" source="SUSE CVE"/>
    <description>
    btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-38203/">CVE-2021-38203</cve>
	<bugzilla href="https://bugzilla.suse.com/1189290">SUSE bug 1189290</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138204" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38204</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38204" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38204" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38204" ref_url="https://www.suse.com/security/cve/CVE-2021-38204" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009486.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009499.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3217-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-September/020289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-38204/">CVE-2021-38204</cve>
	<bugzilla href="https://bugzilla.suse.com/1189291">SUSE bug 1189291</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138205" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38205</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38205" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38205" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38205" ref_url="https://www.suse.com/security/cve/CVE-2021-38205" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
    <description>
    drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e., the real IOMEM pointer).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-38205/">CVE-2021-38205</cve>
	<bugzilla href="https://bugzilla.suse.com/1189292">SUSE bug 1189292</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138206" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38206</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38206" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38206" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38206" ref_url="https://www.suse.com/security/cve/CVE-2021-38206" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
    <description>
    The mac80211 subsystem in the Linux kernel before 5.12.13, when a device supporting only 5 GHz is used, allows attackers to cause a denial of service (NULL pointer dereference in the radiotap parser) by injecting a frame with 802.11a rates.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-38206/">CVE-2021-38206</cve>
	<bugzilla href="https://bugzilla.suse.com/1189296">SUSE bug 1189296</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138207" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38207</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38207" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38207" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38207" ref_url="https://www.suse.com/security/cve/CVE-2021-38207" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009508.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1271-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TKO35W4C75JOXT46ZWC6Y4OFM23PXCNX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
    <description>
    drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-38207/">CVE-2021-38207</cve>
	<bugzilla href="https://bugzilla.suse.com/1189298">SUSE bug 1189298</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704948" comment="kernel-default-5.3.18-24.83.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704949" comment="kernel-default-base-5.3.18-24.83.2.9.38.3 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009633320" comment="kernel-rt-5.3.18-51.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138209" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38209</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38209" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38209" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38209" ref_url="https://www.suse.com/security/cve/CVE-2021-38209" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-September/009505.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3205-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009590.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3179-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UNTKFNNFNHHX5QOW7C4SZXLANXGXQCYJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3205-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AUF5M64CM26PNMNFO4R3S57DLRRNSTVG/" source="SUSE-SU"/>
    <description>
    net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX, NF_SYSCTL_CT_EXPECT_MAX, and NF_SYSCTL_CT_BUCKETS sysctls.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-38209/">CVE-2021-38209</cve>
	<bugzilla href="https://bugzilla.suse.com/1189393">SUSE bug 1189393</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138300" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38300</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38300" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38300" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38300" ref_url="https://www.suse.com/security/cve/CVE-2021-38300" source="SUSE CVE"/>
    <description>
    arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed the 128 KB limit of the MIPS architecture.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-38300/">CVE-2021-38300</cve>
	<bugzilla href="https://bugzilla.suse.com/1190427">SUSE bug 1190427</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202138604" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-38604</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-38604" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38604" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-38604" ref_url="https://www.suse.com/security/cve/CVE-2021-38604" source="SUSE CVE"/>
    <description>
    In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-38604/">CVE-2021-38604</cve>
	<bugzilla href="https://bugzilla.suse.com/1189426">SUSE bug 1189426</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333938" comment="glibc is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334828" comment="glibc-locale is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009339499" comment="glibc-locale-base is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213864" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3864</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3864" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3864" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3864" ref_url="https://www.suse.com/security/cve/CVE-2021-3864" source="SUSE CVE"/>
    <description>
    A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern is set to a relative value, its core dump is stored in the current directory with uid:gid permissions. An unprivileged local user with eligible root SUID binary could use this flaw to place core dumps into root-owned directories, potentially resulting in escalation of privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-01"/>
	<updated date="2022-11-05"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3864/">CVE-2021-3864</cve>
	<bugzilla href="https://bugzilla.suse.com/1191281">SUSE bug 1191281</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192449">SUSE bug 1192449</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205059">SUSE bug 1205059</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213872" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3872</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3872" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3872" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3872" ref_url="https://www.suse.com/security/cve/CVE-2021-3872" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Heap-based Buffer Overflow
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3872/">CVE-2021-3872</cve>
	<bugzilla href="https://bugzilla.suse.com/1191893">SUSE bug 1191893</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213892" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3892</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3892" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3892" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3892" ref_url="https://www.suse.com/security/cve/CVE-2021-3892" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-18198. Reason: This candidate is a reservation duplicate of CVE-2019-18198. Notes: All CVE users should reference CVE-2019-18198 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3892/">CVE-2021-3892</cve>
	<bugzilla href="https://bugzilla.suse.com/1192261">SUSE bug 1192261</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213896" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3896</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3896" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3896" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3896" ref_url="https://www.suse.com/security/cve/CVE-2021-3896" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43389. Reason: This candidate is a reservation duplicate of CVE-2021-43389. Notes: All CVE users should reference CVE-2021-43389 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3896/">CVE-2021-3896</cve>
	<bugzilla href="https://bugzilla.suse.com/1191958">SUSE bug 1191958</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704995" comment="kernel-default-5.3.18-24.93.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704996" comment="kernel-default-base-5.3.18-24.93.1.9.42.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651700" comment="kernel-rt-5.3.18-57.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213927" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3927</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3927" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3927" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3927" ref_url="https://www.suse.com/security/cve/CVE-2021-3927" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Heap-based Buffer Overflow
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" href="https://www.suse.com/security/cve/CVE-2021-3927/">CVE-2021-3927</cve>
	<bugzilla href="https://bugzilla.suse.com/1192481">SUSE bug 1192481</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213928" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3928</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3928" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3928" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3928" ref_url="https://www.suse.com/security/cve/CVE-2021-3928" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3228-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3259-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013170.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1144-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1145-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013286.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Use of Uninitialized Variable
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" href="https://www.suse.com/security/cve/CVE-2021-3928/">CVE-2021-3928</cve>
	<bugzilla href="https://bugzilla.suse.com/1192478">SUSE bug 1192478</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213930" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3930</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3930" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3930" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3930" ref_url="https://www.suse.com/security/cve/CVE-2021-3930" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2021:14848-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009799.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0930-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010676.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0930-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VFLDWSRMX7BN3NXC6GXAFPJLCC5D5KIJ/" source="SUSE-SU"/>
    <description>
    An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-3930/">CVE-2021-3930</cve>
	<bugzilla href="https://bugzilla.suse.com/1192525">SUSE bug 1192525</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192526">SUSE bug 1192526</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213947" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3947</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3947" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3947" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3947" ref_url="https://www.suse.com/security/cve/CVE-2021-3947" source="SUSE CVE"/>
    <description>
    A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3947/">CVE-2021-3947</cve>
	<bugzilla href="https://bugzilla.suse.com/1192706">SUSE bug 1192706</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139537" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39537</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39537" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39537" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39537" ref_url="https://www.suse.com/security/cve/CVE-2021-39537" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:423-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:449-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:482-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009758.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:570-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:571-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:572-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009632.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1417-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RTS45TDORJPZD3OEON7W6CTYLNX6KQ3J/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3490-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2IZOG455BIMQ6NKBIPOWITV4SHIG5YT7/" source="SUSE-SU"/>
    <description>
    An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-39537/">CVE-2021-39537</cve>
	<bugzilla href="https://bugzilla.suse.com/1190793">SUSE bug 1190793</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196626">SUSE bug 1196626</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704961" comment="libncurses6-6.1-5.9.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704962" comment="ncurses-utils-6.1-5.9.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704963" comment="terminfo-6.1-5.9.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704964" comment="terminfo-base-6.1-5.9.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139636" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39636</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39636" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39636" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39636" ref_url="https://www.suse.com/security/cve/CVE-2021-39636" source="SUSE CVE"/>
    <description>
    In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-39636/">CVE-2021-39636</cve>
	<bugzilla href="https://bugzilla.suse.com/1193812">SUSE bug 1193812</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139648" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39648</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39648" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39648" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39648" ref_url="https://www.suse.com/security/cve/CVE-2021-39648" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0363-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010216.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0372-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010282.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4ZJSATCJ2GMGCX6RSG2TU2YU4DDOMVQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0370-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ASMTCFCDULHGAOBQUFJH4PHVCQSTF7S6/" source="SUSE-SU"/>
    <description>
    In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-160822094References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-39648/">CVE-2021-39648</cve>
	<bugzilla href="https://bugzilla.suse.com/1193861">SUSE bug 1193861</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009667498" comment="kernel-default-5.3.18-24.102.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667499" comment="kernel-default-base-5.3.18-24.102.1.9.48.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009668286" comment="kernel-rt-5.3.18-73.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139656" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39656</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39656" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39656" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39656" ref_url="https://www.suse.com/security/cve/CVE-2021-39656" source="SUSE CVE"/>
    <description>
    In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174049066References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-39656/">CVE-2021-39656</cve>
	<bugzilla href="https://bugzilla.suse.com/1193862">SUSE bug 1193862</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139657" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39657</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39657" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39657" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39657" ref_url="https://www.suse.com/security/cve/CVE-2021-39657" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0363-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010216.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0372-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010282.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4ZJSATCJ2GMGCX6RSG2TU2YU4DDOMVQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0370-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ASMTCFCDULHGAOBQUFJH4PHVCQSTF7S6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194696049References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-39657/">CVE-2021-39657</cve>
	<bugzilla href="https://bugzilla.suse.com/1193864">SUSE bug 1193864</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009667498" comment="kernel-default-5.3.18-24.102.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667499" comment="kernel-default-base-5.3.18-24.102.1.9.48.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009668286" comment="kernel-rt-5.3.18-73.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213968" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3968</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3968" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3968" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3968" ref_url="https://www.suse.com/security/cve/CVE-2021-3968" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Heap-based Buffer Overflow
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-31"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3968/">CVE-2021-3968</cve>
	<bugzilla href="https://bugzilla.suse.com/1192902">SUSE bug 1192902</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208308">SUSE bug 1208308</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208649">SUSE bug 1208649</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208651">SUSE bug 1208651</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139685" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39685</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39685" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39685" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39685" ref_url="https://www.suse.com/security/cve/CVE-2021-39685" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0363-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010216.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010282.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4ZJSATCJ2GMGCX6RSG2TU2YU4DDOMVQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0370-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ASMTCFCDULHGAOBQUFJH4PHVCQSTF7S6/" source="SUSE-SU"/>
    <description>
    In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210292376References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-39685/">CVE-2021-39685</cve>
	<bugzilla href="https://bugzilla.suse.com/1193802">SUSE bug 1193802</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194459">SUSE bug 1194459</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139686" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39686</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39686" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39686" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39686" ref_url="https://www.suse.com/security/cve/CVE-2021-39686" source="SUSE CVE"/>
    <description>
    In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-200688826References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-39686/">CVE-2021-39686</cve>
	<bugzilla href="https://bugzilla.suse.com/1196954">SUSE bug 1196954</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139698" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39698</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39698" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39698" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39698" ref_url="https://www.suse.com/security/cve/CVE-2021-39698" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010721.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1224-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010774.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1634-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1989-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011242.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2515-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011613.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011614.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011890.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3411-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012391.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3465-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4036-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012948.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013266.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-185125206References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-30"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-39698/">CVE-2021-39698</cve>
	<bugzilla href="https://bugzilla.suse.com/1196956">SUSE bug 1196956</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196959">SUSE bug 1196959</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209225">SUSE bug 1209225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139714" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39714</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39714" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39714" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39714" ref_url="https://www.suse.com/security/cve/CVE-2021-39714" source="SUSE CVE"/>
    <description>
    In ion_buffer_kmap_get of ion.c, there is a possible use-after-free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-205573273References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-39714/">CVE-2021-39714</cve>
	<bugzilla href="https://bugzilla.suse.com/1197214">SUSE bug 1197214</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197218">SUSE bug 1197218</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139715" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39715</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39715" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39715" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39715" ref_url="https://www.suse.com/security/cve/CVE-2021-39715" source="SUSE CVE"/>
    <description>
    In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-178379135References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-39715/">CVE-2021-39715</cve>
	<bugzilla href="https://bugzilla.suse.com/1197210">SUSE bug 1197210</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139725" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39725</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39725" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39725" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39725" ref_url="https://www.suse.com/security/cve/CVE-2021-39725" source="SUSE CVE"/>
    <description>
    In gasket_free_coherent_memory_all of gasket_page_table.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-151454974References: N/A
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-39725/">CVE-2021-39725</cve>
	<bugzilla href="https://bugzilla.suse.com/1197206">SUSE bug 1197206</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213973" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3973</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3973" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3973" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3973" ref_url="https://www.suse.com/security/cve/CVE-2021-3973" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Heap-based Buffer Overflow
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-31"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3973/">CVE-2021-3973</cve>
	<bugzilla href="https://bugzilla.suse.com/1192903">SUSE bug 1192903</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208308">SUSE bug 1208308</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208649">SUSE bug 1208649</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208651">SUSE bug 1208651</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139735" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39735</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39735" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39735" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39735" ref_url="https://www.suse.com/security/cve/CVE-2021-39735" source="SUSE CVE"/>
    <description>
    In gasket_alloc_coherent_memory of gasket_page_table.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-151455484References: N/A
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-39735/">CVE-2021-39735</cve>
	<bugzilla href="https://bugzilla.suse.com/1197205">SUSE bug 1197205</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213975" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3975</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3975" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3975" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3975" ref_url="https://www.suse.com/security/cve/CVE-2021-3975" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0031-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0032-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0041-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0042-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0045-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0045-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0128-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010027.html" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3975/">CVE-2021-3975</cve>
	<bugzilla href="https://bugzilla.suse.com/1192876">SUSE bug 1192876</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009662009" comment="libvirt-daemon-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662012" comment="libvirt-daemon-driver-interface-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662015" comment="libvirt-daemon-driver-network-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662016" comment="libvirt-daemon-driver-nodedev-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662017" comment="libvirt-daemon-driver-nwfilter-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662018" comment="libvirt-daemon-driver-qemu-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662019" comment="libvirt-daemon-driver-secret-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662020" comment="libvirt-daemon-driver-storage-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662021" comment="libvirt-daemon-driver-storage-core-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662022" comment="libvirt-daemon-driver-storage-disk-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662023" comment="libvirt-daemon-driver-storage-iscsi-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662024" comment="libvirt-daemon-driver-storage-logical-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662025" comment="libvirt-daemon-driver-storage-mpath-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662026" comment="libvirt-daemon-driver-storage-rbd-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662027" comment="libvirt-daemon-driver-storage-scsi-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662030" comment="libvirt-daemon-qemu-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662034" comment="libvirt-libs-6.0.0-13.24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139792" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39792</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39792" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39792" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39792" ref_url="https://www.suse.com/security/cve/CVE-2021-39792" source="SUSE CVE"/>
    <description>
    In usb_gadget_giveback_request of core.c, there is a possible use after free out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-161010552References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4.1/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-39792/">CVE-2021-39792</cve>
	<bugzilla href="https://bugzilla.suse.com/1197203">SUSE bug 1197203</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139800" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39800</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39800" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39800" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39800" ref_url="https://www.suse.com/security/cve/CVE-2021-39800" source="SUSE CVE"/>
    <description>
    In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-208277166References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-39800/">CVE-2021-39800</cve>
	<bugzilla href="https://bugzilla.suse.com/1198444">SUSE bug 1198444</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139801" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39801</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39801" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39801" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39801" ref_url="https://www.suse.com/security/cve/CVE-2021-39801" source="SUSE CVE"/>
    <description>
    In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-209791720References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-39801/">CVE-2021-39801</cve>
	<bugzilla href="https://bugzilla.suse.com/1198443">SUSE bug 1198443</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202139802" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-39802</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-39802" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39802" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-39802" ref_url="https://www.suse.com/security/cve/CVE-2021-39802" source="SUSE CVE"/>
    <description>
    In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-213339151References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-39802/">CVE-2021-39802</cve>
	<bugzilla href="https://bugzilla.suse.com/1198445">SUSE bug 1198445</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213981" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3981</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3981" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3981" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3981" ref_url="https://www.suse.com/security/cve/CVE-2021-3981" source="SUSE CVE"/>
    <description>
    A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3981/">CVE-2021-3981</cve>
	<bugzilla href="https://bugzilla.suse.com/1189644">SUSE bug 1189644</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198244">SUSE bug 1198244</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009338902" comment="grub2 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009339065" comment="grub2-arm64-efi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338904" comment="grub2-i386-pc is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338906" comment="grub2-snapper-plugin is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338908" comment="grub2-x86_64-efi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338909" comment="grub2-x86_64-xen is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213984" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3984</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3984" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3984" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3984" ref_url="https://www.suse.com/security/cve/CVE-2021-3984" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Heap-based Buffer Overflow
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3984/">CVE-2021-3984</cve>
	<bugzilla href="https://bugzilla.suse.com/1193298">SUSE bug 1193298</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213995" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3995</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3995" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3995" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3995" ref_url="https://www.suse.com/security/cve/CVE-2021-3995" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:253-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:258-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010538.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0727-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010762.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0727-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GUBUSLRBG42MLRL65HHMLIWQIKS3SKKP/" source="SUSE-SU"/>
    <description>
    A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3995/">CVE-2021-3995</cve>
	<bugzilla href="https://bugzilla.suse.com/1194976">SUSE bug 1194976</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009337634" comment="libblkid1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664921" comment="libfdisk1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664923" comment="libmount1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664926" comment="libsmartcols1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009337635" comment="libuuid1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334326" comment="util-linux is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213996" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3996</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3996" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3996" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3996" ref_url="https://www.suse.com/security/cve/CVE-2021-3996" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:253-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:258-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010538.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010364.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0727-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010762.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0727-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GUBUSLRBG42MLRL65HHMLIWQIKS3SKKP/" source="SUSE-SU"/>
    <description>
    A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3996/">CVE-2021-3996</cve>
	<bugzilla href="https://bugzilla.suse.com/1194976">SUSE bug 1194976</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009337634" comment="libblkid1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664921" comment="libfdisk1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664923" comment="libmount1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664926" comment="libsmartcols1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009337635" comment="libuuid1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334326" comment="util-linux is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213997" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3997</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3997" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3997" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3997" ref_url="https://www.suse.com/security/cve/CVE-2021-3997" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:195-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010286.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:206-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010291.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:207-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010297.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010314.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:39-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0043-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009991.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0539-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010281.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0043-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BMN5QRPEKDGOKDHBMC6SXHPA733I43MV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0539-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VLDAI5QR7ALPYFJ4GNL2TIX7IMLOLXUU/" source="SUSE-SU"/>
    <description>
    A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-3997/">CVE-2021-3997</cve>
	<bugzilla href="https://bugzilla.suse.com/1194178">SUSE bug 1194178</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009336434" comment="libsystemd0 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335309" comment="libudev1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334001" comment="systemd is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009624596" comment="systemd-container is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335313" comment="systemd-sysvinit is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335314" comment="udev is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213998" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3998</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3998" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3998" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3998" ref_url="https://www.suse.com/security/cve/CVE-2021-3998" source="SUSE CVE"/>
    <description>
    A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-3998/">CVE-2021-3998</cve>
	<bugzilla href="https://bugzilla.suse.com/1194620">SUSE bug 1194620</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333938" comment="glibc is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334828" comment="glibc-locale is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009339499" comment="glibc-locale-base is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20213999" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-3999</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-3999" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3999" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-3999" ref_url="https://www.suse.com/security/cve/CVE-2021-3999" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010193.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010226.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010233.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010314.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:286-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010468.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:290-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010514.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0330-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0909-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010485.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010489.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0330-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WUNMTSOEM6LU65NFICFVIHBARFG7LVO7/" source="SUSE-SU"/>
    <description>
    A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-3999/">CVE-2021-3999</cve>
	<bugzilla href="https://bugzilla.suse.com/1194640">SUSE bug 1194640</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196024">SUSE bug 1196024</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196389">SUSE bug 1196389</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199869">SUSE bug 1199869</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200203">SUSE bug 1200203</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669024" comment="glibc-2.26-13.65.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669032" comment="glibc-locale-2.26-13.65.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669033" comment="glibc-locale-base-2.26-13.65.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214001" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4001</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4001" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4001" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4001" ref_url="https://www.suse.com/security/cve/CVE-2021-4001" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010553.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
    <description>
    A race condition was found in the Linux kernel's ebpf verifier between bpf_map_update_elem and bpf_map_freeze due to a missing lock in kernel/bpf/syscall.c. In this flaw, a local user with a special privilege (cap_sys_admin or cap_bpf) can modify the frozen mapped address space. This flaw affects kernel versions prior to 5.16 rc2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-4001/">CVE-2021-4001</cve>
	<bugzilla href="https://bugzilla.suse.com/1192990">SUSE bug 1192990</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192991">SUSE bug 1192991</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658985" comment="kernel-rt-5.3.18-65.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214002" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4002</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4002" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4002" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4002" ref_url="https://www.suse.com/security/cve/CVE-2021-4002" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-4002/">CVE-2021-4002</cve>
	<bugzilla href="https://bugzilla.suse.com/1192946">SUSE bug 1192946</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192973">SUSE bug 1192973</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658985" comment="kernel-rt-5.3.18-65.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214019" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4019</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4019" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4019" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4019" ref_url="https://www.suse.com/security/cve/CVE-2021-4019" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Heap-based Buffer Overflow
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4019/">CVE-2021-4019</cve>
	<bugzilla href="https://bugzilla.suse.com/1193294">SUSE bug 1193294</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214023" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4023</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4023" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4023" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4023" ref_url="https://www.suse.com/security/cve/CVE-2021-4023" source="SUSE CVE"/>
    <description>
    A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a shortage of free space. This flaw allows a local user with permissions to execute io-uring requests to possibly crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4023/">CVE-2021-4023</cve>
	<bugzilla href="https://bugzilla.suse.com/1193107">SUSE bug 1193107</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214024" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4024</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4024" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4024" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4024" ref_url="https://www.suse.com/security/cve/CVE-2021-4024" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:23018-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010347.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013710.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:23018-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5BA2TLW7O5ZURGQUAQUH4HD5SQYNDDZ6/" source="SUSE-SU"/>
    <description>
    A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-4024/">CVE-2021-4024</cve>
	<bugzilla href="https://bugzilla.suse.com/1193166">SUSE bug 1193166</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009343329" comment="podman is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009343330" comment="podman-cni-config is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214028" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4028</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4028" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4028" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4028" ref_url="https://www.suse.com/security/cve/CVE-2021-4028" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010156.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0295-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021589.html" source="SUSE-SU"/>
    <description>
    A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a local attacker could leverage this use-after-free to crash the system or possibly escalate privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-4028/">CVE-2021-4028</cve>
	<bugzilla href="https://bugzilla.suse.com/1193167">SUSE bug 1193167</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193529">SUSE bug 1193529</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214032" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4032</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4032" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4032" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4032" ref_url="https://www.suse.com/security/cve/CVE-2021-4032" source="SUSE CVE"/>
    <description>
    A vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allocation was detected. In this flaw the KVM subsystem may crash the kernel due to mishandling of memory errors that happens during VCPU construction, which allows an attacker with special user privilege to cause a denial of service. This flaw affects kernel versions prior to 5.15 rc7.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4032/">CVE-2021-4032</cve>
	<bugzilla href="https://bugzilla.suse.com/1193187">SUSE bug 1193187</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214034" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4034</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4034" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4034" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4034" ref_url="https://www.suse.com/security/cve/CVE-2021-4034" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010074.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0190-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-January/021462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0191-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010075.html" source="SUSE-SU"/>
		<reference ref_id="TID000020564" ref_url="https://www.suse.com/support/kb/doc/?id=000020564" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0190-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SGEROI6PUOTOXKFIH2MPKUQ3PI6VWLXQ/" source="SUSE-SU"/>
    <description>
    A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-4034/">CVE-2021-4034</cve>
	<bugzilla href="https://bugzilla.suse.com/1194568">SUSE bug 1194568</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195125">SUSE bug 1195125</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195136">SUSE bug 1195136</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195246">SUSE bug 1195246</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195265">SUSE bug 1195265</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195278">SUSE bug 1195278</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195528">SUSE bug 1195528</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195541">SUSE bug 1195541</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196165">SUSE bug 1196165</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196388">SUSE bug 1196388</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664559" comment="libpolkit0-0.116-3.6.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664560" comment="polkit-0.116-3.6.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214044" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4044</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4044" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4044" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4044" ref_url="https://www.suse.com/security/cve/CVE-2021-4044" source="SUSE CVE"/>
    <description>
    Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as SSL_connect() or SSL_do_handshake()) to not indicate success and a subsequent call to SSL_get_error() to return the value SSL_ERROR_WANT_RETRY_VERIFY. This return value is only supposed to be returned by OpenSSL if the application has previously called SSL_CTX_set_cert_verify_callback(). Since most applications do not do this the SSL_ERROR_WANT_RETRY_VERIFY return value from SSL_get_error() will be totally unexpected and applications may not behave correctly as a result. The exact behaviour will depend on the application but it could result in crashes, infinite loops or other similar incorrect responses. This issue is made more serious in combination with a separate bug in OpenSSL 3.0 that will cause X509_verify_cert() to indicate an internal error when processing a certificate chain. This will occur where a certificate does not include the Subject Alternative Name extension but where a Certificate Authority has enforced name constraints. This issue can occur even with valid chains. By combining the two issues an attacker could induce incorrect, application dependent behaviour. Fixed in OpenSSL 3.0.1 (Affected 3.0.0).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4044/">CVE-2021-4044</cve>
	<bugzilla href="https://bugzilla.suse.com/1193740">SUSE bug 1193740</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334866" comment="libopenssl1_1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333944" comment="openssl-1_1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202140490" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-40490</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-40490" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40490" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-40490" ref_url="https://www.suse.com/security/cve/CVE-2021-40490" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009703.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3337-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009568.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3386-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009580.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3388-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009582.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3389-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-October/020461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3447-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009597.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1357-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SS5B6JL55TTUNHHOGTFHK5JQ6EZOF7ZV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1365-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JSK2K2OLYKIFCAMBX4QB7AGV6SKS3BTM/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3338-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/H64LCXMISTZ7YB7R4ABO2Y73X23DJFXU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3387-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MHXVHXC6JGHDS7W6EJQF3JKAPVYH3ES5/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3447-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IAN74FTXJ7PFHCBV6YMLTPNW7VFYCPFV/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-40490/">CVE-2021-40490</cve>
	<bugzilla href="https://bugzilla.suse.com/1190159">SUSE bug 1190159</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192775">SUSE bug 1192775</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704954" comment="kernel-default-5.3.18-24.86.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704955" comment="kernel-default-base-5.3.18-24.86.2.9.40.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651689" comment="kernel-rt-5.3.18-54.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704956" comment="kmod-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704957" comment="kmod-compat-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704958" comment="libkmod2-25-6.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704959" comment="perl-Bootloader-0.931-3.5.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214083" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4083</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4083" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4083" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4083" ref_url="https://www.suse.com/security/cve/CVE-2021-4083" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0289-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0372-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0418-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010228.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0552-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S44U3IKMS3KZS626YQ5ZYDHA2HLKQNER/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0198-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JVCSEXTJ2SI3QLMCUUQNNUT3HNZQJIML/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system. This flaw affects Linux kernel versions prior to 5.16-rc4.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-4083/">CVE-2021-4083</cve>
	<bugzilla href="https://bugzilla.suse.com/1193727">SUSE bug 1193727</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194460">SUSE bug 1194460</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196722">SUSE bug 1196722</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662947" comment="kernel-rt-5.3.18-68.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214090" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4090</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4090" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4090" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4090" ref_url="https://www.suse.com/security/cve/CVE-2021-4090" source="SUSE CVE"/>
    <description>
    An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4090/">CVE-2021-4090</cve>
	<bugzilla href="https://bugzilla.suse.com/1193663">SUSE bug 1193663</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214093" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4093</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4093" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4093" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4093" ref_url="https://www.suse.com/security/cve/CVE-2021-4093" source="SUSE CVE"/>
    <description>
    A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for example, outs or ins) using the exit reason SVM_EXIT_IOIO. This issue results in a crash of the entire system or a potential guest-to-host escape scenario.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-4093/">CVE-2021-4093</cve>
	<bugzilla href="https://bugzilla.suse.com/1193716">SUSE bug 1193716</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214095" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4095</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4095" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4095" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4095" ref_url="https://www.suse.com/security/cve/CVE-2021-4095" source="SUSE CVE"/>
    <description>
    A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU context. An unprivileged local attacker on the host may use this flaw to cause a kernel oops condition and thus a denial of service by issuing a KVM_XEN_HVM_SET_ATTR ioctl. This flaw affects Linux kernel versions prior to 5.17-rc1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4095/">CVE-2021-4095</cve>
	<bugzilla href="https://bugzilla.suse.com/1193769">SUSE bug 1193769</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202141073" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-41073</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-41073" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41073" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-41073" ref_url="https://www.suse.com/security/cve/CVE-2021-41073" source="SUSE CVE"/>
    <description>
    loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/&lt;pid&gt;/maps for exploitation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-41073/">CVE-2021-41073</cve>
	<bugzilla href="https://bugzilla.suse.com/1190664">SUSE bug 1190664</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202141089" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-41089</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-41089" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41089" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-41089" ref_url="https://www.suse.com/security/cve/CVE-2021-41089" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010123.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0334-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010185.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1404-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L7ADRJZ4HKOCVZC5ZKIM4MD6EZEHBNB3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3506-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NP4XGHFKECRFSI6UYXER53KXVGP66EHQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0334-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ULRUJXC3YBVKDKJAERWLY6BKJ7U3246G/" source="SUSE-SU"/>
    <description>
    Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers do not need to be restarted.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="3.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-41089/">CVE-2021-41089</cve>
	<bugzilla href="https://bugzilla.suse.com/1191015">SUSE bug 1191015</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191355">SUSE bug 1191355</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705036" comment="containerd-1.4.12-60.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705037" comment="docker-20.10.12_ce-159.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651739" comment="runc-1.0.2-23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202141091" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-41091</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-41091" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41091" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-41091" ref_url="https://www.suse.com/security/cve/CVE-2021-41091" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010123.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0334-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010185.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1404-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L7ADRJZ4HKOCVZC5ZKIM4MD6EZEHBNB3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3506-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NP4XGHFKECRFSI6UYXER53KXVGP66EHQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0334-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ULRUJXC3YBVKDKJAERWLY6BKJ7U3246G/" source="SUSE-SU"/>
    <description>
    Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as `setuid`), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade limit access to the host to trusted users. Limit access to host volumes to trusted containers.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-41091/">CVE-2021-41091</cve>
	<bugzilla href="https://bugzilla.suse.com/1191355">SUSE bug 1191355</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191434">SUSE bug 1191434</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705036" comment="containerd-1.4.12-60.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705037" comment="docker-20.10.12_ce-159.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651739" comment="runc-1.0.2-23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202141092" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-41092</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-41092" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41092" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-41092" ref_url="https://www.suse.com/security/cve/CVE-2021-41092" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010123.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0334-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010185.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1404-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L7ADRJZ4HKOCVZC5ZKIM4MD6EZEHBNB3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3506-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NP4XGHFKECRFSI6UYXER53KXVGP66EHQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0334-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ULRUJXC3YBVKDKJAERWLY6BKJ7U3246G/" source="SUSE-SU"/>
    <description>
    Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-registry.example.com` with a misconfigured configuration file (typically `~/.docker/config.json`) listing a `credsStore` or `credHelpers` that could not be executed would result in any provided credentials being sent to `registry-1.docker.io` rather than the intended private registry. This bug has been fixed in Docker CLI 20.10.9. Users should update to this version as soon as possible. For users unable to update ensure that any configured credsStore or credHelpers entries in the configuration file reference an installed credential helper that is executable and on the PATH.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.4/CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-41092/">CVE-2021-41092</cve>
	<bugzilla href="https://bugzilla.suse.com/1191334">SUSE bug 1191334</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191355">SUSE bug 1191355</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705036" comment="containerd-1.4.12-60.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705037" comment="docker-20.10.12_ce-159.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651739" comment="runc-1.0.2-23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202141103" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-41103</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-41103" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41103" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-41103" ref_url="https://www.suse.com/security/cve/CVE-2021-41103" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2021:741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009653.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009654.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009674.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-October/009645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010123.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0334-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010185.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1404-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L7ADRJZ4HKOCVZC5ZKIM4MD6EZEHBNB3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3506-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NP4XGHFKECRFSI6UYXER53KXVGP66EHQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0334-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ULRUJXC3YBVKDKJAERWLY6BKJ7U3246G/" source="SUSE-SU"/>
    <description>
    containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as setuid), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files. This vulnerability has been fixed in containerd 1.4.11 and containerd 1.5.7. Users should update to these version when they are released and may restart containers or update directory permissions to mitigate the vulnerability. Users unable to update should limit access to the host to trusted users. Update directory permission on container bundles directories.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-41103/">CVE-2021-41103</cve>
	<bugzilla href="https://bugzilla.suse.com/1191121">SUSE bug 1191121</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191355">SUSE bug 1191355</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705036" comment="containerd-1.4.12-60.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705037" comment="docker-20.10.12_ce-159.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651739" comment="runc-1.0.2-23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214115" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4115</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4115" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4115" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4115" ref_url="https://www.suse.com/security/cve/CVE-2021-4115" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0524-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010277.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0525-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0525-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013660.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0525-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/D6R7S5GYVKZ4LZLTJ5KNEDZRGJISXBAZ/" source="SUSE-SU"/>
    <description>
    There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-08"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-4115/">CVE-2021-4115</cve>
	<bugzilla href="https://bugzilla.suse.com/1195542">SUSE bug 1195542</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705038" comment="libpolkit0-0.116-3.9.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705039" comment="polkit-0.116-3.9.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202141190" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-41190</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-41190" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41190" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-41190" ref_url="https://www.suse.com/security/cve/CVE-2021-41190" source="SUSE CVE"/>
		<reference ref_id="GHSA-qq97-vm5h-rrhg" ref_url="https://github.com/distribution/distribution/security/advisories//GHSA-qq97-vm5h-rrhg" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0213-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010123.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0334-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:23018-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010347.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013710.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1525-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L3AGIEOXZIUUEYYMWKJCJCQI7V235UTR/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0334-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ULRUJXC3YBVKDKJAERWLY6BKJ7U3246G/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:23018-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5BA2TLW7O5ZURGQUAQUH4HD5SQYNDDZ6/" source="SUSE-SU"/>
    <description>
    The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both “manifests” and “layers” fields could be interpreted as either a manifest or an index in the absence of an accompanying Content-Type header. If a Content-Type header changed between two pulls of the same digest, a client may interpret the resulting content differently. The OCI Distribution Specification has been updated to require that a mediaType value present in a manifest or index match the Content-Type header used during the push and pull operations. Clients pulling from a registry may distrust the Content-Type header and reject an ambiguous document that contains both “manifests” and “layers” fields or “manifests” and “config” fields if they are unable to update to version 1.0.1 of the spec.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-12"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2021-41190/">CVE-2021-41190</cve>
	<bugzilla href="https://bugzilla.suse.com/1193273">SUSE bug 1193273</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705036" comment="containerd-1.4.12-60.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705037" comment="docker-20.10.12_ce-159.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214122" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4122</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4122" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4122" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4122" ref_url="https://www.suse.com/security/cve/CVE-2021-4122" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0144-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010043.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0144-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ILTMKWZNQBSX2H2MPF3XKXVDEDPDYAIB/" source="SUSE-SU"/>
    <description>
    It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-4122/">CVE-2021-4122</cve>
	<bugzilla href="https://bugzilla.suse.com/1194469">SUSE bug 1194469</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009339165" comment="cryptsetup is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009339166" comment="libcryptsetup12 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214135" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4135</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4135" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4135" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4135" ref_url="https://www.suse.com/security/cve/CVE-2021-4135" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0289-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0372-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S44U3IKMS3KZS626YQ5ZYDHA2HLKQNER/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0198-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JVCSEXTJ2SI3QLMCUUQNNUT3HNZQJIML/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for the device such that function nsim_map_alloc_elem being called. A local user could use this flaw to get unauthorized access to some data.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-4135/">CVE-2021-4135</cve>
	<bugzilla href="https://bugzilla.suse.com/1193927">SUSE bug 1193927</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662947" comment="kernel-rt-5.3.18-68.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214136" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4136</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4136" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4136" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4136" ref_url="https://www.suse.com/security/cve/CVE-2021-4136" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Heap-based Buffer Overflow
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-31"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-4136/">CVE-2021-4136</cve>
	<bugzilla href="https://bugzilla.suse.com/1193905">SUSE bug 1193905</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208308">SUSE bug 1208308</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208649">SUSE bug 1208649</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208651">SUSE bug 1208651</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214145" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4145</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4145" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4145" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4145" ref_url="https://www.suse.com/security/cve/CVE-2021-4145" source="SUSE CVE"/>
    <description>
    A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4145/">CVE-2021-4145</cve>
	<bugzilla href="https://bugzilla.suse.com/1193995">SUSE bug 1193995</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214147" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4147</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4147" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4147" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4147" ref_url="https://www.suse.com/security/cve/CVE-2021-4147" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:35-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0021-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009962.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0031-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0032-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009972.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0041-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0042-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0045-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0045-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0128-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010027.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0021-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4GRZCYHIJFWN3FE3P7JJYRY7F7UO2HTA/" source="SUSE-SU"/>
    <description>
    A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4147/">CVE-2021-4147</cve>
	<bugzilla href="https://bugzilla.suse.com/1194041">SUSE bug 1194041</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194313">SUSE bug 1194313</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009662009" comment="libvirt-daemon-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662012" comment="libvirt-daemon-driver-interface-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662015" comment="libvirt-daemon-driver-network-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662016" comment="libvirt-daemon-driver-nodedev-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662017" comment="libvirt-daemon-driver-nwfilter-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662018" comment="libvirt-daemon-driver-qemu-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662019" comment="libvirt-daemon-driver-secret-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662020" comment="libvirt-daemon-driver-storage-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662021" comment="libvirt-daemon-driver-storage-core-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662022" comment="libvirt-daemon-driver-storage-disk-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662023" comment="libvirt-daemon-driver-storage-iscsi-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662024" comment="libvirt-daemon-driver-storage-logical-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662025" comment="libvirt-daemon-driver-storage-mpath-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662026" comment="libvirt-daemon-driver-storage-rbd-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662027" comment="libvirt-daemon-driver-storage-scsi-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662030" comment="libvirt-daemon-qemu-6.0.0-13.24.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662034" comment="libvirt-libs-6.0.0-13.24.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214148" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4148</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4148" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4148" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4148" ref_url="https://www.suse.com/security/cve/CVE-2021-4148" source="SUSE CVE"/>
    <description>
    A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4148/">CVE-2021-4148</cve>
	<bugzilla href="https://bugzilla.suse.com/1193983">SUSE bug 1193983</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214149" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4149</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4149" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4149" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4149" ref_url="https://www.suse.com/security/cve/CVE-2021-4149" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0289-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S44U3IKMS3KZS626YQ5ZYDHA2HLKQNER/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0198-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JVCSEXTJ2SI3QLMCUUQNNUT3HNZQJIML/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4149/">CVE-2021-4149</cve>
	<bugzilla href="https://bugzilla.suse.com/1194001">SUSE bug 1194001</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662947" comment="kernel-rt-5.3.18-68.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214150" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4150</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4150" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4150" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4150" ref_url="https://www.suse.com/security/cve/CVE-2021-4150" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call fails when adding a partition to the disk.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4150/">CVE-2021-4150</cve>
	<bugzilla href="https://bugzilla.suse.com/1193994">SUSE bug 1193994</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214154" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4154</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4154" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4154" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4154" ref_url="https://www.suse.com/security/cve/CVE-2021-4154" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0292-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0295-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1669-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011033.html" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-4154/">CVE-2021-4154</cve>
	<bugzilla href="https://bugzilla.suse.com/1193842">SUSE bug 1193842</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194461">SUSE bug 1194461</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214158" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4158</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4158" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4158" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4158" ref_url="https://www.suse.com/security/cve/CVE-2021-4158" source="SUSE CVE"/>
    <description>
    A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4158/">CVE-2021-4158</cve>
	<bugzilla href="https://bugzilla.suse.com/1194063">SUSE bug 1194063</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214160" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4160</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4160" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4160" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4160" ref_url="https://www.suse.com/security/cve/CVE-2021-4160" source="SUSE CVE"/>
    <description>
    There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH private key among multiple clients, which is no longer an option since CVE-2016-0701. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0.0. It was addressed in the releases of 1.1.1m and 3.0.1 on the 15th of December 2021. For the 1.0.2 release it is addressed in git commit 6fc1aaaf3 that is available to premium support customers only. It will be made available in 1.0.2zc when it is released. The issue only affects OpenSSL on MIPS platforms. Fixed in OpenSSL 3.0.1 (Affected 3.0.0). Fixed in OpenSSL 1.1.1m (Affected 1.1.1-1.1.1l). Fixed in OpenSSL 1.0.2zc-dev (Affected 1.0.2-1.0.2zb).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-4160/">CVE-2021-4160</cve>
	<bugzilla href="https://bugzilla.suse.com/1195379">SUSE bug 1195379</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334866" comment="libopenssl1_1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333944" comment="openssl-1_1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202141617" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-41617</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-41617" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41617" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-41617" ref_url="https://www.suse.com/security/cve/CVE-2021-41617" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14847-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009807.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14870-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009814.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3887-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009854.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3950-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009857.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3951-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0805-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010415.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3950-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BEK24NI33V77MMNQQN72LO2RGAF23X76/" source="SUSE-SU"/>
    <description>
    sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-41617/">CVE-2021-41617</cve>
	<bugzilla href="https://bugzilla.suse.com/1190975">SUSE bug 1190975</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193497">SUSE bug 1193497</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196721">SUSE bug 1196721</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200782">SUSE bug 1200782</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205056">SUSE bug 1205056</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1212247">SUSE bug 1212247</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1212281">SUSE bug 1212281</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671497" comment="openssh-8.1p1-5.21.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214173" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4173</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4173" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4173" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4173" ref_url="https://www.suse.com/security/cve/CVE-2021-4173" source="SUSE CVE"/>
    <description>
    vim is vulnerable to Use After Free
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4173/">CVE-2021-4173</cve>
	<bugzilla href="https://bugzilla.suse.com/1194108">SUSE bug 1194108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202141816" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-41816</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-41816" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41816" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-41816" ref_url="https://www.suse.com/security/cve/CVE-2021-41816" source="SUSE CVE"/>
    <description>
    CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-41816/">CVE-2021-41816</cve>
	<bugzilla href="https://bugzilla.suse.com/1193080">SUSE bug 1193080</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009348236" comment="libruby2_5-2_5 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348228" comment="ruby2.5 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348239" comment="ruby2.5-stdlib is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202141817" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-41817</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-41817" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41817" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-41817" ref_url="https://www.suse.com/security/cve/CVE-2021-41817" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:862-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010920.html" source="SUSE-SU"/>
    <description>
    Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-41817/">CVE-2021-41817</cve>
	<bugzilla href="https://bugzilla.suse.com/1193035">SUSE bug 1193035</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009680329" comment="libruby2_5-2_5-2.5.9-150000.4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680330" comment="ruby2.5-2.5.9-150000.4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680333" comment="ruby2.5-stdlib-2.5.9-150000.4.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202141864" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-41864</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-41864" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41864" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-41864" ref_url="https://www.suse.com/security/cve/CVE-2021-41864" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3684-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3692-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3712-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3735-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3737-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3742-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-41864/">CVE-2021-41864</cve>
	<bugzilla href="https://bugzilla.suse.com/1191317">SUSE bug 1191317</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191318">SUSE bug 1191318</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704995" comment="kernel-default-5.3.18-24.93.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704996" comment="kernel-default-base-5.3.18-24.93.1.9.42.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651700" comment="kernel-rt-5.3.18-57.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214187" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4187</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4187" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4187" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4187" ref_url="https://www.suse.com/security/cve/CVE-2021-4187" source="SUSE CVE"/>
    <description>
    vim is vulnerable to Use After Free
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2021-4187/">CVE-2021-4187</cve>
	<bugzilla href="https://bugzilla.suse.com/1194301">SUSE bug 1194301</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214193" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4193</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4193" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4193" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4193" ref_url="https://www.suse.com/security/cve/CVE-2021-4193" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Out-of-bounds Read
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-4193/">CVE-2021-4193</cve>
	<bugzilla href="https://bugzilla.suse.com/1194216">SUSE bug 1194216</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214197" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4197</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4197" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4197" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4197" ref_url="https://www.suse.com/security/cve/CVE-2021-4197" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0289-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0372-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S44U3IKMS3KZS626YQ5ZYDHA2HLKQNER/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0198-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JVCSEXTJ2SI3QLMCUUQNNUT3HNZQJIML/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2021-4197/">CVE-2021-4197</cve>
	<bugzilla href="https://bugzilla.suse.com/1194302">SUSE bug 1194302</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662947" comment="kernel-rt-5.3.18-68.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202142008" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-42008</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-42008" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42008" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-42008" ref_url="https://www.suse.com/security/cve/CVE-2021-42008" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-42008/">CVE-2021-42008</cve>
	<bugzilla href="https://bugzilla.suse.com/1191315">SUSE bug 1191315</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1191660">SUSE bug 1191660</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196722">SUSE bug 1196722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196810">SUSE bug 1196810</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196914">SUSE bug 1196914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704995" comment="kernel-default-5.3.18-24.93.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704996" comment="kernel-default-base-5.3.18-24.93.1.9.42.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651700" comment="kernel-rt-5.3.18-57.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214202" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4202</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4202" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4202" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4202" ref_url="https://www.suse.com/security/cve/CVE-2021-4202" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0289-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0372-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0418-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010228.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0552-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S44U3IKMS3KZS626YQ5ZYDHA2HLKQNER/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0198-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JVCSEXTJ2SI3QLMCUUQNNUT3HNZQJIML/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed, leading to a privilege escalation problem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-4202/">CVE-2021-4202</cve>
	<bugzilla href="https://bugzilla.suse.com/1194529">SUSE bug 1194529</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194533">SUSE bug 1194533</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662947" comment="kernel-rt-5.3.18-68.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214204" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4204</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4204" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4204" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4204" ref_url="https://www.suse.com/security/cve/CVE-2021-4204" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-4204/">CVE-2021-4204</cve>
	<bugzilla href="https://bugzilla.suse.com/1194111">SUSE bug 1194111</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214206" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4206</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4206" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4206" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4206" ref_url="https://www.suse.com/security/cve/CVE-2021-4206" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:2254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2260-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011391.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3594-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015047.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-03"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-4206/">CVE-2021-4206</cve>
	<bugzilla href="https://bugzilla.suse.com/1198035">SUSE bug 1198035</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1211582">SUSE bug 1211582</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214207" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4207</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4207" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4207" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4207" ref_url="https://www.suse.com/security/cve/CVE-2021-4207" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:2254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011388.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2260-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011391.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3594-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3015-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030627.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor-&gt;header.width` and `cursor-&gt;header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-07-29"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-4207/">CVE-2021-4207</cve>
	<bugzilla href="https://bugzilla.suse.com/1198037">SUSE bug 1198037</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334819" comment="xen-libs is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214209" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4209</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4209" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4209" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4209" ref_url="https://www.suse.com/security/cve/CVE-2021-4209" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1854-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1855-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:252-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010375.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010514.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010334.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010333.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0717-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010350.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011930.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0717-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RI5PFWTNO6UDYFJ3HLMKV5PQYAJ77E46/" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4209/">CVE-2021-4209</cve>
	<bugzilla href="https://bugzilla.suse.com/1196167">SUSE bug 1196167</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705040" comment="libgnutls30-3.6.7-14.16.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20214218" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-4218</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-4218" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4218" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-4218" ref_url="https://www.suse.com/security/cve/CVE-2021-4218" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA counters. Reading the counter sysctl panics the system. This flaw allows a local attacker with local access to cause a denial of service while the system reboots. The issue is specific to CentOS/RHEL.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-4218/">CVE-2021-4218</cve>
	<bugzilla href="https://bugzilla.suse.com/1195374">SUSE bug 1195374</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202142252" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-42252</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-42252" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42252" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-42252" ref_url="https://www.suse.com/security/cve/CVE-2021-42252" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3969-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-42252/">CVE-2021-42252</cve>
	<bugzilla href="https://bugzilla.suse.com/1190479">SUSE bug 1190479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192444">SUSE bug 1192444</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704995" comment="kernel-default-5.3.18-24.93.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704996" comment="kernel-default-base-5.3.18-24.93.1.9.42.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651700" comment="kernel-rt-5.3.18-57.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202142327" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-42327</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-42327" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42327" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-42327" ref_url="https://www.suse.com/security/cve/CVE-2021-42327" source="SUSE CVE"/>
    <description>
    dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display drivers debug filesystem. There are no checks on size within parse_write_buffer_into_params when it uses the size of copy_from_user to copy a userspace buffer into a 40-byte heap buffer.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-42327/">CVE-2021-42327</cve>
	<bugzilla href="https://bugzilla.suse.com/1191949">SUSE bug 1191949</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202142739" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-42739</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-42739" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42739" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-42739" ref_url="https://www.suse.com/security/cve/CVE-2021-42739" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3748-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020791.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3876-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009810.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010144.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010158.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010157.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010156.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0292-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0295-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021589.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0296-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010167.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0298-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0327-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010186.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0328-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010184.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3876-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JOIHHN3KQX7O34NG25NJOF7PFEZF2TVP/" source="SUSE-SU"/>
    <description>
    A heap-based buffer overflow flaw was found in the Linux kernel FireDTV media card driver, where the user calls the CA_SEND_MSG ioctl. This flaw allows a local user of the host machine to crash the system or escalate privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-42739/">CVE-2021-42739</cve>
	<bugzilla href="https://bugzilla.suse.com/1184673">SUSE bug 1184673</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1192036">SUSE bug 1192036</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196722">SUSE bug 1196722</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196914">SUSE bug 1196914</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704995" comment="kernel-default-5.3.18-24.93.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704996" comment="kernel-default-base-5.3.18-24.93.1.9.42.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651700" comment="kernel-rt-5.3.18-57.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202142771" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-42771</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-42771" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42771" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-42771" ref_url="https://www.suse.com/security/cve/CVE-2021-42771" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4161-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009933.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0028-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0029-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3590-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012537.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1553-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WAKYSLN4RPESEDQ7LN7KPRMYQUFA4SYU/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3945-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3M6C27L6BK2YIQKO3YT5OHAJOGRYCEHB/" source="SUSE-SU"/>
    <description>
    Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-16"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-42771/">CVE-2021-42771</cve>
	<bugzilla href="https://bugzilla.suse.com/1185768">SUSE bug 1185768</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658530" comment="python3-Babel-2.8.0-3.3.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143056" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43056</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43056" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43056" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43056" ref_url="https://www.suse.com/security/cve/CVE-2021-43056" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3641-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3642-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009757.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1460-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MLGTNISZMAYBWA26GZHGZYQYWHM3VSZI/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1477-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/J325P6NPH7BF7P7B3LO6FGQNCTFNGKEW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3641-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RDPFUBRGNGPD3YZQTYFCSNGZKH75ZKUP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3655-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ET2XZDZ74SKULHCBR4GCFG3KJRMSHJQQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel for powerpc before 5.14.15. It allows a malicious KVM guest to crash the host, when the host is running on Power8, due to an arch/powerpc/kvm/book3s_hv_rmhandlers.S implementation bug in the handling of the SRR1 register values.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-43056/">CVE-2021-43056</cve>
	<bugzilla href="https://bugzilla.suse.com/1192107">SUSE bug 1192107</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009704995" comment="kernel-default-5.3.18-24.93.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009704996" comment="kernel-default-base-5.3.18-24.93.1.9.42.5 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009651700" comment="kernel-rt-5.3.18-57.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143057" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43057</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43057" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43057" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43057" ref_url="https://www.suse.com/security/cve/CVE-2021-43057" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.14.8. A use-after-free in selinux_ptrace_traceme (aka the SELinux handler for PTRACE_TRACEME) could be used by local attackers to cause memory corruption and escalate privileges, aka CID-a3727a8bac0a. This occurs because of an attempt to access the subjective credentials of another task.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-43057/">CVE-2021-43057</cve>
	<bugzilla href="https://bugzilla.suse.com/1192260">SUSE bug 1192260</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143085" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43085</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43085" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43085" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43085" ref_url="https://www.suse.com/security/cve/CVE-2021-43085" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2021-43085/">CVE-2021-43085</cve>
	<bugzilla href="https://bugzilla.suse.com/1197505">SUSE bug 1197505</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334866" comment="libopenssl1_1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333944" comment="openssl-1_1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143267" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43267</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43267" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43267" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43267" ref_url="https://www.suse.com/security/cve/CVE-2021-43267" source="SUSE CVE"/>
    <description>
    An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-43267/">CVE-2021-43267</cve>
	<bugzilla href="https://bugzilla.suse.com/1192341">SUSE bug 1192341</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195254">SUSE bug 1195254</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143389" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43389</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43389" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43389" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43389" ref_url="https://www.suse.com/security/cve/CVE-2021-43389" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:37-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2021:772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-November/009774.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3807-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-November/020844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3929-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009873.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1651-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1668-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1686-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011291.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011310.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1501-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5J6FJF42AOGK3VQ4EFVDHQENHCDEMVT3/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3675-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YKWZ52CYLL6JHU7XBR4T2MCMZQTD4U57/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3806-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WLGTBAKURNXDJOZBJTW2QLXJEWT66GSC/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-43389/">CVE-2021-43389</cve>
	<bugzilla href="https://bugzilla.suse.com/1191958">SUSE bug 1191958</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009705000" comment="kernel-default-5.3.18-24.96.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705001" comment="kernel-default-base-5.3.18-24.96.1.9.44.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658974" comment="kernel-rt-5.3.18-62.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143519" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43519</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43519" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43519" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43519" ref_url="https://www.suse.com/security/cve/CVE-2021-43519" source="SUSE CVE"/>
    <description>
    Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-43519/">CVE-2021-43519</cve>
	<bugzilla href="https://bugzilla.suse.com/1192613">SUSE bug 1192613</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348261" comment="liblua5_3-5 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143527" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43527</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43527" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43527" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43527" ref_url="https://www.suse.com/security/cve/CVE-2021-43527" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011642.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011643.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1622-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011644.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1629-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011652.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1709-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011721.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1710-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011722.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1711-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1730-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:14858-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009861.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3934-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2021-December/020999.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3939-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009847.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011639.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3934-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SZRKUBO5D2JZTQ5VCQBSEGXEMFC4D5FB/" source="SUSE-SU"/>
    <description>
    NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS &lt; 3.73 and NSS &lt; 3.68.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-43527/">CVE-2021-43527</cve>
	<bugzilla href="https://bugzilla.suse.com/1193170">SUSE bug 1193170</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193331">SUSE bug 1193331</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1193378">SUSE bug 1193378</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194288">SUSE bug 1194288</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199301">SUSE bug 1199301</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009659044" comment="libfreebl3-3.68.1-3.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009659046" comment="libsoftokn3-3.68.1-3.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009659048" comment="mozilla-nss-3.68.1-3.61.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009659049" comment="mozilla-nss-certs-3.68.1-3.61.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143565" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43565</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43565" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43565" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43565" ref_url="https://www.suse.com/security/cve/CVE-2021-43565" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:33-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:34-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:35-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:38-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0040-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0526-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010275.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1689-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0040-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PH3Q2TLVW235XFTNU2563GON62BFYPLP/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0526-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4HOBR6WV7O5C5LLCJ6DZK4KZKG37EDV4/" source="SUSE-SU"/>
    <description>
    The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-08"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-43565/">CVE-2021-43565</cve>
	<bugzilla href="https://bugzilla.suse.com/1193930">SUSE bug 1193930</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009681381" comment="containerd-1.5.11-150000.68.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009681382" comment="docker-20.10.14_ce-150000.163.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143618" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43618</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43618" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43618" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43618" ref_url="https://www.suse.com/security/cve/CVE-2021-43618" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2021:541-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009818.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:568-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:569-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009868.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:581-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009883.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2021:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:14-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009973.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:24-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:25-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009975.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:26-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009976.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:27-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:52-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:53-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:54-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:55-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:56-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:57-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:63-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:65-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010088.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:66-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010089.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:67-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010090.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:68-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:70-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010093.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:71-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010094.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:72-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010095.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:73-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010096.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:74-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010097.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:75-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010098.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:77-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010100.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:78-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010101.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:79-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010102.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:82-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010105.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:83-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:84-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:85-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:86-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010110.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:89-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010112.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:94-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:95-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010118.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:96-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010119.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:97-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010120.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:98-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010121.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009813.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:3946-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009846.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1569-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/B57NW5VYILA46TZMVY3NWIAZTPRTGTXJ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:3946-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/R45QGO5IGOQU6FDWBSNSZHXXXTFJHN5O/" source="SUSE-SU"/>
    <description>
    GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-43618/">CVE-2021-43618</cve>
	<bugzilla href="https://bugzilla.suse.com/1192717">SUSE bug 1192717</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705003" comment="libgmp10-6.1.2-4.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143784" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43784</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43784" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43784" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43784" ref_url="https://www.suse.com/security/cve/CVE-2021-43784" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009963.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:2-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009964.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:3-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009965.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2021:4059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2021-December/009902.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:1625-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XCIUJE3F5UEWI5TYYL5CQ7SCQZU5V76Q/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2021:4171-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6DD7LA7CG2OYZJT2SOA3MHVO7GOW3ANO/" source="SUSE-SU"/>
    <description>
    runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serialization system for specifying the relevant container configuration to the `C` portion of the code (responsible for the based namespace setup of containers). In all versions of runc prior to 1.0.3, the encoder did not handle the possibility of an integer overflow in the 16-bit length field for the byte array attribute type, meaning that a large enough malicious byte array attribute could result in the length overflowing and the attribute contents being parsed as netlink messages for container configuration. This vulnerability requires the attacker to have some control over the configuration of the container and would allow the attacker to bypass the namespace restrictions of the container by simply adding their own netlink payload which disables all namespaces. The main users impacted are those who allow untrusted images with untrusted configurations to run on their machines (such as with shared cloud infrastructure). runc version 1.0.3 contains a fix for this bug. As a workaround, one may try disallowing untrusted namespace paths from your container. It should be noted that untrusted namespace paths would allow the attacker to disable namespace protections entirely even in the absence of this bug.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-43784/">CVE-2021-43784</cve>
	<bugzilla href="https://bugzilla.suse.com/1193436">SUSE bug 1193436</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009659270" comment="runc-1.0.3-27.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143816" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43816</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43816" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43816" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43816" ref_url="https://www.suse.com/security/cve/CVE-2021-43816" source="SUSE CVE"/>
    <description>
    containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved by placing the in-container location of the hostPath volume mount at either `/etc/hosts`, `/etc/hostname`, or `/etc/resolv.conf`. These locations are being relabeled indiscriminately to match the container process-label which effectively elevates permissions for savvy containers that would not normally be able to access privileged host files. This issue has been resolved in version 1.5.9. Users are advised to upgrade as soon as possible.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8/CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-43816/">CVE-2021-43816</cve>
	<bugzilla href="https://bugzilla.suse.com/1194359">SUSE bug 1194359</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009663792" comment="containerd is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143975" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43975</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43975" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43975" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43975" ref_url="https://www.suse.com/security/cve/CVE-2021-43975" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-43975/">CVE-2021-43975</cve>
	<bugzilla href="https://bugzilla.suse.com/1192845">SUSE bug 1192845</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658985" comment="kernel-rt-5.3.18-65.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202143976" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-43976</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-43976" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43976" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-43976" ref_url="https://www.suse.com/security/cve/CVE-2021-43976" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-43976/">CVE-2021-43976</cve>
	<bugzilla href="https://bugzilla.suse.com/1192847">SUSE bug 1192847</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009658985" comment="kernel-rt-5.3.18-65.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144568" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44568</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44568" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44568" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44568" ref_url="https://www.suse.com/security/cve/CVE-2021-44568" source="SUSE CVE"/>
    <description>
    Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 &amp; line 1995), which could cause a remote Denial of Service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-17"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-44568/">CVE-2021-44568</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144569" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44569</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44569" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44569" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44569" ref_url="https://www.suse.com/security/cve/CVE-2021-44569" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-16"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-44569/">CVE-2021-44569</cve>
	<bugzilla href="https://bugzilla.suse.com/1196288">SUSE bug 1196288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144570" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44570</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44570" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44570" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44570" ref_url="https://www.suse.com/security/cve/CVE-2021-44570" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-16"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-44570/">CVE-2021-44570</cve>
	<bugzilla href="https://bugzilla.suse.com/1196288">SUSE bug 1196288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144571" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44571</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44571" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44571" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44571" ref_url="https://www.suse.com/security/cve/CVE-2021-44571" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-16"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-44571/">CVE-2021-44571</cve>
	<bugzilla href="https://bugzilla.suse.com/1196288">SUSE bug 1196288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144573" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44573</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44573" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44573" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44573" ref_url="https://www.suse.com/security/cve/CVE-2021-44573" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-16"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-44573/">CVE-2021-44573</cve>
	<bugzilla href="https://bugzilla.suse.com/1196288">SUSE bug 1196288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144574" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44574</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44574" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44574" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44574" ref_url="https://www.suse.com/security/cve/CVE-2021-44574" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-16"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-44574/">CVE-2021-44574</cve>
	<bugzilla href="https://bugzilla.suse.com/1196288">SUSE bug 1196288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144575" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44575</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44575" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44575" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44575" ref_url="https://www.suse.com/security/cve/CVE-2021-44575" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-16"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-44575/">CVE-2021-44575</cve>
	<bugzilla href="https://bugzilla.suse.com/1196288">SUSE bug 1196288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144576" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44576</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44576" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44576" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44576" ref_url="https://www.suse.com/security/cve/CVE-2021-44576" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-16"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-44576/">CVE-2021-44576</cve>
	<bugzilla href="https://bugzilla.suse.com/1196288">SUSE bug 1196288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144577" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44577</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44577" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44577" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44577" ref_url="https://www.suse.com/security/cve/CVE-2021-44577" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-16"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-44577/">CVE-2021-44577</cve>
	<bugzilla href="https://bugzilla.suse.com/1196288">SUSE bug 1196288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009336106" comment="libsolv-tools is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144647" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44647</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44647" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44647" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44647" ref_url="https://www.suse.com/security/cve/CVE-2021-44647" source="SUSE CVE"/>
    <description>
    Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-05"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-44647/">CVE-2021-44647</cve>
	<bugzilla href="https://bugzilla.suse.com/1194575">SUSE bug 1194575</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348261" comment="liblua5_3-5 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144733" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44733</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44733" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44733" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44733" ref_url="https://www.suse.com/security/cve/CVE-2021-44733" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0289-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0363-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010216.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0372-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4ZJSATCJ2GMGCX6RSG2TU2YU4DDOMVQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0370-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ASMTCFCDULHGAOBQUFJH4PHVCQSTF7S6/" source="SUSE-SU"/>
    <description>
    A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-44733/">CVE-2021-44733</cve>
	<bugzilla href="https://bugzilla.suse.com/1193767">SUSE bug 1193767</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662947" comment="kernel-rt-5.3.18-68.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144879" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44879</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44879" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44879" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44879" ref_url="https://www.suse.com/security/cve/CVE-2021-44879" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010402.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010398.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0768-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-44879/">CVE-2021-44879</cve>
	<bugzilla href="https://bugzilla.suse.com/1195987">SUSE bug 1195987</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202144964" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-44964</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-44964" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44964" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-44964" ref_url="https://www.suse.com/security/cve/CVE-2021-44964" source="SUSE CVE"/>
    <description>
    Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-44964/">CVE-2021-44964</cve>
	<bugzilla href="https://bugzilla.suse.com/1197165">SUSE bug 1197165</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348261" comment="liblua5_3-5 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202145095" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-45095</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-45095" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45095" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-45095" ref_url="https://www.suse.com/security/cve/CVE-2021-45095" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0363-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010216.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010282.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010396.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4ZJSATCJ2GMGCX6RSG2TU2YU4DDOMVQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0370-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ASMTCFCDULHGAOBQUFJH4PHVCQSTF7S6/" source="SUSE-SU"/>
    <description>
    pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-45095/">CVE-2021-45095</cve>
	<bugzilla href="https://bugzilla.suse.com/1193867">SUSE bug 1193867</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009667498" comment="kernel-default-5.3.18-24.102.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667499" comment="kernel-default-base-5.3.18-24.102.1.9.48.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009668286" comment="kernel-rt-5.3.18-73.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202145100" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-45100</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-45100" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45100" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-45100" ref_url="https://www.suse.com/security/cve/CVE-2021-45100" source="SUSE CVE"/>
    <description>
    The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using the SMB 3.1.1 protocol, which is a violation of the SMB protocol specification. When Windows 10 detects this protocol violation, it disables encryption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-45100/">CVE-2021-45100</cve>
	<bugzilla href="https://bugzilla.suse.com/1193865">SUSE bug 1193865</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202145402" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-45402</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-45402" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45402" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-45402" ref_url="https://www.suse.com/security/cve/CVE-2021-45402" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bounds while handling the mov32 instruction, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-45402/">CVE-2021-45402</cve>
	<bugzilla href="https://bugzilla.suse.com/1196130">SUSE bug 1196130</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202145469" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-45469</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-45469" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45469" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-45469" ref_url="https://www.suse.com/security/cve/CVE-2021-45469" source="SUSE CVE"/>
    <description>
    In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-45469/">CVE-2021-45469</cve>
	<bugzilla href="https://bugzilla.suse.com/1194060">SUSE bug 1194060</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194462">SUSE bug 1194462</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202145480" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-45480</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-45480" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45480" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-45480" ref_url="https://www.suse.com/security/cve/CVE-2021-45480" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function in net/rds/connection.c in a certain combination of circumstances.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2021-45480/">CVE-2021-45480</cve>
	<bugzilla href="https://bugzilla.suse.com/1194090">SUSE bug 1194090</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202145485" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-45485</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-45485" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45485" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-45485" ref_url="https://www.suse.com/security/cve/CVE-2021-45485" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0289-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S44U3IKMS3KZS626YQ5ZYDHA2HLKQNER/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0198-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JVCSEXTJ2SI3QLMCUUQNNUT3HNZQJIML/" source="SUSE-SU"/>
    <description>
    In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-45485/">CVE-2021-45485</cve>
	<bugzilla href="https://bugzilla.suse.com/1194094">SUSE bug 1194094</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662947" comment="kernel-rt-5.3.18-68.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202145486" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-45486</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-45486" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45486" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-45486" ref_url="https://www.suse.com/security/cve/CVE-2021-45486" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/009994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010003.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010004.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010008.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0289-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0056-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6QFPACQDVZMSNEBMXPO5WA2LCCPKDKR2/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0131-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JZDQSQYHYML6BZRVAEZ7TDW2LFGCJEZO/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S44U3IKMS3KZS626YQ5ZYDHA2HLKQNER/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0198-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JVCSEXTJ2SI3QLMCUUQNNUT3HNZQJIML/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2021-45486/">CVE-2021-45486</cve>
	<bugzilla href="https://bugzilla.suse.com/1194087">SUSE bug 1194087</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662947" comment="kernel-rt-5.3.18-68.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202145868" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-45868</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-45868" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45868" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-45868" ref_url="https://www.suse.com/security/cve/CVE-2021-45868" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013765.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for example, lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-45868/">CVE-2021-45868</cve>
	<bugzilla href="https://bugzilla.suse.com/1197366">SUSE bug 1197366</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202145931" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-45931</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-45931" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45931" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-45931" ref_url="https://www.suse.com/security/cve/CVE-2021-45931" source="SUSE CVE"/>
    <description>
    HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t&lt;hb_bit_set_invertible_t&gt;::set and hb_set_copy).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-45931/">CVE-2021-45931</cve>
	<bugzilla href="https://bugzilla.suse.com/1194218">SUSE bug 1194218</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338893" comment="libharfbuzz0 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202145960" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-45960</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-45960" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45960" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-45960" ref_url="https://www.suse.com/security/cve/CVE-2021-45960" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:58-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:60-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-January/021467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0178-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5POFOWWCWJ3SLTEUIQRMKXQB4GOECNOP/" source="SUSE-SU"/>
    <description>
    In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2021-45960/">CVE-2021-45960</cve>
	<bugzilla href="https://bugzilla.suse.com/1194251">SUSE bug 1194251</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664062" comment="libexpat1-2.2.5-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202146059" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-46059</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-46059" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46059" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-46059" ref_url="https://www.suse.com/security/cve/CVE-2021-46059" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-46059/">CVE-2021-46059</cve>
	<bugzilla href="https://bugzilla.suse.com/1194556">SUSE bug 1194556</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202146143" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-46143</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-46143" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46143" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-46143" ref_url="https://www.suse.com/security/cve/CVE-2021-46143" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:58-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:60-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-January/021467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0178-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5POFOWWCWJ3SLTEUIQRMKXQB4GOECNOP/" source="SUSE-SU"/>
    <description>
    In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2021-46143/">CVE-2021-46143</cve>
	<bugzilla href="https://bugzilla.suse.com/1194362">SUSE bug 1194362</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195327">SUSE bug 1195327</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196387">SUSE bug 1196387</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664062" comment="libexpat1-2.2.5-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202146283" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-46283</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-46283" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46283" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-46283" ref_url="https://www.suse.com/security/cve/CVE-2021-46283" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010175.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S44U3IKMS3KZS626YQ5ZYDHA2HLKQNER/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0198-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JVCSEXTJ2SI3QLMCUUQNNUT3HNZQJIML/" source="SUSE-SU"/>
    <description>
    nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_elem_expr_alloc. A local user can set a netfilter table expression in their own namespace.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2021-46283/">CVE-2021-46283</cve>
	<bugzilla href="https://bugzilla.suse.com/1194518">SUSE bug 1194518</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202146705" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2021-46705</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2021-46705" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46705" source="CVE"/>
    <reference ref_id="SUSE CVE-2021-46705" ref_url="https://www.suse.com/security/cve/CVE-2021-46705" source="SUSE CVE"/>
    <description>
    A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to 2.06-150400.7.1. SUSE openSUSE Factory grub2 versions prior to 2.06-18.1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2021-46705/">CVE-2021-46705</cve>
	<bugzilla href="https://bugzilla.suse.com/1190474">SUSE bug 1190474</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009338902" comment="grub2 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009339065" comment="grub2-arm64-efi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338904" comment="grub2-i386-pc is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338906" comment="grub2-snapper-plugin is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338908" comment="grub2-x86_64-efi is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009338909" comment="grub2-x86_64-xen is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220001" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0001</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0001" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0001" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0001" ref_url="https://www.suse.com/security/cve/CVE-2022-0001" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0755-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010402.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010398.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010391.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0939-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010506.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0940-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010818.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010396.html" source="SUSE-SU"/>
		<reference ref_id="TID000020607" ref_url="https://www.suse.com/support/kb/doc/?id=000020607" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0755-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PDLUIZF7VQIB7OV6GCQHOPOBN2UU2POW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0760-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GIEQJF6RAZADJBWJQFLIHOBULB4E2C7K/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0768-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0940-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NXODJTCX5G5LLTBOEFVBOCIWYKEGYAMP/" source="SUSE-SU"/>
    <description>
    Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-0001/">CVE-2022-0001</cve>
	<bugzilla href="https://bugzilla.suse.com/1191580">SUSE bug 1191580</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196901">SUSE bug 1196901</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671417" comment="kernel-rt-5.3.18-76.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680342" comment="xen-libs-4.13.4_08-150200.3.50.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220002" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0002</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0002" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0002" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0002" ref_url="https://www.suse.com/security/cve/CVE-2022-0002" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0755-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010402.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010398.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010391.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0931-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010501.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0939-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010506.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0940-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010504.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010818.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010396.html" source="SUSE-SU"/>
		<reference ref_id="TID000020607" ref_url="https://www.suse.com/support/kb/doc/?id=000020607" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0755-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PDLUIZF7VQIB7OV6GCQHOPOBN2UU2POW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0760-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GIEQJF6RAZADJBWJQFLIHOBULB4E2C7K/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0768-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0940-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NXODJTCX5G5LLTBOEFVBOCIWYKEGYAMP/" source="SUSE-SU"/>
    <description>
    Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-0002/">CVE-2022-0002</cve>
	<bugzilla href="https://bugzilla.suse.com/1191580">SUSE bug 1191580</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196901">SUSE bug 1196901</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671417" comment="kernel-rt-5.3.18-76.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680342" comment="xen-libs-4.13.4_08-150200.3.50.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220128" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0128</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0128" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0128" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0128" ref_url="https://www.suse.com/security/cve/CVE-2022-0128" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    vim is vulnerable to Out-of-bounds Read
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-0128/">CVE-2022-0128</cve>
	<bugzilla href="https://bugzilla.suse.com/1194388">SUSE bug 1194388</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220135" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0135</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0135" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0135" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0135" ref_url="https://www.suse.com/security/cve/CVE-2022-0135" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0478-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010244.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010243.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2395-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011545.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0479-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EQXVEUIFIMFD6G5N2JBQ2A6XUYVZBCSY/" source="SUSE-SU"/>
    <description>
    An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0135/">CVE-2022-0135</cve>
	<bugzilla href="https://bugzilla.suse.com/1195389">SUSE bug 1195389</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196396">SUSE bug 1196396</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667314" comment="libvirglrenderer0-0.6.0-4.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220156" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0156</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0156" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0156" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0156" ref_url="https://www.suse.com/security/cve/CVE-2022-0156" source="SUSE CVE"/>
    <description>
    vim is vulnerable to Use After Free
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2022-0156/">CVE-2022-0156</cve>
	<bugzilla href="https://bugzilla.suse.com/1194559">SUSE bug 1194559</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220158" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0158</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0158" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0158" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0158" ref_url="https://www.suse.com/security/cve/CVE-2022-0158" source="SUSE CVE"/>
    <description>
    vim is vulnerable to Heap-based Buffer Overflow
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0158/">CVE-2022-0158</cve>
	<bugzilla href="https://bugzilla.suse.com/1194553">SUSE bug 1194553</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220168" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0168</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0168" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0168" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0168" ref_url="https://www.suse.com/security/cve/CVE-2022-0168" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2078-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011302.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011353.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:2177-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S2QMD6CJ6PZDFYQ3RKSOGAZNRK7WC5W7/" source="SUSE-SU"/>
    <description>
    A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet File System (CIFS) due to an incorrect return from the memdup_user function. This flaw allows a local, privileged (CAP_SYS_ADMIN) attacker to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0168/">CVE-2022-0168</cve>
	<bugzilla href="https://bugzilla.suse.com/1197472">SUSE bug 1197472</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220171" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0171</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0171" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0171" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0171" ref_url="https://www.suse.com/security/cve/CVE-2022-0171" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0171/">CVE-2022-0171</cve>
	<bugzilla href="https://bugzilla.suse.com/1199509">SUSE bug 1199509</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220175" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0175</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0175" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0175" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0175" ref_url="https://www.suse.com/security/cve/CVE-2022-0175" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0110-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-January/021373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010020.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0111-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/LNFLD35UGUIRPTGF3HA3JP2MXLLHWPIX/" source="SUSE-SU"/>
    <description>
    A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-0175/">CVE-2022-0175</cve>
	<bugzilla href="https://bugzilla.suse.com/1194601">SUSE bug 1194601</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705025" comment="libvirglrenderer0-0.6.0-4.6.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220185" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0185</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0185" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0185" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0185" ref_url="https://www.suse.com/security/cve/CVE-2022-0185" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0254-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010156.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0289-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0291-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0292-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010176.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0295-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021589.html" source="SUSE-SU"/>
		<reference ref_id="TID000020565" ref_url="https://www.suse.com/support/kb/doc/?id=000020565" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S44U3IKMS3KZS626YQ5ZYDHA2HLKQNER/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0198-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JVCSEXTJ2SI3QLMCUUQNNUT3HNZQJIML/" source="SUSE-SU"/>
    <description>
    A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0185/">CVE-2022-0185</cve>
	<bugzilla href="https://bugzilla.suse.com/1194517">SUSE bug 1194517</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1194737">SUSE bug 1194737</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662947" comment="kernel-rt-5.3.18-68.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220264" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0264</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0264" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0264" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0264" ref_url="https://www.suse.com/security/cve/CVE-2022-0264" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in the Linux kernel's eBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel. This flaws affects kernel versions &lt; v5.16-rc6
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-0264/">CVE-2022-0264</cve>
	<bugzilla href="https://bugzilla.suse.com/1194826">SUSE bug 1194826</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220286" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0286</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0286" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0286" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0286" ref_url="https://www.suse.com/security/cve/CVE-2022-0286" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0363-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010216.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010282.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4ZJSATCJ2GMGCX6RSG2TU2YU4DDOMVQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0370-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ASMTCFCDULHGAOBQUFJH4PHVCQSTF7S6/" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0286/">CVE-2022-0286</cve>
	<bugzilla href="https://bugzilla.suse.com/1195371">SUSE bug 1195371</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220318" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0318</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0318" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0318" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0318" ref_url="https://www.suse.com/security/cve/CVE-2022-0318" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    Heap-based Buffer Overflow in vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0318/">CVE-2022-0318</cve>
	<bugzilla href="https://bugzilla.suse.com/1195004">SUSE bug 1195004</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220319" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0319</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0319" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0319" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0319" ref_url="https://www.suse.com/security/cve/CVE-2022-0319" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    Out-of-bounds Read in vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-0319/">CVE-2022-0319</cve>
	<bugzilla href="https://bugzilla.suse.com/1195066">SUSE bug 1195066</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220322" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0322</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0322" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0322" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0322" ref_url="https://www.suse.com/security/cve/CVE-2022-0322" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0169-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010060.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010080.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0289-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0372-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0169-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S44U3IKMS3KZS626YQ5ZYDHA2HLKQNER/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0198-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JVCSEXTJ2SI3QLMCUUQNNUT3HNZQJIML/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
    <description>
    A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0322/">CVE-2022-0322</cve>
	<bugzilla href="https://bugzilla.suse.com/1194985">SUSE bug 1194985</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009664563" comment="kernel-default-5.3.18-24.99.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664564" comment="kernel-default-base-5.3.18-24.99.1.9.46.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009662947" comment="kernel-rt-5.3.18-68.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220330" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0330</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0330" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0330" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0330" ref_url="https://www.suse.com/security/cve/CVE-2022-0330" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0363-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010216.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0372-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0477-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010282.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1569-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010975.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010984.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010976.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1640-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010991.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4ZJSATCJ2GMGCX6RSG2TU2YU4DDOMVQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0366-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CFUCZRWH2IP7FOHVYO3TO3G5PFWQXLP6/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0370-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ASMTCFCDULHGAOBQUFJH4PHVCQSTF7S6/" source="SUSE-SU"/>
    <description>
    A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0330/">CVE-2022-0330</cve>
	<bugzilla href="https://bugzilla.suse.com/1194880">SUSE bug 1194880</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195950">SUSE bug 1195950</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009667498" comment="kernel-default-5.3.18-24.102.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667499" comment="kernel-default-base-5.3.18-24.102.1.9.48.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009668286" comment="kernel-rt-5.3.18-73.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220351" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0351</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0351" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0351" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0351" ref_url="https://www.suse.com/security/cve/CVE-2022-0351" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-0351/">CVE-2022-0351</cve>
	<bugzilla href="https://bugzilla.suse.com/1195126">SUSE bug 1195126</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220358" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0358</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0358" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0358" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0358" ref_url="https://www.suse.com/security/cve/CVE-2022-0358" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0930-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0930-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010778.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0930-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VFLDWSRMX7BN3NXC6GXAFPJLCC5D5KIJ/" source="SUSE-SU"/>
    <description>
    A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0358/">CVE-2022-0358</cve>
	<bugzilla href="https://bugzilla.suse.com/1195161">SUSE bug 1195161</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220361" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0361</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0361" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0361" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0361" ref_url="https://www.suse.com/security/cve/CVE-2022-0361" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2022-0361/">CVE-2022-0361</cve>
	<bugzilla href="https://bugzilla.suse.com/1195202">SUSE bug 1195202</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220368" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0368</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0368" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0368" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0368" ref_url="https://www.suse.com/security/cve/CVE-2022-0368" source="SUSE CVE"/>
    <description>
    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0368/">CVE-2022-0368</cve>
	<bugzilla href="https://bugzilla.suse.com/1195205">SUSE bug 1195205</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220382" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0382</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0382" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0382" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0382" ref_url="https://www.suse.com/security/cve/CVE-2022-0382" source="SUSE CVE"/>
    <description>
    An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. This issue is limited to no more than 7 bytes, and the user cannot control what is read. This flaw affects the Linux kernel versions prior to 5.17-rc1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-0382/">CVE-2022-0382</cve>
	<bugzilla href="https://bugzilla.suse.com/1195199">SUSE bug 1195199</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220393" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0393</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0393" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0393" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0393" ref_url="https://www.suse.com/security/cve/CVE-2022-0393" source="SUSE CVE"/>
    <description>
    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0393/">CVE-2022-0393</cve>
	<bugzilla href="https://bugzilla.suse.com/1195336">SUSE bug 1195336</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220407" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0407</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0407" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0407" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0407" ref_url="https://www.suse.com/security/cve/CVE-2022-0407" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-31"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0407/">CVE-2022-0407</cve>
	<bugzilla href="https://bugzilla.suse.com/1195354">SUSE bug 1195354</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208308">SUSE bug 1208308</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208649">SUSE bug 1208649</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208651">SUSE bug 1208651</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220408" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0408</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0408" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0408" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0408" ref_url="https://www.suse.com/security/cve/CVE-2022-0408" source="SUSE CVE"/>
    <description>
    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2022-0408/">CVE-2022-0408</cve>
	<bugzilla href="https://bugzilla.suse.com/1195459">SUSE bug 1195459</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220413" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0413</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0413" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0413" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0413" ref_url="https://www.suse.com/security/cve/CVE-2022-0413" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010366.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0736-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0736-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FDNZ3N5S7UGKPUUKPGOQQGPJJK3YTW37/" source="SUSE-SU"/>
    <description>
    Use After Free in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-31"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0413/">CVE-2022-0413</cve>
	<bugzilla href="https://bugzilla.suse.com/1195356">SUSE bug 1195356</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208308">SUSE bug 1208308</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208651">SUSE bug 1208651</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669883" comment="vim-data-common-8.0.1568-5.17.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705042" comment="vim-small-8.0.1568-5.17.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220417" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0417</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0417" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0417" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0417" ref_url="https://www.suse.com/security/cve/CVE-2022-0417" source="SUSE CVE"/>
    <description>
    Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2022-0417/">CVE-2022-0417</cve>
	<bugzilla href="https://bugzilla.suse.com/1195499">SUSE bug 1195499</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220433" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0433</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0433" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0433" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0433" ref_url="https://www.suse.com/security/cve/CVE-2022-0433" source="SUSE CVE"/>
    <description>
    A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kernel versions prior to 5.17-rc1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0433/">CVE-2022-0433</cve>
	<bugzilla href="https://bugzilla.suse.com/1195373">SUSE bug 1195373</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220435" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0435</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0435" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0435" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0435" ref_url="https://www.suse.com/security/cve/CVE-2022-0435" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0363-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0367-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010216.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010217.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0372-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0418-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010228.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010227.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="TID000020580" ref_url="https://www.suse.com/support/kb/doc/?id=000020580" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4ZJSATCJ2GMGCX6RSG2TU2YU4DDOMVQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0370-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ASMTCFCDULHGAOBQUFJH4PHVCQSTF7S6/" source="SUSE-SU"/>
    <description>
    A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0435/">CVE-2022-0435</cve>
	<bugzilla href="https://bugzilla.suse.com/1195254">SUSE bug 1195254</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195308">SUSE bug 1195308</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009667498" comment="kernel-default-5.3.18-24.102.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667499" comment="kernel-default-base-5.3.18-24.102.1.9.48.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220443" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0443</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0443" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0443" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0443" ref_url="https://www.suse.com/security/cve/CVE-2022-0443" source="SUSE CVE"/>
    <description>
    Use After Free in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2022-0443/">CVE-2022-0443</cve>
	<bugzilla href="https://bugzilla.suse.com/1195509">SUSE bug 1195509</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220487" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0487</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0487" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0487" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0487" ref_url="https://www.suse.com/security/cve/CVE-2022-0487" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010402.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1012-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010561.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0768-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0487/">CVE-2022-0487</cve>
	<bugzilla href="https://bugzilla.suse.com/1194516">SUSE bug 1194516</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195949">SUSE bug 1195949</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198615">SUSE bug 1198615</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220492" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0492</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0492" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0492" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0492" ref_url="https://www.suse.com/security/cve/CVE-2022-0492" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0755-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010402.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010398.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0991-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010550.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1012-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010561.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1036-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010569.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010396.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0755-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PDLUIZF7VQIB7OV6GCQHOPOBN2UU2POW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0760-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GIEQJF6RAZADJBWJQFLIHOBULB4E2C7K/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0768-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/" source="SUSE-SU"/>
    <description>
    A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0492/">CVE-2022-0492</cve>
	<bugzilla href="https://bugzilla.suse.com/1195543">SUSE bug 1195543</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195908">SUSE bug 1195908</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196612">SUSE bug 1196612</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196776">SUSE bug 1196776</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198615">SUSE bug 1198615</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199255">SUSE bug 1199255</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199615">SUSE bug 1199615</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200084">SUSE bug 1200084</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220494" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0494</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0494" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0494" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0494" ref_url="https://www.suse.com/security/cve/CVE-2022-0494" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows a local attacker with a special user privilege (CAP_SYS_ADMIN or CAP_SYS_RAWIO) to create issues with confidentiality.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-21"/>
	<updated date="2023-02-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-0494/">CVE-2022-0494</cve>
	<bugzilla href="https://bugzilla.suse.com/1197386">SUSE bug 1197386</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1207783">SUSE bug 1207783</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220500" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0500</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0500" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0500" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0500" ref_url="https://www.suse.com/security/cve/CVE-2022-0500" source="SUSE CVE"/>
    <description>
    A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0500/">CVE-2022-0500</cve>
	<bugzilla href="https://bugzilla.suse.com/1196261">SUSE bug 1196261</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196811">SUSE bug 1196811</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220516" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0516</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0516" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0516" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0516" ref_url="https://www.suse.com/security/cve/CVE-2022-0516" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010319.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010320.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0660-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0755-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0755-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PDLUIZF7VQIB7OV6GCQHOPOBN2UU2POW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0760-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GIEQJF6RAZADJBWJQFLIHOBULB4E2C7K/" source="SUSE-SU"/>
    <description>
    A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0516/">CVE-2022-0516</cve>
	<bugzilla href="https://bugzilla.suse.com/1195516">SUSE bug 1195516</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195947">SUSE bug 1195947</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220554" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0554</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0554" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0554" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0554" ref_url="https://www.suse.com/security/cve/CVE-2022-0554" source="SUSE CVE"/>
    <description>
    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0554/">CVE-2022-0554</cve>
	<bugzilla href="https://bugzilla.suse.com/1195846">SUSE bug 1195846</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220563" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0563</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0563" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0563" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0563" ref_url="https://www.suse.com/security/cve/CVE-2022-0563" source="SUSE CVE"/>
    <description>
    A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-0563/">CVE-2022-0563</cve>
	<bugzilla href="https://bugzilla.suse.com/1196241">SUSE bug 1196241</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009337634" comment="libblkid1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664921" comment="libfdisk1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664923" comment="libmount1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664926" comment="libsmartcols1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009337635" comment="libuuid1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334326" comment="util-linux is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220572" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0572</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0572" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0572" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0572" ref_url="https://www.suse.com/security/cve/CVE-2022-0572" source="SUSE CVE"/>
    <description>
    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0572/">CVE-2022-0572</cve>
	<bugzilla href="https://bugzilla.suse.com/1196023">SUSE bug 1196023</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220615" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0615</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0615" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0615" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0615" ref_url="https://www.suse.com/security/cve/CVE-2022-0615" source="SUSE CVE"/>
    <description>
    Use-after-free in eset_rtp kernel module used in ESET products for Linux allows potential attacker to trigger denial-of-service condition on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0615/">CVE-2022-0615</cve>
	<bugzilla href="https://bugzilla.suse.com/1196541">SUSE bug 1196541</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220617" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0617</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0617" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0617" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0617" ref_url="https://www.suse.com/security/cve/CVE-2022-0617" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010402.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010398.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14905-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010396.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0768-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0617/">CVE-2022-0617</cve>
	<bugzilla href="https://bugzilla.suse.com/1196079">SUSE bug 1196079</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220629" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0629</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0629" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0629" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0629" ref_url="https://www.suse.com/security/cve/CVE-2022-0629" source="SUSE CVE"/>
    <description>
    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0629/">CVE-2022-0629</cve>
	<bugzilla href="https://bugzilla.suse.com/1196226">SUSE bug 1196226</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220644" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0644</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0644" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0644" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0644" ref_url="https://www.suse.com/security/cve/CVE-2022-0644" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010402.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010398.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0768-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-30"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0644/">CVE-2022-0644</cve>
	<bugzilla href="https://bugzilla.suse.com/1196155">SUSE bug 1196155</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220646" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0646</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0646" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0646" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0646" ref_url="https://www.suse.com/security/cve/CVE-2022-0646" source="SUSE CVE"/>
    <description>
    A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user could use this flaw to crash the system or escalate their privileges on the system. It is actual from Linux Kernel 5.17-rc1 (when mctp-serial.c introduced) till 5.17-rc5.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0646/">CVE-2022-0646</cve>
	<bugzilla href="https://bugzilla.suse.com/1196090">SUSE bug 1196090</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220685" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0685</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0685" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0685" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0685" ref_url="https://www.suse.com/security/cve/CVE-2022-0685" source="SUSE CVE"/>
    <description>
    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0685/">CVE-2022-0685</cve>
	<bugzilla href="https://bugzilla.suse.com/1196227">SUSE bug 1196227</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220696" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0696</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0696" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0696" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0696" ref_url="https://www.suse.com/security/cve/CVE-2022-0696" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-0696/">CVE-2022-0696</cve>
	<bugzilla href="https://bugzilla.suse.com/1196361">SUSE bug 1196361</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205395">SUSE bug 1205395</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220714" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0714</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0714" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0714" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0714" ref_url="https://www.suse.com/security/cve/CVE-2022-0714" source="SUSE CVE"/>
    <description>
    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2022-0714/">CVE-2022-0714</cve>
	<bugzilla href="https://bugzilla.suse.com/1196358">SUSE bug 1196358</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220729" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0729</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0729" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0729" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0729" ref_url="https://www.suse.com/security/cve/CVE-2022-0729" source="SUSE CVE"/>
    <description>
    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-0729/">CVE-2022-0729</cve>
	<bugzilla href="https://bugzilla.suse.com/1196437">SUSE bug 1196437</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220742" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0742</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0742" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0742" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0742" ref_url="https://www.suse.com/security/cve/CVE-2022-0742" source="SUSE CVE"/>
    <description>
    Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0742/">CVE-2022-0742</cve>
	<bugzilla href="https://bugzilla.suse.com/1197128">SUSE bug 1197128</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197129">SUSE bug 1197129</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220778" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0778</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0778" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0778" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0778" ref_url="https://www.suse.com/security/cve/CVE-2022-0778" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010465.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:287-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010469.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:813-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010871.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010872.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0851-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0854-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0856-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0857-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0860-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0861-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010706.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0935-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010502.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1459-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1461-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1462-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010864.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14915-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010932.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0856-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/V7FRPEEZ7WUHWJ2PK7C5GZJJTXRGWJB2/" source="SUSE-SU"/>
    <description>
    The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-0778/">CVE-2022-0778</cve>
	<bugzilla href="https://bugzilla.suse.com/1196877">SUSE bug 1196877</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197328">SUSE bug 1197328</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197340">SUSE bug 1197340</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199100">SUSE bug 1199100</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199254">SUSE bug 1199254</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199303">SUSE bug 1199303</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199339">SUSE bug 1199339</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200090">SUSE bug 1200090</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009673279" comment="libopenssl1_1-1.1.1d-11.43.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009673282" comment="openssl-1_1-1.1.1d-11.43.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220847" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0847</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0847" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0847" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0847" ref_url="https://www.suse.com/security/cve/CVE-2022-0847" source="SUSE CVE"/>
		<reference ref_id="SUSE-BLOG-DIRTY-PIPE" ref_url="https://www.suse.com/c/suse-statement-on-dirty-pipe-attack/" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0755-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010402.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010397.html" source="SUSE-SU"/>
		<reference ref_id="TID000020603" ref_url="https://www.suse.com/support/kb/doc/?id=000020603" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0755-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PDLUIZF7VQIB7OV6GCQHOPOBN2UU2POW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0760-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GIEQJF6RAZADJBWJQFLIHOBULB4E2C7K/" source="SUSE-SU"/>
    <description>
    A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0847/">CVE-2022-0847</cve>
	<bugzilla href="https://bugzilla.suse.com/1196584">SUSE bug 1196584</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196601">SUSE bug 1196601</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671417" comment="kernel-rt-5.3.18-76.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220850" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0850</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0850" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0850" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0850" ref_url="https://www.suse.com/security/cve/CVE-2022-0850" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-30"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-0850/">CVE-2022-0850</cve>
	<bugzilla href="https://bugzilla.suse.com/1196761">SUSE bug 1196761</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220854" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0854</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0854" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0854" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0854" ref_url="https://www.suse.com/security/cve/CVE-2022-0854" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
    <description>
    A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-0854/">CVE-2022-0854</cve>
	<bugzilla href="https://bugzilla.suse.com/1196823">SUSE bug 1196823</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220934" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0934</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0934" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0934" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0934" ref_url="https://www.suse.com/security/cve/CVE-2022-0934" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:1288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1289-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1307-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010803.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14940-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010783.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14941-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010787.html" source="SUSE-SU"/>
    <description>
    A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-30"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2022-0934/">CVE-2022-0934</cve>
	<bugzilla href="https://bugzilla.suse.com/1197872">SUSE bug 1197872</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679488" comment="dnsmasq-2.86-150100.7.20.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220943" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0943</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0943" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0943" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0943" ref_url="https://www.suse.com/security/cve/CVE-2022-0943" source="SUSE CVE"/>
    <description>
    Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0943/">CVE-2022-0943</cve>
	<bugzilla href="https://bugzilla.suse.com/1197225">SUSE bug 1197225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220995" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0995</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0995" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0995" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0995" ref_url="https://www.suse.com/security/cve/CVE-2022-0995" source="SUSE CVE"/>
    <description>
    An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0995/">CVE-2022-0995</cve>
	<bugzilla href="https://bugzilla.suse.com/1197246">SUSE bug 1197246</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197337">SUSE bug 1197337</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20220998" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-0998</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-0998" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0998" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-0998" ref_url="https://www.suse.com/security/cve/CVE-2022-0998" source="SUSE CVE"/>
    <description>
    An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-06"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-0998/">CVE-2022-0998</cve>
	<bugzilla href="https://bugzilla.suse.com/1197247">SUSE bug 1197247</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197338">SUSE bug 1197338</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221016" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1016</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1016" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1016" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1016" ref_url="https://www.suse.com/security/cve/CVE-2022-1016" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010805.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010815.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010816.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1329-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010824.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1335-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1369-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010856.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1453-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010859.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1486-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010913.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-30"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-1016/">CVE-2022-1016</cve>
	<bugzilla href="https://bugzilla.suse.com/1197335">SUSE bug 1197335</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221043" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1043</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1043" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1043" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1043" ref_url="https://www.suse.com/security/cve/CVE-2022-1043" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to corrupt system memory, crash the system or escalate privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-30"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1043/">CVE-2022-1043</cve>
	<bugzilla href="https://bugzilla.suse.com/1197393">SUSE bug 1197393</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197596">SUSE bug 1197596</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221048" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1048</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1048" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1048" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1048" ref_url="https://www.suse.com/security/cve/CVE-2022-1048" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1939-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1942-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011236.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1945-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011237.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1947-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011238.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1948-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011239.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011243.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1974-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011241.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2000-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011245.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2006-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011246.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013765.html" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1048/">CVE-2022-1048</cve>
	<bugzilla href="https://bugzilla.suse.com/1197331">SUSE bug 1197331</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197597">SUSE bug 1197597</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200041">SUSE bug 1200041</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204132">SUSE bug 1204132</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1212325">SUSE bug 1212325</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221055" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1055</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1055" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1055" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1055" ref_url="https://www.suse.com/security/cve/CVE-2022-1055" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010817.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1369-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010820.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1453-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010859.html" source="SUSE-SU"/>
    <description>
    A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1055/">CVE-2022-1055</cve>
	<bugzilla href="https://bugzilla.suse.com/1197702">SUSE bug 1197702</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197705">SUSE bug 1197705</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221097" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1097</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1097" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1097" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1097" ref_url="https://www.suse.com/security/cve/CVE-2022-1097" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:581-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010725.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010659.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1127-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010667.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010699.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14936-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010660.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1127-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/76BLKP3BHKRBWFX4VJKKQJQXQTYEOOSX/" source="SUSE-SU"/>
    <description>
    &lt;code&gt;NSSToken&lt;/code&gt; objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird &lt; 91.8, Firefox &lt; 99, and Firefox ESR &lt; 91.8.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1097/">CVE-2022-1097</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009678060" comment="libfreebl3-3.68.3-150000.3.67.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009678062" comment="libsoftokn3-3.68.3-150000.3.67.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009678064" comment="mozilla-nss-3.68.3-150000.3.67.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009678065" comment="mozilla-nss-certs-3.68.3-150000.3.67.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221116" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1116</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1116" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1116" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1116" ref_url="https://www.suse.com/security/cve/CVE-2022-1116" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011377.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011614.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011890.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011914.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011976.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2875-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2892-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012083.html" source="SUSE-SU"/>
    <description>
    Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; version 5.4.24 and later versions.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-03-30"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1116/">CVE-2022-1116</cve>
	<bugzilla href="https://bugzilla.suse.com/1199647">SUSE bug 1199647</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199648">SUSE bug 1199648</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209225">SUSE bug 1209225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221154" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1154</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1154" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1154" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1154" ref_url="https://www.suse.com/security/cve/CVE-2022-1154" source="SUSE CVE"/>
    <description>
    Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1154/">CVE-2022-1154</cve>
	<bugzilla href="https://bugzilla.suse.com/1197813">SUSE bug 1197813</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221158" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1158</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1158" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1158" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1158" ref_url="https://www.suse.com/security/cve/CVE-2022-1158" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1569-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010966.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1571-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1575-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010976.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010983.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1629-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1634-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1669-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011302.html" source="SUSE-SU"/>
    <description>
    A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1158/">CVE-2022-1158</cve>
	<bugzilla href="https://bugzilla.suse.com/1197660">SUSE bug 1197660</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198133">SUSE bug 1198133</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221160" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1160</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1160" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1160" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1160" ref_url="https://www.suse.com/security/cve/CVE-2022-1160" source="SUSE CVE"/>
    <description>
    heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1160/">CVE-2022-1160</cve>
	<bugzilla href="https://bugzilla.suse.com/1197814">SUSE bug 1197814</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221195" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1195</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1195" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1195" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1195" ref_url="https://www.suse.com/security/cve/CVE-2022-1195" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker with a user privilege to cause a denial of service (DOS) when the mkiss or sixpack device is detached and reclaim resources early.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1195/">CVE-2022-1195</cve>
	<bugzilla href="https://bugzilla.suse.com/1198029">SUSE bug 1198029</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221198" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1198</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1198" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1198" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1198" ref_url="https://www.suse.com/security/cve/CVE-2022-1198" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by simulating ax25 device using 6pack driver from user space.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-30"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1198/">CVE-2022-1198</cve>
	<bugzilla href="https://bugzilla.suse.com/1198030">SUSE bug 1198030</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221199" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1199</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1199" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1199" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1199" ref_url="https://www.suse.com/security/cve/CVE-2022-1199" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-30"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1199/">CVE-2022-1199</cve>
	<bugzilla href="https://bugzilla.suse.com/1198028">SUSE bug 1198028</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221204" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1204</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1204" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1204" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1204" ref_url="https://www.suse.com/security/cve/CVE-2022-1204" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocol. This flaw allows a local user to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-30"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1204/">CVE-2022-1204</cve>
	<bugzilla href="https://bugzilla.suse.com/1198025">SUSE bug 1198025</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221205" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1205</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1205" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1205" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1205" ref_url="https://www.suse.com/security/cve/CVE-2022-1205" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocol. This flaw allows a local user to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1205/">CVE-2022-1205</cve>
	<bugzilla href="https://bugzilla.suse.com/1198027">SUSE bug 1198027</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221247" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1247</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1247" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1247" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1247" ref_url="https://www.suse.com/security/cve/CVE-2022-1247" source="SUSE CVE"/>
    <description>
    An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh-&gt;use to represent how many objects are using the rose_neigh. When a user wants to delete a rose_route via rose_ioctl(), the rose driver calls rose_del_node() and removes neighbours only if their “count” and “use” are zero.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1247/">CVE-2022-1247</cve>
	<bugzilla href="https://bugzilla.suse.com/1199434">SUSE bug 1199434</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199696">SUSE bug 1199696</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204132">SUSE bug 1204132</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221263" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1263</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1263" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1263" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1263" ref_url="https://www.suse.com/security/cve/CVE-2022-1263" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1263/">CVE-2022-1263</cve>
	<bugzilla href="https://bugzilla.suse.com/1198189">SUSE bug 1198189</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221271" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1271</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1271" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1271" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1271" ref_url="https://www.suse.com/security/cve/CVE-2022-1271" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1007-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1018-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011036.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1052-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-May/023165.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011091.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1228-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1229-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011214.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:596-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010712.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010713.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010714.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010715.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010716.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010719.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010720.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010722.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:610-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010724.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010725.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:612-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010726.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010727.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010729.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:616-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010730.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:625-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010780.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:714-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010827.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010828.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:720-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010829.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:721-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010830.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:723-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010831.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:725-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010832.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010833.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:729-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010880.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010881.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010882.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:833-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-April/022888.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:835-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010886.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010887.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:837-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010888.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010889.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:840-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010890.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:841-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010891.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:843-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010893.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010894.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010912.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:871-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010942.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:872-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010943.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:873-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010944.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:874-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010945.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010946.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:877-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:880-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:906-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:910-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010958.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:917-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:919-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010961.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:961-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010985.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:972-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010988.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:973-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:675-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014047.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:677-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014051.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:680-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:681-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014053.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:683-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014056.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014057.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:686-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014058.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:689-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014061.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010686.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1160-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010685.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1250-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1272-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1275-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010766.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14938-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010979.html" source="SUSE-SU"/>
    <description>
    An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1271/">CVE-2022-1271</cve>
	<bugzilla href="https://bugzilla.suse.com/1198062">SUSE bug 1198062</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198812">SUSE bug 1198812</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199107">SUSE bug 1199107</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199108">SUSE bug 1199108</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009682445" comment="gzip-1.10-150200.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679181" comment="liblzma5-5.2.3-150000.4.7.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679182" comment="xz-5.2.3-150000.4.7.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221280" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1280</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1280" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1280" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1280" ref_url="https://www.suse.com/security/cve/CVE-2022-1280" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1651-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1668-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1669-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1686-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011117.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011134.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1849-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011165.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011401.html" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or a kernel information leak.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1280/">CVE-2022-1280</cve>
	<bugzilla href="https://bugzilla.suse.com/1197914">SUSE bug 1197914</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198590">SUSE bug 1198590</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221292" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1292</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1292" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1292" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1292" ref_url="https://www.suse.com/security/cve/CVE-2022-1292" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1325-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1326-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1329-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011307.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1330-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1400-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1401-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1404-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1405-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011396.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011444.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1417-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1418-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011446.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1419-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011447.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1420-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011448.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1421-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011449.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1423-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1425-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1438-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011464.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1471-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011507.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1616-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011814.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:953-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2075-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011282.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2098-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2106-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011304.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011355.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2251-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011387.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2251-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2306-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-July/023781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2308-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011417.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011468.html" source="SUSE-SU"/>
    <description>
    The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1292/">CVE-2022-1292</cve>
	<bugzilla href="https://bugzilla.suse.com/1199166">SUSE bug 1199166</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200550">SUSE bug 1200550</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200650">SUSE bug 1200650</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200758">SUSE bug 1200758</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1202688">SUSE bug 1202688</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221304" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1304</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1304" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1304" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1304" ref_url="https://www.suse.com/security/cve/CVE-2022-1304" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1021-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1022-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1024-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011042.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011043.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1040-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011044.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1044-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011046.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1046-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011048.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011049.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1051-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-May/023164.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1054-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1055-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011064.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1060-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-May/023191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011066.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1064-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1066-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1068-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1070-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011070.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011071.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1074-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011072.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011086.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1150-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1198-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1204-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1205-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1228-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1229-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011214.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1232-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1356-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1357-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1358-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1361-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011328.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1616-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011624.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1736-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012142.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2087-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2088-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2089-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2090-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012149.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2091-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2092-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012152.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2094-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012153.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2095-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012154.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:983-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1652-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010997.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1688-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011031.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1695-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011050.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1718-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011061.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2022-1304/">CVE-2022-1304</cve>
	<bugzilla href="https://bugzilla.suse.com/1198446">SUSE bug 1198446</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201130">SUSE bug 1201130</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009682231" comment="e2fsprogs-1.43.8-150000.4.33.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009682235" comment="libcom_err2-1.43.8-150000.4.33.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009682238" comment="libext2fs2-1.43.8-150000.4.33.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221343" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1343</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1343" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1343" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1343" ref_url="https://www.suse.com/security/cve/CVE-2022-1343" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:2306-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-July/023781.html" source="SUSE-SU"/>
    <description>
    The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL "ocsp" application. When verifying an ocsp response with the "-no_cert_checks" option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2022-1343/">CVE-2022-1343</cve>
	<bugzilla href="https://bugzilla.suse.com/1199167">SUSE bug 1199167</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334866" comment="libopenssl1_1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333944" comment="openssl-1_1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221348" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1348</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1348" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1348" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1348" ref_url="https://www.suse.com/security/cve/CVE-2022-1348" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:2149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:953-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2396-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011547.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-1348/">CVE-2022-1348</cve>
	<bugzilla href="https://bugzilla.suse.com/1199652">SUSE bug 1199652</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009684924" comment="logrotate is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221381" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1381</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1381" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1381" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1381" ref_url="https://www.suse.com/security/cve/CVE-2022-1381" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2022-1381/">CVE-2022-1381</cve>
	<bugzilla href="https://bugzilla.suse.com/1198596">SUSE bug 1198596</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221420" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1420</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1420" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1420" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1420" ref_url="https://www.suse.com/security/cve/CVE-2022-1420" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-1420/">CVE-2022-1420</cve>
	<bugzilla href="https://bugzilla.suse.com/1198748">SUSE bug 1198748</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221434" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1434</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1434" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1434" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1434" ref_url="https://www.suse.com/security/cve/CVE-2022-1434" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:2306-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-July/023781.html" source="SUSE-SU"/>
    <description>
    The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a man-in-the-middle attack to modify data being sent from one endpoint to an OpenSSL 3.0 recipient such that the modified data would still pass the MAC integrity check. Note that data sent from an OpenSSL 3.0 endpoint to a non-OpenSSL 3.0 endpoint will always be rejected by the recipient and the connection will fail at that point. Many application protocols require data to be sent from the client to the server first. Therefore, in such a case, only an OpenSSL 3.0 server would be impacted when talking to a non-OpenSSL 3.0 client. If both endpoints are OpenSSL 3.0 then the attacker could modify data being sent in both directions. In this case both clients and servers could be affected, regardless of the application protocol. Note that in the absence of an attacker this bug means that an OpenSSL 3.0 endpoint communicating with a non-OpenSSL 3.0 endpoint will fail to complete the handshake when using this ciphersuite. The confidentiality of data is not impacted by this issue, i.e. an attacker cannot decrypt data that has been encrypted using this ciphersuite - they can only modify it. In order for this attack to work both endpoints must legitimately negotiate the RC4-MD5 ciphersuite. This ciphersuite is not compiled by default in OpenSSL 3.0, and is not available within the default provider or the default ciphersuite list. This ciphersuite will never be used if TLSv1.3 has been negotiated. In order for an OpenSSL 3.0 endpoint to use this ciphersuite the following must have occurred: 1) OpenSSL must have been compiled with the (non-default) compile time option enable-weak-ssl-ciphers 2) OpenSSL must have had the legacy provider explicitly loaded (either through application code or via configuration) 3) The ciphersuite must have been explicitly added to the ciphersuite list 4) The libssl security level must have been set to 0 (default is 1) 5) A version of SSL/TLS below TLSv1.3 must have been negotiated 6) Both endpoints must negotiate the RC4-MD5 ciphersuite in preference to any others that both endpoints have in common Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1434/">CVE-2022-1434</cve>
	<bugzilla href="https://bugzilla.suse.com/1199168">SUSE bug 1199168</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334866" comment="libopenssl1_1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333944" comment="openssl-1_1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221473" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1473</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1473" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1473" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1473" ref_url="https://www.suse.com/security/cve/CVE-2022-1473" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:2306-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-July/023781.html" source="SUSE-SU"/>
    <description>
    The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1473/">CVE-2022-1473</cve>
	<bugzilla href="https://bugzilla.suse.com/1199168">SUSE bug 1199168</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199169">SUSE bug 1199169</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333942" comment="openssl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334866" comment="libopenssl1_1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009333944" comment="openssl-1_1 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221508" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1508</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1508" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1508" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1508" ref_url="https://www.suse.com/security/cve/CVE-2022-1508" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-1508/">CVE-2022-1508</cve>
	<bugzilla href="https://bugzilla.suse.com/1198968">SUSE bug 1198968</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221587" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1587</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1587" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1587" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1587" ref_url="https://www.suse.com/security/cve/CVE-2022-1587" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1680-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1681-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011688.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1682-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1685-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1686-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1688-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1689-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1690-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011696.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011772.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1774-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011815.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1852-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2086-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012145.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2229-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012224.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3032-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2565-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2566-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2649-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011755.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:2649-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZVHVSVNKKW7CC77JRUJ23MMS76WXHBBU/" source="SUSE-SU"/>
    <description>
    An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.6/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2022-1587/">CVE-2022-1587</cve>
	<bugzilla href="https://bugzilla.suse.com/1199235">SUSE bug 1199235</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201754">SUSE bug 1201754</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1203032">SUSE bug 1203032</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335823" comment="libpcre1 is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221619" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1619</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1619" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1619" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1619" ref_url="https://www.suse.com/security/cve/CVE-2022-1619" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2022-1619/">CVE-2022-1619</cve>
	<bugzilla href="https://bugzilla.suse.com/1199333">SUSE bug 1199333</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221621" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1621</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1621" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1621" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1621" ref_url="https://www.suse.com/security/cve/CVE-2022-1621" source="SUSE CVE"/>
    <description>
    Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1621/">CVE-2022-1621</cve>
	<bugzilla href="https://bugzilla.suse.com/1199435">SUSE bug 1199435</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221629" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1629</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1629" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1629" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1629" ref_url="https://www.suse.com/security/cve/CVE-2022-1629" source="SUSE CVE"/>
    <description>
    Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1629/">CVE-2022-1629</cve>
	<bugzilla href="https://bugzilla.suse.com/1199436">SUSE bug 1199436</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221651" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1651</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1651" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1651" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1651" ref_url="https://www.suse.com/security/cve/CVE-2022-1651" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    A memory leak flaw was found in the Linux kernel in acrn_dev_ioctl in the drivers/virt/acrn/hsm.c function in how the ACRN Device Model emulates virtual NICs in VM. This flaw allows a local privileged attacker to leak unauthorized kernel information, causing a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1651/">CVE-2022-1651</cve>
	<bugzilla href="https://bugzilla.suse.com/1199433">SUSE bug 1199433</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221671" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1671</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1671" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1671" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1671" ref_url="https://www.suse.com/security/cve/CVE-2022-1671" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1671/">CVE-2022-1671</cve>
	<bugzilla href="https://bugzilla.suse.com/1199439">SUSE bug 1199439</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221674" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1674</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1674" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1674" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1674" ref_url="https://www.suse.com/security/cve/CVE-2022-1674" source="SUSE CVE"/>
    <description>
    NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-1674/">CVE-2022-1674</cve>
	<bugzilla href="https://bugzilla.suse.com/1199502">SUSE bug 1199502</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221678" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1678</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1678" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1678" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1678" ref_url="https://www.suse.com/security/cve/CVE-2022-1678" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1678/">CVE-2022-1678</cve>
	<bugzilla href="https://bugzilla.suse.com/1199939">SUSE bug 1199939</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221733" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1733</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1733" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1733" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1733" ref_url="https://www.suse.com/security/cve/CVE-2022-1733" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-1733/">CVE-2022-1733</cve>
	<bugzilla href="https://bugzilla.suse.com/1199655">SUSE bug 1199655</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221769" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1769</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1769" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1769" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1769" ref_url="https://www.suse.com/security/cve/CVE-2022-1769" source="SUSE CVE"/>
    <description>
    Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-1769/">CVE-2022-1769</cve>
	<bugzilla href="https://bugzilla.suse.com/1199658">SUSE bug 1199658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221789" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1789</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1789" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1789" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1789" ref_url="https://www.suse.com/security/cve/CVE-2022-1789" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1789/">CVE-2022-1789</cve>
	<bugzilla href="https://bugzilla.suse.com/1199674">SUSE bug 1199674</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221851" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1851</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1851" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1851" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1851" ref_url="https://www.suse.com/security/cve/CVE-2022-1851" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-1851/">CVE-2022-1851</cve>
	<bugzilla href="https://bugzilla.suse.com/1199936">SUSE bug 1199936</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221852" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1852</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1852" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1852" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1852" ref_url="https://www.suse.com/security/cve/CVE-2022-1852" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn in arch/x86/kvm/emulate.c. This flaw occurs while executing an illegal instruction in guest in the Intel CPU.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1852/">CVE-2022-1852</cve>
	<bugzilla href="https://bugzilla.suse.com/1199875">SUSE bug 1199875</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221882" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1882</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1882" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1882" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1882" ref_url="https://www.suse.com/security/cve/CVE-2022-1882" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in the Linux kernel’s pipes functionality in how a user performs manipulations with the pipe post_one_notification() after free_pipe_info() that is already called. This flaw allows a local user to crash or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-24"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1882/">CVE-2022-1882</cve>
	<bugzilla href="https://bugzilla.suse.com/1199904">SUSE bug 1199904</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200058">SUSE bug 1200058</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221886" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1886</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1886" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1886" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1886" ref_url="https://www.suse.com/security/cve/CVE-2022-1886" source="SUSE CVE"/>
    <description>
    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-1886/">CVE-2022-1886</cve>
	<bugzilla href="https://bugzilla.suse.com/1199969">SUSE bug 1199969</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221927" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1927</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1927" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1927" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1927" ref_url="https://www.suse.com/security/cve/CVE-2022-1927" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2102-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4619-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013343.html" source="SUSE-SU"/>
    <description>
    Buffer Over-read in GitHub repository vim/vim prior to 8.2.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" href="https://www.suse.com/security/cve/CVE-2022-1927/">CVE-2022-1927</cve>
	<bugzilla href="https://bugzilla.suse.com/1200012">SUSE bug 1200012</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009475442" comment="vim-data-common is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009655960" comment="vim-small is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221943" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1943</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1943" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1943" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1943" ref_url="https://www.suse.com/security/cve/CVE-2022-1943" source="SUSE CVE"/>
    <description>
    A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1943/">CVE-2022-1943</cve>
	<bugzilla href="https://bugzilla.suse.com/1200055">SUSE bug 1200055</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221966" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1966</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1966" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1966" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1966" ref_url="https://www.suse.com/security/cve/CVE-2022-1966" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011286.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011302.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011311.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2173-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011347.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2629-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011744.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:2173-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CWOILJAA3L3ZOAEUSAUQRV4VH2BJEGVX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:2177-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S2QMD6CJ6PZDFYQ3RKSOGAZNRK7WC5W7/" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-32250. Reason: This candidate is a duplicate of CVE-2022-32250. Notes: All CVE users should reference CVE-2022-32250 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1966/">CVE-2022-1966</cve>
	<bugzilla href="https://bugzilla.suse.com/1200015">SUSE bug 1200015</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200268">SUSE bug 1200268</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200494">SUSE bug 1200494</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200529">SUSE bug 1200529</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221972" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1972</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1972" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1972" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1972" ref_url="https://www.suse.com/security/cve/CVE-2022-1972" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2078-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:2177-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S2QMD6CJ6PZDFYQ3RKSOGAZNRK7WC5W7/" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2078. Reason: This candidate is a reservation duplicate of CVE-2022-2078. Notes: All CVE users should reference CVE-2022-2078 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1972/">CVE-2022-1972</cve>
	<bugzilla href="https://bugzilla.suse.com/1200019">SUSE bug 1200019</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200266">SUSE bug 1200266</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221973" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1973</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1973" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1973" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1973" ref_url="https://www.suse.com/security/cve/CVE-2022-1973" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash the system and leads to a kernel information leak problem.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-1973/">CVE-2022-1973</cve>
	<bugzilla href="https://bugzilla.suse.com/1200023">SUSE bug 1200023</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20221998" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-1998</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-1998" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1998" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-1998" ref_url="https://www.suse.com/security/cve/CVE-2022-1998" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-1998/">CVE-2022-1998</cve>
	<bugzilla href="https://bugzilla.suse.com/1200284">SUSE bug 1200284</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202220009" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-20009</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-20009" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20009" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-20009" ref_url="https://www.suse.com/security/cve/CVE-2022-20009" source="SUSE CVE"/>
    <description>
    In various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-213172319References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-20009/">CVE-2022-20009</cve>
	<bugzilla href="https://bugzilla.suse.com/1199566">SUSE bug 1199566</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202220117" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-20117</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-20117" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20117" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-20117" ref_url="https://www.suse.com/security/cve/CVE-2022-20117" source="SUSE CVE"/>
    <description>
    In (TBD) of (TBD), there is a possible way to decrypt local data encrypted by the GSC due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-217475903References: N/A
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-20117/">CVE-2022-20117</cve>
	<bugzilla href="https://bugzilla.suse.com/1199569">SUSE bug 1199569</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202220118" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-20118</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-20118" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20118" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-20118" ref_url="https://www.suse.com/security/cve/CVE-2022-20118" source="SUSE CVE"/>
    <description>
    In ion_ioctl and related functions of ion.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-205707793References: N/A
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-20118/">CVE-2022-20118</cve>
	<bugzilla href="https://bugzilla.suse.com/1199570">SUSE bug 1199570</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202220119" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-20119</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-20119" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20119" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-20119" ref_url="https://www.suse.com/security/cve/CVE-2022-20119" source="SUSE CVE"/>
    <description>
    In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-213170715References: N/A
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-20119/">CVE-2022-20119</cve>
	<bugzilla href="https://bugzilla.suse.com/1199563">SUSE bug 1199563</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202220148" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-20148</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-20148" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20148" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-20148" ref_url="https://www.suse.com/security/cve/CVE-2022-20148" source="SUSE CVE"/>
    <description>
    In TBD of TBD, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-219513976References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-20148/">CVE-2022-20148</cve>
	<bugzilla href="https://bugzilla.suse.com/1200610">SUSE bug 1200610</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202220153" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-20153</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-20153" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20153" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-20153" ref_url="https://www.suse.com/security/cve/CVE-2022-20153" source="SUSE CVE"/>
    <description>
    In rcu_cblist_dequeue of rcu_segcblist.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222091980References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-20153/">CVE-2022-20153</cve>
	<bugzilla href="https://bugzilla.suse.com/1200609">SUSE bug 1200609</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202220158" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-20158</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-20158" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20158" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-20158" ref_url="https://www.suse.com/security/cve/CVE-2022-20158" source="SUSE CVE"/>
    <description>
    In bdi_put and bdi_unregister of backing-dev.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-182815710References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-02"/>
	<updated date="2022-09-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-20158/">CVE-2022-20158</cve>
	<bugzilla href="https://bugzilla.suse.com/1202345">SUSE bug 1202345</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202220371" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-20371</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-20371" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20371" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-20371" ref_url="https://www.suse.com/security/cve/CVE-2022-20371" source="SUSE CVE"/>
    <description>
    In dm_bow_dtr and related functions of dm-bow.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195565510References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-13"/>
	<updated date="2022-08-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-20371/">CVE-2022-20371</cve>
	<bugzilla href="https://bugzilla.suse.com/1202348">SUSE bug 1202348</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202220382" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-20382</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-20382" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20382" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-20382" ref_url="https://www.suse.com/security/cve/CVE-2022-20382" source="SUSE CVE"/>
    <description>
    In (TBD) of (TBD), there is a possible out of bounds write due to kernel stack overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-214245176References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-13"/>
	<updated date="2022-08-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-20382/">CVE-2022-20382</cve>
	<bugzilla href="https://bugzilla.suse.com/1202349">SUSE bug 1202349</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222078" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2078</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2078" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2078" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2078" ref_url="https://www.suse.com/security/cve/CVE-2022-2078" source="SUSE CVE"/>
    <description>
    A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of service and possibly to run code.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-2078/">CVE-2022-2078</cve>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202221505" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-21505</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-21505" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21505" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-21505" ref_url="https://www.suse.com/security/cve/CVE-2022-21505" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2722-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011908.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011914.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011976.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2875-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011993.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2892-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012040.html" source="SUSE-SU"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-10"/>
	<updated date="2022-10-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-21505/">CVE-2022-21505</cve>
	<bugzilla href="https://bugzilla.suse.com/1201458">SUSE bug 1201458</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222196" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2196</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2196" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2196" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2196" ref_url="https://www.suse.com/security/cve/CVE-2022-2196" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2140-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2141-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2146-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2147-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2148-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2231-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029435.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
    <description>
    A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks.?L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB?after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or past commit?2e7eab81425a

    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-11"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-2196/">CVE-2022-2196</cve>
	<bugzilla href="https://bugzilla.suse.com/1206992">SUSE bug 1206992</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222058" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22058</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22058" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22058" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22058" ref_url="https://www.suse.com/security/cve/CVE-2022-22058" source="SUSE CVE"/>
    <description>
    Memory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &amp; Music, Snapdragon Wearables
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-29"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-22058/">CVE-2022-22058</cve>
	<bugzilla href="https://bugzilla.suse.com/1203777">SUSE bug 1203777</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222075" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22075</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22075" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22075" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22075" ref_url="https://www.suse.com/security/cve/CVE-2022-22075" source="SUSE CVE"/>
    <description>
    Information Disclosure in Graphics during GPU context switch.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-14"/>
	<updated date="2023-03-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-22075/">CVE-2022-22075</cve>
	<bugzilla href="https://bugzilla.suse.com/1209195">SUSE bug 1209195</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222209" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2209</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2209" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2209" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2209" ref_url="https://www.suse.com/security/cve/CVE-2022-2209" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2022-2209/">CVE-2022-2209</cve>
	<bugzilla href="https://bugzilla.suse.com/1201828">SUSE bug 1201828</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222822" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22822</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22822" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22822" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22822" ref_url="https://www.suse.com/security/cve/CVE-2022-22822" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:58-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:60-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-January/021467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0178-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5POFOWWCWJ3SLTEUIQRMKXQB4GOECNOP/" source="SUSE-SU"/>
    <description>
    addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-22822/">CVE-2022-22822</cve>
	<bugzilla href="https://bugzilla.suse.com/1194474">SUSE bug 1194474</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195327">SUSE bug 1195327</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664062" comment="libexpat1-2.2.5-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222823" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22823</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22823" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22823" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22823" ref_url="https://www.suse.com/security/cve/CVE-2022-22823" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:58-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:60-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-January/021467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0178-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5POFOWWCWJ3SLTEUIQRMKXQB4GOECNOP/" source="SUSE-SU"/>
    <description>
    build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-22823/">CVE-2022-22823</cve>
	<bugzilla href="https://bugzilla.suse.com/1194476">SUSE bug 1194476</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195327">SUSE bug 1195327</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664062" comment="libexpat1-2.2.5-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222824" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22824</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22824" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22824" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22824" ref_url="https://www.suse.com/security/cve/CVE-2022-22824" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:58-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:60-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-January/021467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0178-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5POFOWWCWJ3SLTEUIQRMKXQB4GOECNOP/" source="SUSE-SU"/>
    <description>
    defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-22824/">CVE-2022-22824</cve>
	<bugzilla href="https://bugzilla.suse.com/1194477">SUSE bug 1194477</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195327">SUSE bug 1195327</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664062" comment="libexpat1-2.2.5-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222825" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22825</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22825" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22825" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22825" ref_url="https://www.suse.com/security/cve/CVE-2022-22825" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:58-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:60-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-January/021467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0178-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5POFOWWCWJ3SLTEUIQRMKXQB4GOECNOP/" source="SUSE-SU"/>
    <description>
    lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-22825/">CVE-2022-22825</cve>
	<bugzilla href="https://bugzilla.suse.com/1194478">SUSE bug 1194478</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195327">SUSE bug 1195327</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664062" comment="libexpat1-2.2.5-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222826" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22826</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22826" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22826" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22826" ref_url="https://www.suse.com/security/cve/CVE-2022-22826" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:58-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:60-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-January/021467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0178-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5POFOWWCWJ3SLTEUIQRMKXQB4GOECNOP/" source="SUSE-SU"/>
    <description>
    nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-22826/">CVE-2022-22826</cve>
	<bugzilla href="https://bugzilla.suse.com/1194479">SUSE bug 1194479</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195327">SUSE bug 1195327</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664062" comment="libexpat1-2.2.5-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222827" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22827</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22827" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22827" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22827" ref_url="https://www.suse.com/security/cve/CVE-2022-22827" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010140.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:109-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:58-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010077.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:60-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-January/021467.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:64-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:69-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010092.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:76-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010099.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:80-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:81-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:88-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010111.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:90-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010113.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:91-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:92-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010115.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:93-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010116.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010136.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010137.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:28-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010128.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:29-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010129.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:30-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010130.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:31-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010131.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:32-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010132.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:36-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010139.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:49-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0178-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010063.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0179-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010069.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-January/010066.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0178-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/5POFOWWCWJ3SLTEUIQRMKXQB4GOECNOP/" source="SUSE-SU"/>
    <description>
    storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-22827/">CVE-2022-22827</cve>
	<bugzilla href="https://bugzilla.suse.com/1194480">SUSE bug 1194480</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195327">SUSE bug 1195327</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009664062" comment="libexpat1-2.2.5-3.9.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222934" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22934</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22934" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22934" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22934" ref_url="https://www.suse.com/security/cve/CVE-2022-22934" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010578.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1060-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1527-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1529-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010934.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1533-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010932.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1537-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010933.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010947.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M6VBWD2MJTOPNB6DMK7CF6TQJ4N7ZFUD/" source="SUSE-SU"/>
    <description>
    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-22934/">CVE-2022-22934</cve>
	<bugzilla href="https://bugzilla.suse.com/1197417">SUSE bug 1197417</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197765">SUSE bug 1197765</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009680833" comment="python3-salt-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680834" comment="salt-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680841" comment="salt-minion-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009681002" comment="salt-transactional-update-3002.2-150200.64.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222935" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22935</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22935" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22935" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22935" ref_url="https://www.suse.com/security/cve/CVE-2022-22935" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010578.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1060-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1527-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1529-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1533-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010932.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1537-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010933.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010947.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M6VBWD2MJTOPNB6DMK7CF6TQJ4N7ZFUD/" source="SUSE-SU"/>
    <description>
    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.5/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-22935/">CVE-2022-22935</cve>
	<bugzilla href="https://bugzilla.suse.com/1197417">SUSE bug 1197417</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197765">SUSE bug 1197765</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009680833" comment="python3-salt-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680834" comment="salt-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680841" comment="salt-minion-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009681002" comment="salt-transactional-update-3002.2-150200.64.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222936" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22936</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22936" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22936" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22936" ref_url="https://www.suse.com/security/cve/CVE-2022-22936" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010578.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1060-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1527-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1529-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010934.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1533-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010932.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1537-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010933.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010947.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M6VBWD2MJTOPNB6DMK7CF6TQJ4N7ZFUD/" source="SUSE-SU"/>
    <description>
    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run old jobs. File server replies can also be re-played. A sufficient craft attacker could gain root access on minion under certain scenarios.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-22936/">CVE-2022-22936</cve>
	<bugzilla href="https://bugzilla.suse.com/1197417">SUSE bug 1197417</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197765">SUSE bug 1197765</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009680833" comment="python3-salt-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680834" comment="salt-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680841" comment="salt-minion-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009681002" comment="salt-transactional-update-3002.2-150200.64.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222941" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22941</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22941" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22941" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22941" ref_url="https://www.suse.com/security/cve/CVE-2022-22941" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010581.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010576.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1050-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010578.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1051-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1056-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010572.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1059-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1060-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010571.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14932-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14933-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010585.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1514-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1527-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1529-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010936.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1531-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010934.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1533-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010937.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010931.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1536-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010932.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1537-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010933.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1538-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1545-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010947.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1059-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M6VBWD2MJTOPNB6DMK7CF6TQJ4N7ZFUD/" source="SUSE-SU"/>
    <description>
    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configured commands. This requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured minion.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-22941/">CVE-2022-22941</cve>
	<bugzilla href="https://bugzilla.suse.com/1197417">SUSE bug 1197417</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197765">SUSE bug 1197765</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009680833" comment="python3-salt-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680834" comment="salt-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680841" comment="salt-minion-3002.2-150200.64.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009681002" comment="salt-transactional-update-3002.2-150200.64.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202222942" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-22942</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-22942" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22942" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-22942" ref_url="https://www.suse.com/security/cve/CVE-2022-22942" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0363-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021670.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010216.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0372-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010282.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010721.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010733.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010776.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1593-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010977.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011310.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0363-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K4ZJSATCJ2GMGCX6RSG2TU2YU4DDOMVQ/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0370-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ASMTCFCDULHGAOBQUFJH4PHVCQSTF7S6/" source="SUSE-SU"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-22942/">CVE-2022-22942</cve>
	<bugzilla href="https://bugzilla.suse.com/1195065">SUSE bug 1195065</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1195951">SUSE bug 1195951</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009667498" comment="kernel-default-5.3.18-24.102.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009667499" comment="kernel-default-base-5.3.18-24.102.1.9.48.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009668286" comment="kernel-rt-5.3.18-73.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223033" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23033</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23033" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23033" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23033" ref_url="https://www.suse.com/security/cve/CVE-2022-23033" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0333-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0467-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010239.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0468-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010242.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0469-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010241.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0333-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XIM2A32O55DKEA5CCA7L5EE2KL4DYQJF/" source="SUSE-SU"/>
    <description>
    arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2m pagetable on Arm (p2m_remove_mapping, guest_physmap_remove_page, and p2m_set_entry with mfn set to INVALID_MFN) do not actually clear the pagetable entry if the entry doesn't have the valid bit set. It is possible to have a valid pagetable entry without the valid bit set when a guest operating system uses set/way cache maintenance instructions. For instance, a guest issuing a set/way cache maintenance instruction, then calling the XENMEM_decrease_reservation hypercall to give back memory pages to Xen, might be able to retain access to those pages even after Xen started reusing them for other purposes.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23033/">CVE-2022-23033</cve>
	<bugzilla href="https://bugzilla.suse.com/1194576">SUSE bug 1194576</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009665606" comment="xen-libs-4.13.4_04-3.43.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223034" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23034</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23034" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23034" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23034" ref_url="https://www.suse.com/security/cve/CVE-2022-23034" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010190.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0333-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010198.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0467-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010239.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0468-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010242.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0469-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010241.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14886-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010240.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0333-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XIM2A32O55DKEA5CCA7L5EE2KL4DYQJF/" source="SUSE-SU"/>
    <description>
    A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mappings for the case where a PV guest would have the IOMMU enabled. PV guests can request two forms of mappings. When both are in use for any individual mapping, unmapping of such a mapping can be requested in two steps. The reference count for such a mapping would then mistakenly be decremented twice. Underflow of the counters gets detected, resulting in the triggering of a hypervisor bug check.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-23034/">CVE-2022-23034</cve>
	<bugzilla href="https://bugzilla.suse.com/1194581">SUSE bug 1194581</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009665606" comment="xen-libs-4.13.4_04-3.43.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223035" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23035</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23035" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23035" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23035" ref_url="https://www.suse.com/security/cve/CVE-2022-23035" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010190.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0333-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010182.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010191.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010198.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0467-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010239.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0468-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010242.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0469-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010241.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14886-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010240.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0333-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XIM2A32O55DKEA5CCA7L5EE2KL4DYQJF/" source="SUSE-SU"/>
    <description>
    Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x86 HVM guests involves an iterative operation in particular when cleaning up after the guest's use of the device. In the case where an interrupt is not quiescent yet at the time this cleanup gets invoked, the cleanup attempt may be scheduled to be retried. When multiple interrupts are involved, this scheduling of a retry may get erroneously skipped. At the same time pointers may get cleared (resulting in a de-reference of NULL) and freed (resulting in a use-after-free), while other code would continue to assume them to be valid.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-23035/">CVE-2022-23035</cve>
	<bugzilla href="https://bugzilla.suse.com/1194588">SUSE bug 1194588</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009665606" comment="xen-libs-4.13.4_04-3.43.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223036" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23036</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23036" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23036" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23036" ref_url="https://www.suse.com/security/cve/CVE-2022-23036" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the success of removing the granted access of a shared ring buffer. blkfront: CVE-2022-23036 netfront: CVE-2022-23037 scsifront: CVE-2022-23038 gntalloc: CVE-2022-23039 xenbus: CVE-2022-23040 blkfront, netfront, scsifront, usbfront, dmabuf, xenbus, 9p, kbdfront, and pvcalls are using a functionality to delay freeing a grant reference until it is no longer in use, but the freeing of the related data page is not synchronized with dropping the granted access. As a result the backend can keep access to the memory page even after it has been freed and then re-used for a different purpose. CVE-2022-23041 netfront will fail a BUG_ON() assertion if it fails to revoke access in the rx path. This will result in a Denial of Service (DoS) situation of the guest which can be triggered by the backend. CVE-2022-23042
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23036/">CVE-2022-23036</cve>
	<bugzilla href="https://bugzilla.suse.com/1196488">SUSE bug 1196488</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199099">SUSE bug 1199099</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199141">SUSE bug 1199141</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204132">SUSE bug 1204132</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223037" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23037</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23037" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23037" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23037" ref_url="https://www.suse.com/security/cve/CVE-2022-23037" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the success of removing the granted access of a shared ring buffer. blkfront: CVE-2022-23036 netfront: CVE-2022-23037 scsifront: CVE-2022-23038 gntalloc: CVE-2022-23039 xenbus: CVE-2022-23040 blkfront, netfront, scsifront, usbfront, dmabuf, xenbus, 9p, kbdfront, and pvcalls are using a functionality to delay freeing a grant reference until it is no longer in use, but the freeing of the related data page is not synchronized with dropping the granted access. As a result the backend can keep access to the memory page even after it has been freed and then re-used for a different purpose. CVE-2022-23041 netfront will fail a BUG_ON() assertion if it fails to revoke access in the rx path. This will result in a Denial of Service (DoS) situation of the guest which can be triggered by the backend. CVE-2022-23042
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23037/">CVE-2022-23037</cve>
	<bugzilla href="https://bugzilla.suse.com/1199099">SUSE bug 1199099</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199141">SUSE bug 1199141</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204132">SUSE bug 1204132</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223038" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23038</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23038" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23038" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23038" ref_url="https://www.suse.com/security/cve/CVE-2022-23038" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the success of removing the granted access of a shared ring buffer. blkfront: CVE-2022-23036 netfront: CVE-2022-23037 scsifront: CVE-2022-23038 gntalloc: CVE-2022-23039 xenbus: CVE-2022-23040 blkfront, netfront, scsifront, usbfront, dmabuf, xenbus, 9p, kbdfront, and pvcalls are using a functionality to delay freeing a grant reference until it is no longer in use, but the freeing of the related data page is not synchronized with dropping the granted access. As a result the backend can keep access to the memory page even after it has been freed and then re-used for a different purpose. CVE-2022-23041 netfront will fail a BUG_ON() assertion if it fails to revoke access in the rx path. This will result in a Denial of Service (DoS) situation of the guest which can be triggered by the backend. CVE-2022-23042
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23038/">CVE-2022-23038</cve>
	<bugzilla href="https://bugzilla.suse.com/1199099">SUSE bug 1199099</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199141">SUSE bug 1199141</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204132">SUSE bug 1204132</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223039" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23039</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23039" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23039" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23039" ref_url="https://www.suse.com/security/cve/CVE-2022-23039" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the success of removing the granted access of a shared ring buffer. blkfront: CVE-2022-23036 netfront: CVE-2022-23037 scsifront: CVE-2022-23038 gntalloc: CVE-2022-23039 xenbus: CVE-2022-23040 blkfront, netfront, scsifront, usbfront, dmabuf, xenbus, 9p, kbdfront, and pvcalls are using a functionality to delay freeing a grant reference until it is no longer in use, but the freeing of the related data page is not synchronized with dropping the granted access. As a result the backend can keep access to the memory page even after it has been freed and then re-used for a different purpose. CVE-2022-23041 netfront will fail a BUG_ON() assertion if it fails to revoke access in the rx path. This will result in a Denial of Service (DoS) situation of the guest which can be triggered by the backend. CVE-2022-23042
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23039/">CVE-2022-23039</cve>
	<bugzilla href="https://bugzilla.suse.com/1199099">SUSE bug 1199099</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199141">SUSE bug 1199141</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204132">SUSE bug 1204132</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223040" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23040</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23040" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23040" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23040" ref_url="https://www.suse.com/security/cve/CVE-2022-23040" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the success of removing the granted access of a shared ring buffer. blkfront: CVE-2022-23036 netfront: CVE-2022-23037 scsifront: CVE-2022-23038 gntalloc: CVE-2022-23039 xenbus: CVE-2022-23040 blkfront, netfront, scsifront, usbfront, dmabuf, xenbus, 9p, kbdfront, and pvcalls are using a functionality to delay freeing a grant reference until it is no longer in use, but the freeing of the related data page is not synchronized with dropping the granted access. As a result the backend can keep access to the memory page even after it has been freed and then re-used for a different purpose. CVE-2022-23041 netfront will fail a BUG_ON() assertion if it fails to revoke access in the rx path. This will result in a Denial of Service (DoS) situation of the guest which can be triggered by the backend. CVE-2022-23042
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23040/">CVE-2022-23040</cve>
	<bugzilla href="https://bugzilla.suse.com/1199099">SUSE bug 1199099</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199141">SUSE bug 1199141</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204132">SUSE bug 1204132</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223041" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23041</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23041" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23041" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23041" ref_url="https://www.suse.com/security/cve/CVE-2022-23041" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the success of removing the granted access of a shared ring buffer. blkfront: CVE-2022-23036 netfront: CVE-2022-23037 scsifront: CVE-2022-23038 gntalloc: CVE-2022-23039 xenbus: CVE-2022-23040 blkfront, netfront, scsifront, usbfront, dmabuf, xenbus, 9p, kbdfront, and pvcalls are using a functionality to delay freeing a grant reference until it is no longer in use, but the freeing of the related data page is not synchronized with dropping the granted access. As a result the backend can keep access to the memory page even after it has been freed and then re-used for a different purpose. CVE-2022-23041 netfront will fail a BUG_ON() assertion if it fails to revoke access in the rx path. This will result in a Denial of Service (DoS) situation of the guest which can be triggered by the backend. CVE-2022-23042
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23041/">CVE-2022-23041</cve>
	<bugzilla href="https://bugzilla.suse.com/1199099">SUSE bug 1199099</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199141">SUSE bug 1199141</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204132">SUSE bug 1204132</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223042" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23042</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23042" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23042" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23042" ref_url="https://www.suse.com/security/cve/CVE-2022-23042" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access rights of the backends in ways being subject to race conditions, resulting in potential data leaks, data corruption by malicious backends, and denial of service triggered by malicious backends: blkfront, netfront, scsifront and the gntalloc driver are testing whether a grant reference is still in use. If this is not the case, they assume that a following removal of the granted access will always succeed, which is not true in case the backend has mapped the granted page between those two operations. As a result the backend can keep access to the memory page of the guest no matter how the page will be used after the frontend I/O has finished. The xenbus driver has a similar problem, as it doesn't check the success of removing the granted access of a shared ring buffer. blkfront: CVE-2022-23036 netfront: CVE-2022-23037 scsifront: CVE-2022-23038 gntalloc: CVE-2022-23039 xenbus: CVE-2022-23040 blkfront, netfront, scsifront, usbfront, dmabuf, xenbus, 9p, kbdfront, and pvcalls are using a functionality to delay freeing a grant reference until it is no longer in use, but the freeing of the related data page is not synchronized with dropping the granted access. As a result the backend can keep access to the memory page even after it has been freed and then re-used for a different purpose. CVE-2022-23041 netfront will fail a BUG_ON() assertion if it fails to revoke access in the rx path. This will result in a Denial of Service (DoS) situation of the guest which can be triggered by the backend. CVE-2022-23042
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23042/">CVE-2022-23042</cve>
	<bugzilla href="https://bugzilla.suse.com/1199099">SUSE bug 1199099</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199141">SUSE bug 1199141</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204132">SUSE bug 1204132</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222308" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2308</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2308" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2308" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2308" ref_url="https://www.suse.com/security/cve/CVE-2022-2308" source="SUSE CVE"/>
    <description>
    A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in line with the features advertised by the VDUSE userspace application. In case of a mismatch, Virtio drivers config read helpers do not initialize the memory indirectly passed to vduse_vdpa_get_config() returning uninitialized memory from the stack. This could cause undefined behavior or data leaks in Virtio drivers.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-20"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-2308/">CVE-2022-2308</cve>
	<bugzilla href="https://bugzilla.suse.com/1202573">SUSE bug 1202573</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223218" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23218</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23218" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23218" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23218" ref_url="https://www.suse.com/security/cve/CVE-2022-23218" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010193.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010226.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010233.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010314.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:286-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010468.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:290-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010514.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0330-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0909-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010485.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010489.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0330-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WUNMTSOEM6LU65NFICFVIHBARFG7LVO7/" source="SUSE-SU"/>
    <description>
    The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2022-23218/">CVE-2022-23218</cve>
	<bugzilla href="https://bugzilla.suse.com/1194770">SUSE bug 1194770</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199869">SUSE bug 1199869</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200036">SUSE bug 1200036</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669024" comment="glibc-2.26-13.65.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669032" comment="glibc-locale-2.26-13.65.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669033" comment="glibc-locale-base-2.26-13.65.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223219" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23219</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23219" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23219" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23219" ref_url="https://www.suse.com/security/cve/CVE-2022-23219" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:117-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010193.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:120-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010194.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010200.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:137-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:138-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:140-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010205.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010206.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010207.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010208.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:175-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010226.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:176-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010233.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010314.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:276-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:286-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010468.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:290-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010514.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010516.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0330-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010230.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0832-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0909-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010485.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010489.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0330-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WUNMTSOEM6LU65NFICFVIHBARFG7LVO7/" source="SUSE-SU"/>
    <description>
    The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2022-23219/">CVE-2022-23219</cve>
	<bugzilla href="https://bugzilla.suse.com/1194768">SUSE bug 1194768</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199869">SUSE bug 1199869</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200036">SUSE bug 1200036</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669024" comment="glibc-2.26-13.65.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669032" comment="glibc-locale-2.26-13.65.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669033" comment="glibc-locale-base-2.26-13.65.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223222" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23222</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23222" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23222" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23222" ref_url="https://www.suse.com/security/cve/CVE-2022-23222" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23222/">CVE-2022-23222</cve>
	<bugzilla href="https://bugzilla.suse.com/1194765">SUSE bug 1194765</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222327" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2327</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2327" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2327" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2327" ref_url="https://www.suse.com/security/cve/CVE-2022-2327" source="SUSE CVE"/>
    <description>
    io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2022-2327/">CVE-2022-2327</cve>
	<bugzilla href="https://bugzilla.suse.com/1201829">SUSE bug 1201829</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223303" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23303</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23303" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23303" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23303" ref_url="https://www.suse.com/security/cve/CVE-2022-23303" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0716-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0716-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YZLUSHYXTE7JA3KCOVKZ5L36DTZE7VZM/" source="SUSE-SU"/>
    <description>
    The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-05"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23303/">CVE-2022-23303</cve>
	<bugzilla href="https://bugzilla.suse.com/1194732">SUSE bug 1194732</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205064">SUSE bug 1205064</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669199" comment="wpa_supplicant-2.9-4.33.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223304" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23304</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23304" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23304" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23304" ref_url="https://www.suse.com/security/cve/CVE-2022-23304" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:0716-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010363.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0716-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011164.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0716-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YZLUSHYXTE7JA3KCOVKZ5L36DTZE7VZM/" source="SUSE-SU"/>
    <description>
    The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-11-05"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23304/">CVE-2022-23304</cve>
	<bugzilla href="https://bugzilla.suse.com/1194733">SUSE bug 1194733</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205064">SUSE bug 1205064</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669199" comment="wpa_supplicant-2.9-4.33.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223648" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23648</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23648" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23648" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23648" ref_url="https://www.suse.com/security/cve/CVE-2022-23648" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0719-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010359.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0720-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0720-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-April/022656.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1689-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011030.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0720-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZII6Q7ZAGJJ37CB2SMGVMILNG766D3EX/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:10022-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/43ATI5PP2NX5LEC336CTPYZBZIQPNK2B/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:10094-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TFXT5GO737TPBRXIUOZS7A3WOJKWSJAX/" source="SUSE-SU"/>
    <description>
    containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation. This bug has been fixed in containerd 1.6.1, 1.5.10, and 1.4.12. Users should update to these versions to resolve the issue.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-23648/">CVE-2022-23648</cve>
	<bugzilla href="https://bugzilla.suse.com/1196441">SUSE bug 1196441</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009681381" comment="containerd-1.5.11-150000.68.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009681382" comment="docker-20.10.14_ce-150000.163.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222380" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2380</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2380" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2380" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2380" ref_url="https://www.suse.com/security/cve/CVE-2022-2380" source="SUSE CVE"/>
    <description>
    The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() function. The vulnerability could result in local attackers being able to crash the kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-2380/">CVE-2022-2380</cve>
	<bugzilla href="https://bugzilla.suse.com/1201378">SUSE bug 1201378</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223816" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23816</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23816" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23816" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23816" ref_url="https://www.suse.com/security/cve/CVE-2022-23816" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2557-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2560-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2569-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011684.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2574-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011700.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011715.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2599-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011718.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2599-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012059.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2600-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011720.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011717.html" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-09"/>
	<updated date="2023-01-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.6/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-23816/">CVE-2022-23816</cve>
	<bugzilla href="https://bugzilla.suse.com/1201456">SUSE bug 1201456</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201469">SUSE bug 1201469</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223852" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23852</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23852" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23852" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23852" ref_url="https://www.suse.com/security/cve/CVE-2022-23852" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010297.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010314.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010253.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010268.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14884-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010199.html" source="SUSE-SU"/>
		<reference ref_id="TID000020633" ref_url="https://www.suse.com/support/kb/doc/?id=000020633" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0498-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2BCJZG2PLWMYBP7YS7O3T6NSE3AKSEBB/" source="SUSE-SU"/>
    <description>
    Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23852/">CVE-2022-23852</cve>
	<bugzilla href="https://bugzilla.suse.com/1195054">SUSE bug 1195054</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196480">SUSE bug 1196480</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009665462" comment="libexpat1-2.2.5-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202223990" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-23990</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-23990" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23990" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-23990" ref_url="https://www.suse.com/security/cve/CVE-2022-23990" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:180-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:181-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:186-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:208-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010293.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:211-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010297.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:217-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:222-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010314.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:238-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:282-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-February/021863.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:284-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010253.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010268.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14884-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010199.html" source="SUSE-SU"/>
		<reference ref_id="TID000020633" ref_url="https://www.suse.com/support/kb/doc/?id=000020633" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0498-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2BCJZG2PLWMYBP7YS7O3T6NSE3AKSEBB/" source="SUSE-SU"/>
    <description>
    Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-23990/">CVE-2022-23990</cve>
	<bugzilla href="https://bugzilla.suse.com/1195217">SUSE bug 1195217</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196480">SUSE bug 1196480</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009665462" comment="libexpat1-2.2.5-3.12.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202224122" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-24122</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-24122" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24122" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-24122" ref_url="https://www.suse.com/security/cve/CVE-2022-24122" source="SUSE CVE"/>
    <description>
    kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-24122/">CVE-2022-24122</cve>
	<bugzilla href="https://bugzilla.suse.com/1195306">SUSE bug 1195306</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196028">SUSE bug 1196028</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202224407" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-24407</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-24407" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24407" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-24407" ref_url="https://www.suse.com/security/cve/CVE-2022-24407" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:241-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010373.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:252-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010375.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010385.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2655-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010386.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:308-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:312-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010480.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010513.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010514.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:343-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010517.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:344-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010518.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:345-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:346-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010520.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010521.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010522.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:350-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010524.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:351-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010525.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:352-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010526.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:353-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:363-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:372-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010535.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010538.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:404-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010539.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:405-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010540.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010541.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:414-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010543.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010544.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:492-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010633.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:494-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010635.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:495-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:496-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:497-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:498-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:499-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010640.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014663.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010322.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0693-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0702-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0743-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010383.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0743-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010704.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010287.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0743-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BPABQLPWLWVSDVE54YNNZUHMKWEV6F3X/" source="SUSE-SU"/>
    <description>
    In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-29"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-24407/">CVE-2022-24407</cve>
	<bugzilla href="https://bugzilla.suse.com/1196036">SUSE bug 1196036</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198600">SUSE bug 1198600</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199112">SUSE bug 1199112</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199494">SUSE bug 1199494</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200197">SUSE bug 1200197</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200200">SUSE bug 1200200</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009669200" comment="cyrus-sasl-2.1.26-5.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669205" comment="cyrus-sasl-digestmd5-2.1.26-5.10.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669214" comment="libsasl2-3-2.1.26-5.10.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202224448" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-24448</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-24448" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24448" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-24448" ref_url="https://www.suse.com/security/cve/CVE-2022-24448" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0555-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-February/010290.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010402.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2080-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011286.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0768-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns uninitialized data in the file descriptor.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-24448/">CVE-2022-24448</cve>
	<bugzilla href="https://bugzilla.suse.com/1195612">SUSE bug 1195612</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202224769" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-24769</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-24769" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24769" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-24769" ref_url="https://www.suse.com/security/cve/CVE-2022-24769" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1689-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011030.html" source="SUSE-SU"/>
    <description>
    Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during `execve(2)`. Normally, when executable programs have specified permitted file capabilities, otherwise unprivileged users and processes can execute those programs and gain the specified file capabilities up to the bounding set. Due to this bug, containers which included executable programs with inheritable file capabilities allowed otherwise unprivileged users and processes to additionally gain these inheritable file capabilities up to the container's bounding set. Containers which use Linux users and groups to perform privilege separation inside the container are most directly impacted. This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in Moby (Docker Engine) 20.10.14. Running containers should be stopped, deleted, and recreated for the inheritable capabilities to be reset. This fix changes Moby (Docker Engine) behavior such that containers are started with a more typical Linux environment. As a workaround, the entry point of a container can be modified to use a utility like `capsh(1)` to drop inheritable capabilities prior to the primary process starting.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2022-24769/">CVE-2022-24769</cve>
	<bugzilla href="https://bugzilla.suse.com/1197517">SUSE bug 1197517</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009681381" comment="containerd-1.5.11-150000.68.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009681382" comment="docker-20.10.14_ce-150000.163.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202224958" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-24958</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-24958" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24958" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-24958" ref_url="https://www.suse.com/security/cve/CVE-2022-24958" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev-&gt;buf release.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-24958/">CVE-2022-24958</cve>
	<bugzilla href="https://bugzilla.suse.com/1195905">SUSE bug 1195905</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202224959" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-24959</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-24959" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24959" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-24959" ref_url="https://www.suse.com/security/cve/CVE-2022-24959" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010402.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010398.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010400.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010394.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010399.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010395.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0768-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-24959/">CVE-2022-24959</cve>
	<bugzilla href="https://bugzilla.suse.com/1195897">SUSE bug 1195897</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202225235" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-25235</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-25235" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25235" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-25235" ref_url="https://www.suse.com/security/cve/CVE-2022-25235" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1425-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1471-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011507.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011814.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:258-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010538.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:953-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0698-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010336.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010357.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14903-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0713-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6H3EOIG3ASUYP7RIHFPOJG3PFJYN54WT/" source="SUSE-SU"/>
    <description>
    xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-25235/">CVE-2022-25235</cve>
	<bugzilla href="https://bugzilla.suse.com/1196026">SUSE bug 1196026</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197217">SUSE bug 1197217</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198587">SUSE bug 1198587</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201735">SUSE bug 1201735</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669765" comment="libexpat1-2.2.5-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202225236" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-25236</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-25236" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25236" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-25236" ref_url="https://www.suse.com/security/cve/CVE-2022-25236" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1425-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1471-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011507.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011814.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:258-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:279-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010464.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:295-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:363-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:365-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010531.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:368-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010532.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:373-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010538.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:916-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010959.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:917-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010960.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:953-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0698-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010336.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010357.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0842-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010442.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0844-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010758.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14903-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14934-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010614.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0713-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6H3EOIG3ASUYP7RIHFPOJG3PFJYN54WT/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0844-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WAE6CSZY5X5K62OKNSD5W35BIQQRELP4/" source="SUSE-SU"/>
    <description>
    xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-25236/">CVE-2022-25236</cve>
	<bugzilla href="https://bugzilla.suse.com/1196025">SUSE bug 1196025</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196784">SUSE bug 1196784</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197217">SUSE bug 1197217</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201735">SUSE bug 1201735</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671238" comment="libexpat1-2.2.5-3.19.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202225258" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-25258</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-25258" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25258" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-25258" ref_url="https://www.suse.com/security/cve/CVE-2022-25258" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-25258/">CVE-2022-25258</cve>
	<bugzilla href="https://bugzilla.suse.com/1196095">SUSE bug 1196095</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196132">SUSE bug 1196132</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
</definition>
<definition id="oval:org.opensuse.security:def:202225265" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-25265</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-25265" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25265" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-25265" ref_url="https://www.suse.com/security/cve/CVE-2022-25265" source="SUSE CVE"/>
    <description>
    In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-25265/">CVE-2022-25265</cve>
	<bugzilla href="https://bugzilla.suse.com/1196134">SUSE bug 1196134</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009625089" comment="libgcc_s1 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009625100" comment="libstdc++6 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202225313" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-25313</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-25313" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25313" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-25313" ref_url="https://www.suse.com/security/cve/CVE-2022-25313" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1425-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1471-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011507.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011814.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:258-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010538.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:953-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0698-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010336.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010357.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14903-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0713-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6H3EOIG3ASUYP7RIHFPOJG3PFJYN54WT/" source="SUSE-SU"/>
    <description>
    In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-25313/">CVE-2022-25313</cve>
	<bugzilla href="https://bugzilla.suse.com/1196168">SUSE bug 1196168</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669765" comment="libexpat1-2.2.5-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202225314" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-25314</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-25314" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25314" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-25314" ref_url="https://www.suse.com/security/cve/CVE-2022-25314" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1425-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1471-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011507.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011814.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:258-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010538.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:953-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0698-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010336.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010357.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14903-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0713-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6H3EOIG3ASUYP7RIHFPOJG3PFJYN54WT/" source="SUSE-SU"/>
    <description>
    In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-25314/">CVE-2022-25314</cve>
	<bugzilla href="https://bugzilla.suse.com/1196169">SUSE bug 1196169</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197217">SUSE bug 1197217</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198587">SUSE bug 1198587</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199096">SUSE bug 1199096</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669765" comment="libexpat1-2.2.5-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202225315" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-25315</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-25315" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25315" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-25315" ref_url="https://www.suse.com/security/cve/CVE-2022-25315" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1415-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1425-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011453.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011454.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011455.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011456.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011457.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011458.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011460.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011461.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1471-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011507.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011795.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011814.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2123-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012187.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2125-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012188.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2126-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012189.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:243-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010345.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:244-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010379.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:258-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010381.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:263-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010384.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:302-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:309-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010478.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:310-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010479.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010481.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:314-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010482.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:315-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010483.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:316-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010484.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010515.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:362-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:364-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:370-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:371-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010534.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010538.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:491-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010632.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:493-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010645.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:953-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:954-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011619.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0698-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010336.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0713-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010357.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:14903-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010361.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2294-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011419.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0713-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6H3EOIG3ASUYP7RIHFPOJG3PFJYN54WT/" source="SUSE-SU"/>
    <description>
    In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-04-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-25315/">CVE-2022-25315</cve>
	<bugzilla href="https://bugzilla.suse.com/1196171">SUSE bug 1196171</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197217">SUSE bug 1197217</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198587">SUSE bug 1198587</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200038">SUSE bug 1200038</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200198">SUSE bug 1200198</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201735">SUSE bug 1201735</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009669765" comment="libexpat1-2.2.5-3.15.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202225375" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-25375</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-25375" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25375" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-25375" ref_url="https://www.suse.com/security/cve/CVE-2022-25375" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:357-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022067.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:358-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-March/022068.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010422.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0755-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010393.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010397.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010391.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0755-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/PDLUIZF7VQIB7OV6GCQHOPOBN2UU2POW/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:0760-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GIEQJF6RAZADJBWJQFLIHOBULB4E2C7K/" source="SUSE-SU"/>
    <description>
    An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-25375/">CVE-2022-25375</cve>
	<bugzilla href="https://bugzilla.suse.com/1196235">SUSE bug 1196235</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009671505" comment="kernel-default-5.3.18-24.107.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009671506" comment="kernel-default-base-5.3.18-24.107.1.9.50.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202225636" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-25636</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-25636" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25636" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-25636" ref_url="https://www.suse.com/security/cve/CVE-2022-25636" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0984-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:0998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010550.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1034-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010564.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="TID000020615" ref_url="https://www.suse.com/support/kb/doc/?id=000020615" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-25636/">CVE-2022-25636</cve>
	<bugzilla href="https://bugzilla.suse.com/1196299">SUSE bug 1196299</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1196301">SUSE bug 1196301</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222585" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2585</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2585" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2585" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2585" ref_url="https://www.suse.com/security/cve/CVE-2022-2585" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011908.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3108-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012107.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012270.html" source="SUSE-SU"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-13"/>
	<updated date="2022-09-17"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-2585/">CVE-2022-2585</cve>
	<bugzilla href="https://bugzilla.suse.com/1202094">SUSE bug 1202094</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1202163">SUSE bug 1202163</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222586" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2586</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2586" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2586" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2586" ref_url="https://www.suse.com/security/cve/CVE-2022-2586" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-01"/>
	<updated date="2023-09-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-2586/">CVE-2022-2586</cve>
	<bugzilla href="https://bugzilla.suse.com/1202095">SUSE bug 1202095</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209719">SUSE bug 1209719</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222590" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2590</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2590" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2590" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2590" ref_url="https://www.suse.com/security/cve/CVE-2022-2590" source="SUSE CVE"/>
    <description>
    A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only shared memory mappings. This flaw allows an unprivileged, local user to gain write access to read-only memory mappings, increasing their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-15"/>
	<updated date="2022-09-01"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-2590/">CVE-2022-2590</cve>
	<bugzilla href="https://bugzilla.suse.com/1202013">SUSE bug 1202013</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1202089">SUSE bug 1202089</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222602" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2602</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2602" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2602" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2602" ref_url="https://www.suse.com/security/cve/CVE-2022-2602" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4616-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0229-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0237-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013623.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013626.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013628.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0281-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013638.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013714.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0339-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013718.html" source="SUSE-SU"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-10"/>
	<updated date="2023-03-18"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-2602/">CVE-2022-2602</cve>
	<bugzilla href="https://bugzilla.suse.com/1204228">SUSE bug 1204228</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205186">SUSE bug 1205186</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202226353" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-26353</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-26353" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26353" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-26353" ref_url="https://www.suse.com/security/cve/CVE-2022-26353" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:2260-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011391.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-26353/">CVE-2022-26353</cve>
	<bugzilla href="https://bugzilla.suse.com/1198711">SUSE bug 1198711</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333988" comment="qemu is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335414" comment="qemu-arm is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335214" comment="qemu-ipxe is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335244" comment="qemu-seabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335245" comment="qemu-sgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335217" comment="qemu-tools is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335218" comment="qemu-vgabios is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335246" comment="qemu-x86 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202226356" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-26356</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-26356" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26356" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-26356" ref_url="https://www.suse.com/security/cve/CVE-2022-26356" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010818.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011336.html" source="SUSE-SU"/>
    <description>
    Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed call to XEN_DMOP_track_dirty_vram can enable log dirty while another CPU is still in the process of tearing down the structures related to a previously enabled log dirty mode (XEN_DOMCTL_SHADOW_OP_OFF). This is due to lack of mutually exclusive locking between both operations and can lead to entries being added in already freed slots, resulting in a memory leak.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-26356/">CVE-2022-26356</cve>
	<bugzilla href="https://bugzilla.suse.com/1197423">SUSE bug 1197423</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680342" comment="xen-libs-4.13.4_08-150200.3.50.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202226357" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-26357</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-26357" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26357" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-26357" ref_url="https://www.suse.com/security/cve/CVE-2022-26357" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010818.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011336.html" source="SUSE-SU"/>
    <description>
    race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The cleaning up of the housekeeping structures has a race, allowing for VT-d domain IDs to be leaked and flushes to be bypassed.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-26357/">CVE-2022-26357</cve>
	<bugzilla href="https://bugzilla.suse.com/1197425">SUSE bug 1197425</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680342" comment="xen-libs-4.13.4_08-150200.3.50.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202226358" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-26358</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-26358" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26358" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-26358" ref_url="https://www.suse.com/security/cve/CVE-2022-26358" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010818.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011336.html" source="SUSE-SU"/>
    <description>
    IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions need to remain continuouly accessible by the device. This requirement has been violated. Subsequent DMA or interrupts from the device may have unpredictable behaviour, ranging from IOMMU faults to memory corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-26358/">CVE-2022-26358</cve>
	<bugzilla href="https://bugzilla.suse.com/1197426">SUSE bug 1197426</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680342" comment="xen-libs-4.13.4_08-150200.3.50.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202226359" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-26359</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-26359" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26359" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-26359" ref_url="https://www.suse.com/security/cve/CVE-2022-26359" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010818.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011336.html" source="SUSE-SU"/>
    <description>
    IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions need to remain continuouly accessible by the device. This requirement has been violated. Subsequent DMA or interrupts from the device may have unpredictable behaviour, ranging from IOMMU faults to memory corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-26359/">CVE-2022-26359</cve>
	<bugzilla href="https://bugzilla.suse.com/1197426">SUSE bug 1197426</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680342" comment="xen-libs-4.13.4_08-150200.3.50.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202226360" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-26360</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-26360" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26360" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-26360" ref_url="https://www.suse.com/security/cve/CVE-2022-26360" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010818.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011336.html" source="SUSE-SU"/>
    <description>
    IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions need to remain continuouly accessible by the device. This requirement has been violated. Subsequent DMA or interrupts from the device may have unpredictable behaviour, ranging from IOMMU faults to memory corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-26360/">CVE-2022-26360</cve>
	<bugzilla href="https://bugzilla.suse.com/1197426">SUSE bug 1197426</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680342" comment="xen-libs-4.13.4_08-150200.3.50.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202226361" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-26361</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-26361" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26361" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-26361" ref_url="https://www.suse.com/security/cve/CVE-2022-26361" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011494.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011493.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011495.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1285-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1300-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010792.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1359-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010818.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1375-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010821.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1408-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010836.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010916.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010918.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2065-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011276.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011336.html" source="SUSE-SU"/>
    <description>
    IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions need to remain continuouly accessible by the device. This requirement has been violated. Subsequent DMA or interrupts from the device may have unpredictable behaviour, ranging from IOMMU faults to memory corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-26361/">CVE-2022-26361</cve>
	<bugzilla href="https://bugzilla.suse.com/1197426">SUSE bug 1197426</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680342" comment="xen-libs-4.13.4_08-150200.3.50.1 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202226490" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-26490</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-26490" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26490" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-26490" ref_url="https://www.suse.com/security/cve/CVE-2022-26490" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010570.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2700-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2709-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-August/024351.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2726-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2745-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011889.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011888.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011893.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011897.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011898.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2854-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011950.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1037-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-05-19"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-26490/">CVE-2022-26490</cve>
	<bugzilla href="https://bugzilla.suse.com/1196830">SUSE bug 1196830</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201656">SUSE bug 1201656</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201969">SUSE bug 1201969</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1211495">SUSE bug 1211495</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202226878" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-26878</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-26878" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26878" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-26878" ref_url="https://www.suse.com/security/cve/CVE-2022-26878" source="SUSE CVE"/>
    <description>
    drivers/bluetooth/virtio_bt.c in the Linux kernel before 5.16.3 has a memory leak (socket buffers have memory allocated but not freed).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-29"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-26878/">CVE-2022-26878</cve>
	<bugzilla href="https://bugzilla.suse.com/1197035">SUSE bug 1197035</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202226966" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-26966</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-26966" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26966" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-26966" ref_url="https://www.suse.com/security/cve/CVE-2022-26966" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:479-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010679.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:480-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010680.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010681.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010768.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1283-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010777.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:1039-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XWMVMDEM47CT6AQ4RWZEZZJSH2G2J4CV/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-26966/">CVE-2022-26966</cve>
	<bugzilla href="https://bugzilla.suse.com/1196836">SUSE bug 1196836</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202227191" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-27191</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-27191" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27191" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-27191" ref_url="https://www.suse.com/security/cve/CVE-2022-27191" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:1845-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015150.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015151.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1143-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1144-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013284.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1145-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013286.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013289.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1507-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010921.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1689-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011935.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2839-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011941.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2839-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012032.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4409-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013215.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4463-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013228.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2183-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029370.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2185-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2187-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2579-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029950.html" source="SUSE-SU"/>
    <description>
    The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-06-22"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-27191/">CVE-2022-27191</cve>
	<bugzilla href="https://bugzilla.suse.com/1197284">SUSE bug 1197284</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009681381" comment="containerd-1.5.11-150000.68.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009681382" comment="docker-20.10.14_ce-150000.163.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202227223" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-27223</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-27223" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27223" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-27223" ref_url="https://www.suse.com/security/cve/CVE-2022-27223" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:1038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-March/010567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
    <description>
    In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-27223/">CVE-2022-27223</cve>
	<bugzilla href="https://bugzilla.suse.com/1197245">SUSE bug 1197245</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202227666" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-27666</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-27666" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27666" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-27666" ref_url="https://www.suse.com/security/cve/CVE-2022-27666" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1182-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1189-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010705.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1192-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010708.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1193-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1194-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010721.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1212-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010733.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1215-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1223-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010738.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1224-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1242-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1246-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1248-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1261-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010772.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010774.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1278-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010776.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1303-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010793.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
    <description>
    A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.7/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-27666/">CVE-2022-27666</cve>
	<bugzilla href="https://bugzilla.suse.com/1197131">SUSE bug 1197131</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197133">SUSE bug 1197133</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1197462">SUSE bug 1197462</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202227778" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-27778</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-27778" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27778" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-27778" ref_url="https://www.suse.com/security/cve/CVE-2022-27778" source="SUSE CVE"/>
    <description>
    A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2022-27778/">CVE-2022-27778</cve>
	<bugzilla href="https://bugzilla.suse.com/1199220">SUSE bug 1199220</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1202688">SUSE bug 1202688</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333977" comment="curl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335173" comment="libcurl4 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202227779" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-27779</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-27779" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27779" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-27779" ref_url="https://www.suse.com/security/cve/CVE-2022-27779" source="SUSE CVE"/>
    <description>
    libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://publicsuffix.org/)awareness. If PSL support not provided, a more rudimentary check exists to atleast prevent cookies from being set on TLDs. This check was broken if thehost name in the URL uses a trailing dot.This can allow arbitrary sites to set cookies that then would get sent to adifferent and unrelated site or domain.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2022-27779/">CVE-2022-27779</cve>
	<bugzilla href="https://bugzilla.suse.com/1199221">SUSE bug 1199221</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333977" comment="curl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335173" comment="libcurl4 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202227780" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-27780</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-27780" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27780" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-27780" ref_url="https://www.suse.com/security/cve/CVE-2022-27780" source="SUSE CVE"/>
    <description>
    The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe parser and get transposed into `http://example.com/127.0.0.1/`. This flawcan be used to circumvent filters, checks and more.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2022-27780/">CVE-2022-27780</cve>
	<bugzilla href="https://bugzilla.suse.com/1199222">SUSE bug 1199222</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333977" comment="curl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335173" comment="libcurl4 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222785" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2785</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2785" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2785" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2785" ref_url="https://www.suse.com/security/cve/CVE-2022-2785" source="SUSE CVE"/>
    <description>
    There exists an arbitrary memory read within the Linux Kernel BPF - Constants provided to fill pointers in structs passed in to bpf_sys_bpf are not verified and can point anywhere, including memory not owned by BPF. An attacker with CAP_BPF can arbitrarily read memory from anywhere on the system. We recommend upgrading past commit 86f44fcec22c
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-27"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-2785/">CVE-2022-2785</cve>
	<bugzilla href="https://bugzilla.suse.com/1203734">SUSE bug 1203734</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202227950" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-27950</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-27950" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27950" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-27950" ref_url="https://www.suse.com/security/cve/CVE-2022-27950" source="SUSE CVE"/>
    <description>
    In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-27950/">CVE-2022-27950</cve>
	<bugzilla href="https://bugzilla.suse.com/1197646">SUSE bug 1197646</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202228348" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-28348</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-28348" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28348" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-28348" ref_url="https://www.suse.com/security/cve/CVE-2022-28348" source="SUSE CVE"/>
    <description>
    Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper GPU memory operations to reach a use-after-free situation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-28348/">CVE-2022-28348</cve>
	<bugzilla href="https://bugzilla.suse.com/1199720">SUSE bug 1199720</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202228349" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-28349</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-28349" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28349" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-28349" ref_url="https://www.suse.com/security/cve/CVE-2022-28349" source="SUSE CVE"/>
    <description>
    Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p0 through r23p0 before r24p0.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-28349/">CVE-2022-28349</cve>
	<bugzilla href="https://bugzilla.suse.com/1199761">SUSE bug 1199761</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202228350" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-28350</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-28350" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28350" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-28350" ref_url="https://www.suse.com/security/cve/CVE-2022-28350" source="SUSE CVE"/>
    <description>
    Arm Mali GPU Kernel Driver allows improper GPU operations in Valhall r29p0 through r36p0 before r37p0 to reach a use-after-free situation.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-28350/">CVE-2022-28350</cve>
	<bugzilla href="https://bugzilla.suse.com/1199762">SUSE bug 1199762</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202228388" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-28388</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-28388" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28388" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-28388" ref_url="https://www.suse.com/security/cve/CVE-2022-28388" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011287.html" source="SUSE-SU"/>
    <description>
    usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" href="https://www.suse.com/security/cve/CVE-2022-28388/">CVE-2022-28388</cve>
	<bugzilla href="https://bugzilla.suse.com/1198032">SUSE bug 1198032</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202228389" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-28389</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-28389" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28389" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-28389" ref_url="https://www.suse.com/security/cve/CVE-2022-28389" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2700-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2709-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-August/024351.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2726-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2745-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011889.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011888.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011893.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011897.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011898.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2854-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011950.html" source="SUSE-SU"/>
    <description>
    mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-28389/">CVE-2022-28389</cve>
	<bugzilla href="https://bugzilla.suse.com/1198033">SUSE bug 1198033</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201657">SUSE bug 1201657</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202228390" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-28390</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-28390" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28390" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-28390" ref_url="https://www.suse.com/security/cve/CVE-2022-28390" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1163-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010687.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1183-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1196-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010723.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1197-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1255-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1256-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1266-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1267-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1402-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010835.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1407-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010837.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2077-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011285.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011287.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2699-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011825.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2700-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011826.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2709-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-August/024351.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2726-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2728-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011840.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2745-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011889.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011888.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2776-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011893.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011897.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011898.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2789-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011900.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2854-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011950.html" source="SUSE-SU"/>
    <description>
    ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-08"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-28390/">CVE-2022-28390</cve>
	<bugzilla href="https://bugzilla.suse.com/1198031">SUSE bug 1198031</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201517">SUSE bug 1201517</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1207969">SUSE bug 1207969</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009679192" comment="kernel-default-5.3.18-150200.24.112.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679193" comment="kernel-default-base-5.3.18-150200.24.112.1.150200.9.52.2 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222873" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2873</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2873" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2873" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2873" ref_url="https://www.suse.com/security/cve/CVE-2022-2873" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:2342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-20"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-2873/">CVE-2022-2873</cve>
	<bugzilla href="https://bugzilla.suse.com/1202558">SUSE bug 1202558</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202228738" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-28738</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-28738" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28738" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-28738" ref_url="https://www.suse.com/security/cve/CVE-2022-28738" source="SUSE CVE"/>
    <description>
    A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-01-14"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-28738/">CVE-2022-28738</cve>
	<bugzilla href="https://bugzilla.suse.com/1198440">SUSE bug 1198440</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009348236" comment="libruby2_5-2_5 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348228" comment="ruby2.5 is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009348239" comment="ruby2.5-stdlib is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202228739" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-28739</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-28739" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28739" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-28739" ref_url="https://www.suse.com/security/cve/CVE-2022-28739" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:1151-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:1360-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011327.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:862-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010926.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011014.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:633-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011015.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011013.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1512-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010920.html" source="SUSE-SU"/>
    <description>
    There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2022-28739/">CVE-2022-28739</cve>
	<bugzilla href="https://bugzilla.suse.com/1198441">SUSE bug 1198441</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009680329" comment="libruby2_5-2_5-2.5.9-150000.4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680330" comment="ruby2.5-2.5.9-150000.4.23.1 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009680333" comment="ruby2.5-stdlib-2.5.9-150000.4.23.1 is installed"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202228748" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-28748</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-28748" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28748" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-28748" ref_url="https://www.suse.com/security/cve/CVE-2022-28748" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:814-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011574.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:817-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011575.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:836-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011573.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1257-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-April/010746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1651-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/010994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1668-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011019.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1669-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1686-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011035.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011310.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4273-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-November/026621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4561-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013272.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4573-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013280.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4611-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013338.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2964. Reason: This candidate is a reservation duplicate of CVE-2022-2964. Notes: All CVE users should reference CVE-2022-2964 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.7/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-28748/">CVE-2022-28748</cve>
	<bugzilla href="https://bugzilla.suse.com/1196018">SUSE bug 1196018</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009679475" comment="kernel-rt-5.3.18-150200.79.2 is installed"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202228796" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-28796</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-28796" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28796" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-28796" ref_url="https://www.suse.com/security/cve/CVE-2022-28796" source="SUSE CVE"/>
    <description>
    jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2023-02-01"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-28796/">CVE-2022-28796</cve>
	<bugzilla href="https://bugzilla.suse.com/1198325">SUSE bug 1198325</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1198594">SUSE bug 1198594</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202228893" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-28893</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-28893" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28893" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-28893" ref_url="https://www.suse.com/security/cve/CVE-2022-28893" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:853-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011592.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011593.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:878-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011591.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1669-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011033.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011302.html" source="SUSE-SU"/>
    <description>
    The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-28893/">CVE-2022-28893</cve>
	<bugzilla href="https://bugzilla.suse.com/1198330">SUSE bug 1198330</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222905" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2905</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2905" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2905" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2905" ref_url="https://www.suse.com/security/cve/CVE-2022-2905" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:2342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-30"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-2905/">CVE-2022-2905</cve>
	<bugzilla href="https://bugzilla.suse.com/1202860">SUSE bug 1202860</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202229156" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-29156</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-29156" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29156" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-29156" ref_url="https://www.suse.com/security/cve/CVE-2022-29156" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:671-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:678-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:679-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1669-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011018.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1676-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:1687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-May/011033.html" source="SUSE-SU"/>
    <description>
    drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-29156/">CVE-2022-29156</cve>
	<bugzilla href="https://bugzilla.suse.com/1198515">SUSE bug 1198515</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222938" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2938</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2938" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2938" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2938" ref_url="https://www.suse.com/security/cve/CVE-2022-2938" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:2342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-24"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-2938/">CVE-2022-2938</cve>
	<bugzilla href="https://bugzilla.suse.com/1202623">SUSE bug 1202623</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202229582" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-29582</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-29582" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29582" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-29582" ref_url="https://www.suse.com/security/cve/CVE-2022-29582" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-29582/">CVE-2022-29582</cve>
	<bugzilla href="https://bugzilla.suse.com/1198811">SUSE bug 1198811</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1199750">SUSE bug 1199750</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222959" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2959</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2959" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2959" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2959" ref_url="https://www.suse.com/security/cve/CVE-2022-2959" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:2342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. This flaw allows a local user to crash the system or escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-25"/>
	<updated date="2022-12-24"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-2959/">CVE-2022-2959</cve>
	<bugzilla href="https://bugzilla.suse.com/1202681">SUSE bug 1202681</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1202685">SUSE bug 1202685</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222961" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2961</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2961" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2961" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2961" ref_url="https://www.suse.com/security/cve/CVE-2022-2961" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-08"/>
	<updated date="2023-03-08"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2022-2961/">CVE-2022-2961</cve>
	<bugzilla href="https://bugzilla.suse.com/1202660">SUSE bug 1202660</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20222978" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-2978</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-2978" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2978" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-2978" ref_url="https://www.suse.com/security/cve/CVE-2022-2978" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-22"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-2978/">CVE-2022-2978</cve>
	<bugzilla href="https://bugzilla.suse.com/1202700">SUSE bug 1202700</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204745">SUSE bug 1204745</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202229968" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-29968</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-29968" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29968" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-29968" ref_url="https://www.suse.com/security/cve/CVE-2022-29968" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb-&gt;private.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-10-08"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-29968/">CVE-2022-29968</cve>
	<bugzilla href="https://bugzilla.suse.com/1199087">SUSE bug 1199087</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202230115" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-30115</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-30115" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30115" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-30115" ref_url="https://www.suse.com/security/cve/CVE-2022-30115" source="SUSE CVE"/>
    <description>
    Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-12-13"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-30115/">CVE-2022-30115</cve>
	<bugzilla href="https://bugzilla.suse.com/1199225">SUSE bug 1199225</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204386">SUSE bug 1204386</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1206308">SUSE bug 1206308</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333977" comment="curl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335173" comment="libcurl4 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223061" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3061</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3061" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3061" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3061" ref_url="https://www.suse.com/security/cve/CVE-2022-3061" source="SUSE CVE"/>
    <description>
    Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() interface. The driver doesn't check the value of 'pixclock', so it may cause a divide by zero error.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-28"/>
	<updated date="2022-09-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3061/">CVE-2022-3061</cve>
	<bugzilla href="https://bugzilla.suse.com/1202913">SUSE bug 1202913</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223077" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3077</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3077" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3077" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3077" ref_url="https://www.suse.com/security/cve/CVE-2022-3077" source="SUSE CVE"/>
    <description>
    A buffer overflow vulnerability was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it handled the I2C_SMBUS_BLOCK_PROC_CALL case (via the ioctl I2C_SMBUS) with malicious input data. This flaw could allow a local user to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-02"/>
	<updated date="2022-09-10"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" href="https://www.suse.com/security/cve/CVE-2022-3077/">CVE-2022-3077</cve>
	<bugzilla href="https://bugzilla.suse.com/1203040">SUSE bug 1203040</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223078" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3078</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3078" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3078" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3078" ref_url="https://www.suse.com/security/cve/CVE-2022-3078" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:2342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.16-rc6. There is a lack of check after calling vzalloc() and lack of free after allocation in drivers/media/test-drivers/vidtv/vidtv_s302m.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-02"/>
	<updated date="2022-12-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-3078/">CVE-2022-3078</cve>
	<bugzilla href="https://bugzilla.suse.com/1203041">SUSE bug 1203041</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223103" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3103</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3103" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3103" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3103" ref_url="https://www.suse.com/security/cve/CVE-2022-3103" source="SUSE CVE"/>
    <description>
    off-by-one in io_uring module.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-29"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3103/">CVE-2022-3103</cve>
	<bugzilla href="https://bugzilla.suse.com/1203801">SUSE bug 1203801</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223104" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3104</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3104" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3104" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3104" ref_url="https://www.suse.com/security/cve/CVE-2022-3104" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013529.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.16-rc6. lkdtm_ARRAY_BOUNDS in drivers/misc/lkdtm/bugs.c lacks check of the return value of kmalloc() and will cause the null pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3104/">CVE-2022-3104</cve>
	<bugzilla href="https://bugzilla.suse.com/1206396">SUSE bug 1206396</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223105" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3105</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3105" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3105" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3105" ref_url="https://www.suse.com/security/cve/CVE-2022-3105" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013757.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.16-rc6. uapi_finalize in drivers/infiniband/core/uverbs_uapi.c lacks check of kmalloc_array().
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-15"/>
	<updated date="2023-03-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3105/">CVE-2022-3105</cve>
	<bugzilla href="https://bugzilla.suse.com/1206398">SUSE bug 1206398</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223106" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3106</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3106" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3106" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3106" ref_url="https://www.suse.com/security/cve/CVE-2022-3106" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013530.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.16-rc6. ef100_update_stats in drivers/net/ethernet/sfc/ef100_nic.c lacks check of the return value of kmalloc().
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-15"/>
	<updated date="2023-03-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3106/">CVE-2022-3106</cve>
	<bugzilla href="https://bugzilla.suse.com/1206397">SUSE bug 1206397</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223111" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3111</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3111" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3111" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3111" ref_url="https://www.suse.com/security/cve/CVE-2022-3111" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013530.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.16-rc6. free_charger_irq() in drivers/power/supply/wm8350_power.c lacks free of WM8350_IRQ_CHG_FAST_RDY, which is registered in wm8350_init_charger().
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-27"/>
	<updated date="2023-09-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3111/">CVE-2022-3111</cve>
	<bugzilla href="https://bugzilla.suse.com/1206394">SUSE bug 1206394</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223112" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3112</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3112" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3112" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3112" ref_url="https://www.suse.com/security/cve/CVE-2022-3112" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013959.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.16-rc6. amvdec_set_canvases in drivers/staging/media/meson/vdec/vdec_helpers.c lacks check of the return value of kzalloc() and will cause the null pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-15"/>
	<updated date="2023-03-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3112/">CVE-2022-3112</cve>
	<bugzilla href="https://bugzilla.suse.com/1206399">SUSE bug 1206399</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223113" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3113</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3113" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3113" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3113" ref_url="https://www.suse.com/security/cve/CVE-2022-3113" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013529.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3113/">CVE-2022-3113</cve>
	<bugzilla href="https://bugzilla.suse.com/1206390">SUSE bug 1206390</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223114" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3114</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3114" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3114" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3114" ref_url="https://www.suse.com/security/cve/CVE-2022-3114" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013529.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.16-rc6. imx_register_uart_clocks in drivers/clk/imx/clk.c lacks check of the return value of kcalloc() and will cause the null pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-15"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3114/">CVE-2022-3114</cve>
	<bugzilla href="https://bugzilla.suse.com/1206391">SUSE bug 1206391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223115" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3115</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3115" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3115" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3115" ref_url="https://www.suse.com/security/cve/CVE-2022-3115" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013959.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.16-rc6. malidp_crtc_reset in drivers/gpu/drm/arm/malidp_crtc.c lacks check of the return value of kzalloc() and will cause the null pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-04"/>
	<updated date="2023-03-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3115/">CVE-2022-3115</cve>
	<bugzilla href="https://bugzilla.suse.com/1206393">SUSE bug 1206393</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223170" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3170</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3170" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3170" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3170" ref_url="https://www.suse.com/security/cve/CVE-2022-3170" source="SUSE CVE"/>
    <description>
    An out-of-bounds access issue was found in the Linux kernel sound subsystem. It could occur when the 'id-&gt;name' provided by the user did not end with '\0'. A privileged local user could pass a specially crafted name through ioctl() interface and crash the system or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-13"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3170/">CVE-2022-3170</cve>
	<bugzilla href="https://bugzilla.suse.com/1203321">SUSE bug 1203321</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223176" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3176</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3176" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3176" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3176" ref_url="https://www.suse.com/security/cve/CVE-2022-3176" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_uring poll doesn't handle POLLFREE. This allows a use-after-free to occur if a signalfd or binder fd is polled with io_uring poll, and the waitqueue gets freed. We recommend upgrading past commit fc78b2fc21f10c4c9c4d5d659a685710ffa63659
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-01"/>
	<updated date="2023-07-01"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3176/">CVE-2022-3176</cve>
	<bugzilla href="https://bugzilla.suse.com/1203391">SUSE bug 1203391</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1203511">SUSE bug 1203511</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223202" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3202</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3202" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3202" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3202" ref_url="https://www.suse.com/security/cve/CVE-2022-3202" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-15"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3202/">CVE-2022-3202</cve>
	<bugzilla href="https://bugzilla.suse.com/1203389">SUSE bug 1203389</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202232250" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-32250</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-32250" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32250" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-32250" ref_url="https://www.suse.com/security/cve/CVE-2022-32250" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:2342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011346.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2177-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011353.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2214-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011372.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2216-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-June/011374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2230-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2239-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011376.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2245-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011382.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2262-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011390.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2268-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011401.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2722-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011834.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011866.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2875-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011976.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2875-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012052.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:2177-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/S2QMD6CJ6PZDFYQ3RKSOGAZNRK7WC5W7/" source="SUSE-SU"/>
    <description>
    net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-21"/>
	<updated date="2023-01-21"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-32250/">CVE-2022-32250</cve>
	<bugzilla href="https://bugzilla.suse.com/1200015">SUSE bug 1200015</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200268">SUSE bug 1200268</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1200494">SUSE bug 1200494</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1202992">SUSE bug 1202992</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1202993">SUSE bug 1202993</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1203002">SUSE bug 1203002</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223238" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3238</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3238" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3238" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3238" ref_url="https://www.suse.com/security/cve/CVE-2022-3238" source="SUSE CVE"/>
    <description>
    A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-16"/>
	<updated date="2022-11-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3238/">CVE-2022-3238</cve>
	<bugzilla href="https://bugzilla.suse.com/1204655">SUSE bug 1204655</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202232981" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-32981</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-32981" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32981" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-32981" ref_url="https://www.suse.com/security/cve/CVE-2022-32981" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-32981/">CVE-2022-32981</cve>
	<bugzilla href="https://bugzilla.suse.com/1200470">SUSE bug 1200470</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223344" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3344</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3344" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3344" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3344" ref_url="https://www.suse.com/security/cve/CVE-2022-3344" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013529.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept the shutdown of a cooperative nested guest (L2), possibly leading to a page fault and kernel panic in the host (L0).
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-25"/>
	<updated date="2023-02-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3344/">CVE-2022-3344</cve>
	<bugzilla href="https://bugzilla.suse.com/1204652">SUSE bug 1204652</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223435" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3435</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3435" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3435" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3435" ref_url="https://www.suse.com/security/cve/CVE-2022-3435" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013523.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013757.html" source="SUSE-SU"/>
    <description>
    A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-210357 was assigned to this vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-12"/>
	<updated date="2023-03-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3435/">CVE-2022-3435</cve>
	<bugzilla href="https://bugzilla.suse.com/1204171">SUSE bug 1204171</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202234494" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-34494</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-34494" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-34494" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-34494" ref_url="https://www.suse.com/security/cve/CVE-2022-34494" source="SUSE CVE"/>
    <description>
    rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-34494/">CVE-2022-34494</cve>
	<bugzilla href="https://bugzilla.suse.com/1201158">SUSE bug 1201158</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202234495" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-34495</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-34495" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-34495" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-34495" ref_url="https://www.suse.com/security/cve/CVE-2022-34495" source="SUSE CVE"/>
    <description>
    rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-34495/">CVE-2022-34495</cve>
	<bugzilla href="https://bugzilla.suse.com/1201159">SUSE bug 1201159</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202234918" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-34918</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-34918" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-34918" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-34918" ref_url="https://www.suse.com/security/cve/CVE-2022-34918" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1047-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1048-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1049-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011957.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1061-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011978.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1062-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011979.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1067-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011986.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:894-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011604.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:903-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011605.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:904-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011519.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2422-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011579.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2424-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2424-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2520-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-July/011657.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2615-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011728.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2696-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011823.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2726-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011843.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2727-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011841.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2738-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011865.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2759-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011885.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011888.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011892.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:2854-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-August/011950.html" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:2422-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/UCV6OZAODHO3XSCOPNA6KBP5EOWSRH4L/" source="SUSE-SU"/>
		<reference ref_id="openSUSE-SU-2022:2549-1" ref_url="https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YODNNJY6VGTGGVMUQLFLWV5FFYHIFW3C/" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-07"/>
	<updated date="2022-09-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-34918/">CVE-2022-34918</cve>
	<bugzilla href="https://bugzilla.suse.com/1201171">SUSE bug 1201171</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201177">SUSE bug 1201177</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1201222">SUSE bug 1201222</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223526" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3526</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3526" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3526" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3526" ref_url="https://www.suse.com/security/cve/CVE-2022-3526" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A vulnerability classified as problematic was found in Linux Kernel. This vulnerability affects the function macvlan_handle_frame of the file drivers/net/macvlan.c of the component skb. The manipulation leads to memory leak. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211024.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-18"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3526/">CVE-2022-3526</cve>
	<bugzilla href="https://bugzilla.suse.com/1204353">SUSE bug 1204353</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223531" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3531</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3531" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3531" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3531" ref_url="https://www.suse.com/security/cve/CVE-2022-3531" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-19"/>
	<updated date="2022-12-18"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="0/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-3531/">CVE-2022-3531</cve>
	<bugzilla href="https://bugzilla.suse.com/1204420">SUSE bug 1204420</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223532" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3532</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3532" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3532" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3532" ref_url="https://www.suse.com/security/cve/CVE-2022-3532" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-19"/>
	<updated date="2022-12-18"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="0/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-3532/">CVE-2022-3532</cve>
	<bugzilla href="https://bugzilla.suse.com/1204418">SUSE bug 1204418</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223533" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3533</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3533" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3533" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3533" ref_url="https://www.suse.com/security/cve/CVE-2022-3533" source="SUSE CVE"/>
    <description>
    A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects the function parse_usdt_arg of the file tools/lib/bpf/usdt.c of the component BPF. The manipulation of the argument reg_name leads to memory leak. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211031.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-18"/>
	<updated date="2022-10-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3533/">CVE-2022-3533</cve>
	<bugzilla href="https://bugzilla.suse.com/1204393">SUSE bug 1204393</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223534" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3534</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3534" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3534" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3534" ref_url="https://www.suse.com/security/cve/CVE-2022-3534" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2023:0405-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013756.html" source="SUSE-SU"/>
    <description>
    A vulnerability classified as critical has been found in Linux Kernel. Affected is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211032.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-18"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3534/">CVE-2022-3534</cve>
	<bugzilla href="https://bugzilla.suse.com/1204391">SUSE bug 1204391</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223535" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3535</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3535" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3535" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3535" ref_url="https://www.suse.com/security/cve/CVE-2022-3535" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-19"/>
	<updated date="2022-12-24"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.3/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-3535/">CVE-2022-3535</cve>
	<bugzilla href="https://bugzilla.suse.com/1204417">SUSE bug 1204417</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223541" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3541</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3541" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3541" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3541" ref_url="https://www.suse.com/security/cve/CVE-2022-3541" source="SUSE CVE"/>
    <description>
    A vulnerability classified as critical has been found in Linux Kernel. This affects the function spl2sw_nvmem_get_mac_address of the file drivers/net/ethernet/sunplus/spl2sw_driver.c of the component BPF. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211041 was assigned to this vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-19"/>
	<updated date="2023-01-14"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3541/">CVE-2022-3541</cve>
	<bugzilla href="https://bugzilla.suse.com/1204403">SUSE bug 1204403</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223543" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3543</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3543" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3543" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3543" ref_url="https://www.suse.com/security/cve/CVE-2022-3543" source="SUSE CVE"/>
    <description>
    A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function unix_sock_destructor/unix_release_sock of the file net/unix/af_unix.c of the component BPF. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211043.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-19"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3543/">CVE-2022-3543</cve>
	<bugzilla href="https://bugzilla.suse.com/1204401">SUSE bug 1204401</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223544" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3544</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3544" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3544" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3544" ref_url="https://www.suse.com/security/cve/CVE-2022-3544" source="SUSE CVE"/>
    <description>
    A vulnerability, which was classified as problematic, was found in Linux Kernel. Affected is the function damon_sysfs_add_target of the file mm/damon/sysfs.c of the component Netfilter. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211044.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-19"/>
	<updated date="2022-10-19"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3544/">CVE-2022-3544</cve>
	<bugzilla href="https://bugzilla.suse.com/1204404">SUSE bug 1204404</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223577" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3577</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3577" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3577" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3577" ref_url="https://www.suse.com/security/cve/CVE-2022-3577" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4515-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013265.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4562-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4569-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-December/026938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013291.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    An out-of-bounds memory write flaw was found in the Linux kernel’s Kid-friendly Wired Controller driver. This flaw allows a local user to crash or potentially escalate their privileges on the system. It is in bigben_probe of drivers/hid/hid-bigbenff.c. The reason is incorrect assumption - bigben devices all have inputs. However, malicious devices can break this assumption, leaking to out-of-bound write.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-20"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3577/">CVE-2022-3577</cve>
	<bugzilla href="https://bugzilla.suse.com/1204470">SUSE bug 1204470</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204486">SUSE bug 1204486</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223595" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3595</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3595" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3595" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3595" ref_url="https://www.suse.com/security/cve/CVE-2022-3595" source="SUSE CVE"/>
    <description>
    A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue is the function sess_free_buffer of the file fs/cifs/sess.c of the component CIFS Handler. The manipulation leads to double free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211364.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-20"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3595/">CVE-2022-3595</cve>
	<bugzilla href="https://bugzilla.suse.com/1204476">SUSE bug 1204476</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223606" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3606</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3606" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3606" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3606" ref_url="https://www.suse.com/security/cve/CVE-2022-3606" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0405-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0409-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013761.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014076.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. It is recommended to apply a patch to fix this issue. The identifier VDB-211749 was assigned to this vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-20"/>
	<updated date="2023-03-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3606/">CVE-2022-3606</cve>
	<bugzilla href="https://bugzilla.suse.com/1204502">SUSE bug 1204502</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202236123" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-36123</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-36123" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36123" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-36123" ref_url="https://www.suse.com/security/cve/CVE-2022-36123" source="SUSE CVE"/>
    <description>
    The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-08-13"/>
	<updated date="2022-08-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-36123/">CVE-2022-36123</cve>
	<bugzilla href="https://bugzilla.suse.com/1202010">SUSE bug 1202010</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1202583">SUSE bug 1202583</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223619" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3619</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3619" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3619" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3619" ref_url="https://www.suse.com/security/cve/CVE-2022-3619" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. VDB-211918 is the identifier assigned to this vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-21"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3619/">CVE-2022-3619</cve>
	<bugzilla href="https://bugzilla.suse.com/1204569">SUSE bug 1204569</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223623" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3623</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3623" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3623" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3623" ref_url="https://www.suse.com/security/cve/CVE-2022-3623" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function follow_page_pte of the file mm/gup.c of the component BPF. The manipulation leads to race condition. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211921 was assigned to this vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-21"/>
	<updated date="2022-11-09"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3623/">CVE-2022-3623</cve>
	<bugzilla href="https://bugzilla.suse.com/1204575">SUSE bug 1204575</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223624" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3624</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3624" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3624" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3624" ref_url="https://www.suse.com/security/cve/CVE-2022-3624" source="SUSE CVE"/>
    <description>
    A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211928.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-25"/>
	<updated date="2023-01-14"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-3624/">CVE-2022-3624</cve>
	<bugzilla href="https://bugzilla.suse.com/1204639">SUSE bug 1204639</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223625" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3625</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3625" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3625" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3625" ref_url="https://www.suse.com/security/cve/CVE-2022-3625" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in Linux Kernel. It has been classified as critical. This affects the function devlink_param_set/devlink_param_get of the file net/core/devlink.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211929 was assigned to this vulnerability.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-24"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3625/">CVE-2022-3625</cve>
	<bugzilla href="https://bugzilla.suse.com/1204637">SUSE bug 1204637</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223630" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3630</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3630" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3630" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3630" ref_url="https://www.suse.com/security/cve/CVE-2022-3630" source="SUSE CVE"/>
    <description>
    A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects some unknown processing of the file fs/fscache/cookie.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211931.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-24"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3630/">CVE-2022-3630</cve>
	<bugzilla href="https://bugzilla.suse.com/1204634">SUSE bug 1204634</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223633" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3633</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3633" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3633" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3633" ref_url="https://www.suse.com/security/cve/CVE-2022-3633" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211932.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-25"/>
	<updated date="2023-01-04"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-3633/">CVE-2022-3633</cve>
	<bugzilla href="https://bugzilla.suse.com/1204650">SUSE bug 1204650</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223636" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3636</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3636" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3636" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3636" ref_url="https://www.suse.com/security/cve/CVE-2022-3636" source="SUSE CVE"/>
    <description>
    A vulnerability, which was classified as critical, was found in Linux Kernel. This affects the function __mtk_ppe_check_skb of the file drivers/net/ethernet/mediatek/mtk_ppe.c of the component Ethernet Handler. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211935.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-24"/>
	<updated date="2022-10-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3636/">CVE-2022-3636</cve>
	<bugzilla href="https://bugzilla.suse.com/1204638">SUSE bug 1204638</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223640" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3640</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3640" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3640" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3640" ref_url="https://www.suse.com/security/cve/CVE-2022-3640" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4517-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4560-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-December/026940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211944.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-24"/>
	<updated date="2023-03-30"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3640/">CVE-2022-3640</cve>
	<bugzilla href="https://bugzilla.suse.com/1204619">SUSE bug 1204619</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204624">SUSE bug 1204624</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209225">SUSE bug 1209225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223642" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3642</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3642" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3642" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3642" ref_url="https://www.suse.com/security/cve/CVE-2022-3642" source="SUSE CVE"/>
    <description>
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-27"/>
	<updated date="2022-11-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-3642/">CVE-2022-3642</cve>
	<bugzilla href="https://bugzilla.suse.com/1204626">SUSE bug 1204626</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223707" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3707</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3707" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3707" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3707" ref_url="https://www.suse.com/security/cve/CVE-2022-3707" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4616-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-29"/>
	<updated date="2023-03-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-3707/">CVE-2022-3707</cve>
	<bugzilla href="https://bugzilla.suse.com/1204780">SUSE bug 1204780</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223910" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3910</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3910" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3910" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3910" ref_url="https://www.suse.com/security/cve/CVE-2022-3910" source="SUSE CVE"/>
    <description>
    Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which improperly decreased its reference count (leading to Use-After-Free and Local Privilege Escalation). Fixed files are permanently registered to the ring, and should not be put separately. We recommend upgrading past commit https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679 https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-24"/>
	<updated date="2022-11-24"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3910/">CVE-2022-3910</cve>
	<bugzilla href="https://bugzilla.suse.com/1205670">SUSE bug 1205670</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202239189" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-39189</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-39189" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39189" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-39189" ref_url="https://www.suse.com/security/cve/CVE-2022-39189" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012547.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3657-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012867.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4038-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012955.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4053-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012967.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-03"/>
	<updated date="2023-03-30"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-39189/">CVE-2022-39189</cve>
	<bugzilla href="https://bugzilla.suse.com/1203066">SUSE bug 1203066</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1203067">SUSE bug 1203067</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209225">SUSE bug 1209225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202239190" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-39190</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-39190" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39190" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-39190" ref_url="https://www.suse.com/security/cve/CVE-2022-39190" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:2342-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012298.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1082-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012299.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1084-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1110-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012587.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1118-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012606.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3264-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012229.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3288-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3293-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-September/012273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occur upon binding to an already bound chain.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-06"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-39190/">CVE-2022-39190</cve>
	<bugzilla href="https://bugzilla.suse.com/1203117">SUSE bug 1203117</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20223977" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-3977</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-3977" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3977" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-3977" ref_url="https://www.suse.com/security/cve/CVE-2022-3977" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This issue occurs when a user simultaneously calls DROPTAG ioctl and socket close happens, which could allow a local user to crash the system or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-12"/>
	<updated date="2023-01-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-3977/">CVE-2022-3977</cve>
	<bugzilla href="https://bugzilla.suse.com/1207048">SUSE bug 1207048</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202239842" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-39842</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-39842" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39842" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-39842" ref_url="https://www.suse.com/security/cve/CVE-2022-39842" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copy_from_user(), a heap overflow may occur. NOTE: the original discoverer disputes that the overflow can actually happen.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-06"/>
	<updated date="2022-12-20"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-39842/">CVE-2022-39842</cve>
	<bugzilla href="https://bugzilla.suse.com/1203124">SUSE bug 1203124</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202240476" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-40476</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-40476" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40476" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-40476" ref_url="https://www.suse.com/security/cve/CVE-2022-40476" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012989.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-16"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-40476/">CVE-2022-40476</cve>
	<bugzilla href="https://bugzilla.suse.com/1203435">SUSE bug 1203435</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202240540" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-40540</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-40540" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40540" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-40540" ref_url="https://www.suse.com/security/cve/CVE-2022-40540" source="SUSE CVE"/>
    <description>
    Memory corruption due to buffer copy without checking the size of input while loading firmware in Linux Kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-24"/>
	<updated date="2023-03-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-40540/">CVE-2022-40540</cve>
	<bugzilla href="https://bugzilla.suse.com/1209597">SUSE bug 1209597</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202241222" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-41222</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-41222" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41222" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-41222" ref_url="https://www.suse.com/security/cve/CVE-2022-41222" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3657-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
    <description>
    mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-09-22"/>
	<updated date="2023-03-30"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-41222/">CVE-2022-41222</cve>
	<bugzilla href="https://bugzilla.suse.com/1203622">SUSE bug 1203622</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1203624">SUSE bug 1203624</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209225">SUSE bug 1209225</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209476">SUSE bug 1209476</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20224127" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-4127</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-4127" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4127" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-4127" ref_url="https://www.suse.com/security/cve/CVE-2022-4127" source="SUSE CVE"/>
    <description>
    A NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user could use this flaw to potentially crash the system causing a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-25"/>
	<updated date="2022-11-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-4127/">CVE-2022-4127</cve>
	<bugzilla href="https://bugzilla.suse.com/1205703">SUSE bug 1205703</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20224128" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-4128</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-4128" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4128" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-4128" ref_url="https://www.suse.com/security/cve/CVE-2022-4128" source="SUSE CVE"/>
    <description>
    A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow list at disconnect time. A local user could use this flaw to potentially crash the system causing a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-25"/>
	<updated date="2022-11-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-4128/">CVE-2022-4128</cve>
	<bugzilla href="https://bugzilla.suse.com/1205704">SUSE bug 1205704</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20224139" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-4139</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-4139" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4139" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-4139" ref_url="https://www.suse.com/security/cve/CVE-2022-4139" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4503-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013251.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4513-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013255.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4515-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013259.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4516-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013258.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4517-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013256.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4518-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013257.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4528-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013264.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4534-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013265.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4542-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013266.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4543-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013268.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4544-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4551-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4559-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013274.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4560-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-December/026940.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4562-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013278.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4569-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-December/026938.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4572-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013281.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4580-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013291.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4587-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013292.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4589-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013294.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4613-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013340.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4614-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013337.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4616-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013339.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-17"/>
	<updated date="2023-03-30"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-4139/">CVE-2022-4139</cve>
	<bugzilla href="https://bugzilla.suse.com/1205700">SUSE bug 1205700</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1205815">SUSE bug 1205815</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209225">SUSE bug 1209225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202241674" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-41674</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-41674" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41674" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-41674" ref_url="https://www.suse.com/security/cve/CVE-2022-41674" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012547.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3657-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-18"/>
	<updated date="2023-03-30"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-41674/">CVE-2022-41674</cve>
	<bugzilla href="https://bugzilla.suse.com/1203770">SUSE bug 1203770</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1203994">SUSE bug 1203994</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209225">SUSE bug 1209225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202241849" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-41849</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-41849" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41849" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-41849" ref_url="https://www.suse.com/security/cve/CVE-2022-41849" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012536.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012557.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-05"/>
	<updated date="2022-12-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.3/CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-41849/">CVE-2022-41849</cve>
	<bugzilla href="https://bugzilla.suse.com/1203992">SUSE bug 1203992</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202242432" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-42432</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-42432" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42432" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-42432" ref_url="https://www.suse.com/security/cve/CVE-2022-42432" source="SUSE CVE"/>
    <description>
    This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel 6.0-rc2. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the nft_osf_eval function. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the kernel. Was ZDI-CAN-18540.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-24"/>
	<updated date="2023-03-30"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-42432/">CVE-2022-42432</cve>
	<bugzilla href="https://bugzilla.suse.com/1204614">SUSE bug 1204614</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20224269" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-4269</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-4269" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4269" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-4269" ref_url="https://www.suse.com/security/cve/CVE-2022-4269" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:476-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2500-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2502-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2611-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2651-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2653-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2782-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a local unprivileged user could trigger a CPU soft lockup (ABBA deadlock) when the transport protocol in use (TCP or SCTP) does a retransmission, resulting in a denial of service condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-01"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-4269/">CVE-2022-4269</cve>
	<bugzilla href="https://bugzilla.suse.com/1206024">SUSE bug 1206024</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202242719" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-42719</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-42719" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42719" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-42719" ref_url="https://www.suse.com/security/cve/CVE-2022-42719" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012547.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3657-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-18"/>
	<updated date="2023-03-30"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-42719/">CVE-2022-42719</cve>
	<bugzilla href="https://bugzilla.suse.com/1204051">SUSE bug 1204051</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204292">SUSE bug 1204292</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209225">SUSE bug 1209225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202242720" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-42720</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-42720" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42720" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-42720" ref_url="https://www.suse.com/security/cve/CVE-2022-42720" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012547.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3657-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-18"/>
	<updated date="2023-03-30"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-42720/">CVE-2022-42720</cve>
	<bugzilla href="https://bugzilla.suse.com/1204059">SUSE bug 1204059</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204291">SUSE bug 1204291</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209225">SUSE bug 1209225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202242721" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-42721</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-42721" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42721" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-42721" ref_url="https://www.suse.com/security/cve/CVE-2022-42721" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3601-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012547.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3606-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012556.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3657-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012577.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3704-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012636.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-18"/>
	<updated date="2023-03-30"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-42721/">CVE-2022-42721</cve>
	<bugzilla href="https://bugzilla.suse.com/1204060">SUSE bug 1204060</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204290">SUSE bug 1204290</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209225">SUSE bug 1209225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202242722" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-42722</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-42722" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42722" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-42722" ref_url="https://www.suse.com/security/cve/CVE-2022-42722" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1130-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013038.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1133-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013054.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1134-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013055.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3775-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012797.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3897-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012838.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3976-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012915.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3998-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4033-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012953.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4034-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012952.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012954.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4037-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012956.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4039-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012951.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4100-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012994.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4113-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013000.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-24"/>
	<updated date="2023-03-30"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-42722/">CVE-2022-42722</cve>
	<bugzilla href="https://bugzilla.suse.com/1204125">SUSE bug 1204125</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1204289">SUSE bug 1204289</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209225">SUSE bug 1209225</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202242916" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-42916</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-42916" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42916" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-42916" ref_url="https://www.suse.com/security/cve/CVE-2022-42916" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:2745-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2746-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2747-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012742.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2750-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012744.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2751-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012745.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2752-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2753-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2754-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012748.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2755-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012749.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2756-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012750.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2757-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012751.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2760-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2761-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012755.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2762-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012756.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2763-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012758.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2764-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012759.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2765-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012760.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2766-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012761.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2767-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012762.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012763.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2769-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012764.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2770-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012765.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2771-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012766.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012767.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2792-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2794-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-November/025905.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2955-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012894.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:2959-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/012896.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3269-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3374-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013232.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3378-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013234.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3380-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013235.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1229-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014549.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1124-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013024.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1131-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013039.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1132-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-November/013040.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2022:1148-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013288.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:3785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-October/012718.html" source="SUSE-SU"/>
    <description>
    In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion, e.g., using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-10-27"/>
	<updated date="2023-04-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-42916/">CVE-2022-42916</cve>
	<bugzilla href="https://bugzilla.suse.com/1204386">SUSE bug 1204386</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1206308">SUSE bug 1206308</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333977" comment="curl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335173" comment="libcurl4 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202243551" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-43551</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-43551" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43551" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-43551" ref_url="https://www.suse.com/security/cve/CVE-2022-43551" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2022:3426-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3427-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013307.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3428-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013308.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3429-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013309.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3430-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013310.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3431-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013311.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3432-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013312.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013313.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3434-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013314.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3435-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013315.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3436-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3437-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013317.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3438-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-December/027005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3439-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2022-December/027006.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3440-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013320.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3441-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013321.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3442-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013322.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3444-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3445-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3448-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013328.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3449-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013330.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3450-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013331.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3451-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013332.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3452-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013333.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3453-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013334.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3454-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013335.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2022:3455-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013336.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1103-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014450.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014451.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1105-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014452.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1229-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014549.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1231-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014551.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1234-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014552.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:1236-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014553.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:321-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013694.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:322-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013693.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:323-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013695.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:324-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013692.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:330-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:332-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:334-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013735.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:336-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-CU-2023:338-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013737.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4597-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013302.html" source="SUSE-SU"/>
    <description>
    A vulnerability exists in curl &lt;7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, the HSTS mechanism could be bypassed if the host name in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Like using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop (U+002E) `.`. Then in a subsequent request, it does not detect the HSTS state and makes a clear text transfer. Because it would store the info IDN encoded but look for it IDN decoded.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-22"/>
	<updated date="2023-04-23"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-43551/">CVE-2022-43551</cve>
	<bugzilla href="https://bugzilla.suse.com/1206308">SUSE bug 1206308</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009333977" comment="curl is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009335173" comment="libcurl4 is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20224379" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-4379</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-4379" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4379" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-4379" ref_url="https://www.suse.com/security/cve/CVE-2022-4379" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0270-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013634.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0273-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013630.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0277-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013637.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0280-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013639.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0320-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0331-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013714.html" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-23"/>
	<updated date="2023-02-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-4379/">CVE-2022-4379</cve>
	<bugzilla href="https://bugzilla.suse.com/1206209">SUSE bug 1206209</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1206373">SUSE bug 1206373</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20224382" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-4382</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-4382" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4382" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-4382" ref_url="https://www.suse.com/security/cve/CVE-2022-4382" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:154-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:155-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013801.html" source="SUSE-SU"/>
    <description>
    A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found. It could be triggered by yanking out a device that is running the gadgetfs side.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-15"/>
	<updated date="2023-03-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-4382/">CVE-2022-4382</cve>
	<bugzilla href="https://bugzilla.suse.com/1206258">SUSE bug 1206258</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1206363">SUSE bug 1206363</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202244032" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-44032</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-44032" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-44032" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-44032" ref_url="https://www.suse.com/security/cve/CVE-2022-44032" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2023:0416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013765.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4000_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between cmm_open() and cm4000_detach().
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-01"/>
	<updated date="2023-06-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-44032/">CVE-2022-44032</cve>
	<bugzilla href="https://bugzilla.suse.com/1204894">SUSE bug 1204894</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1212290">SUSE bug 1212290</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202244033" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-44033</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-44033" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-44033" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-44033" ref_url="https://www.suse.com/security/cve/CVE-2022-44033" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2023:0416-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013765.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4040_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between cm4040_open() and reader_detach().
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-02"/>
	<updated date="2023-06-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-44033/">CVE-2022-44033</cve>
	<bugzilla href="https://bugzilla.suse.com/1204922">SUSE bug 1204922</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1212306">SUSE bug 1212306</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202244034" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-44034</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-44034" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-44034" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-44034" ref_url="https://www.suse.com/security/cve/CVE-2022-44034" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling open(), aka a race condition between scr24x_open() and scr24x_remove().
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-01"/>
	<updated date="2023-01-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-44034/">CVE-2022-44034</cve>
	<bugzilla href="https://bugzilla.suse.com/1204901">SUSE bug 1204901</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202245869" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-45869</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-45869" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45869" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-45869" ref_url="https://www.suse.com/security/cve/CVE-2022-45869" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    A race condition in the x86 KVM subsystem in the Linux kernel through 6.1-rc6 allows guest OS users to cause a denial of service (host OS crash or host OS memory corruption) when nested virtualisation and the TDP MMU are enabled.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-02"/>
	<updated date="2023-01-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.1/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-45869/">CVE-2022-45869</cve>
	<bugzilla href="https://bugzilla.suse.com/1205882">SUSE bug 1205882</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202245888" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-45888</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-45888" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45888" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-45888" ref_url="https://www.suse.com/security/cve/CVE-2022-45888" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:5-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:8-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013511.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:9-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4504-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013252.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4585-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2022:4617-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2022-December/013342.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-11-26"/>
	<updated date="2023-01-25"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-45888/">CVE-2022-45888</cve>
	<bugzilla href="https://bugzilla.suse.com/1205764">SUSE bug 1205764</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202246781" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-46781</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-46781" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-46781" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-46781" ref_url="https://www.suse.com/security/cve/CVE-2022-46781" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-14"/>
	<updated date="2023-04-22"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2022-46781/">CVE-2022-46781</cve>
	<bugzilla href="https://bugzilla.suse.com/1210235">SUSE bug 1210235</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20224696" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-4696</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-4696" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4696" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-4696" ref_url="https://www.suse.com/security/cve/CVE-2022-4696" source="SUSE CVE"/>
    <description>
    There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current-&gt;nsproxy, so its reference counter is not increased. This assumption is not always true as calling io_splice on specific files will call the get_uts function which will use current-&gt;nsproxy leading to invalidly decreasing its reference counter later causing the use-after-free vulnerability. We recommend upgrading to version 5.10.160 or above
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-13"/>
	<updated date="2023-01-20"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-4696/">CVE-2022-4696</cve>
	<bugzilla href="https://bugzilla.suse.com/1207118">SUSE bug 1207118</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20224744" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-4744</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-4744" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4744" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-4744" ref_url="https://www.suse.com/security/cve/CVE-2022-4744" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1800-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1802-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1811-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1892-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1897-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1992-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2694-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015352.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2695-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030122.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2698-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015362.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2701-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015369.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2710-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030138.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2714-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030133.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2724-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030147.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2727-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030148.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2741-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015389.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2755-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030160.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-10"/>
	<updated date="2023-09-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-4744/">CVE-2022-4744</cve>
	<bugzilla href="https://bugzilla.suse.com/1209635">SUSE bug 1209635</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209672">SUSE bug 1209672</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1211833">SUSE bug 1211833</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202247518" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-47518</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-47518" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47518" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-47518" ref_url="https://www.suse.com/security/cve/CVE-2022-47518" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of operating channels from Wi-Fi management frames.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-20"/>
	<updated date="2022-12-20"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-47518/">CVE-2022-47518</cve>
	<bugzilla href="https://bugzilla.suse.com/1206511">SUSE bug 1206511</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202247519" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-47519</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-47519" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47519" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-47519" ref_url="https://www.suse.com/security/cve/CVE-2022-47519" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the channel list attribute from Wi-Fi management frames.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-20"/>
	<updated date="2022-12-20"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8/CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-47519/">CVE-2022-47519</cve>
	<bugzilla href="https://bugzilla.suse.com/1206512">SUSE bug 1206512</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202247520" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-47520</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-47520" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47520" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-47520" ref_url="https://www.suse.com/security/cve/CVE-2022-47520" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:139-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:141-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013752.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:142-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013753.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0146-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013527.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0147-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013528.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0149-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013959.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in the WILC1000 wireless driver can trigger an out-of-bounds read when parsing a Robust Security Network (RSN) information element from a Netlink packet.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-20"/>
	<updated date="2023-03-18"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L" href="https://www.suse.com/security/cve/CVE-2022-47520/">CVE-2022-47520</cve>
	<bugzilla href="https://bugzilla.suse.com/1206515">SUSE bug 1206515</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1207823">SUSE bug 1207823</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202247521" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-47521</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-47521" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47521" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-47521" ref_url="https://www.suse.com/security/cve/CVE-2022-47521" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the operating channel attribute from Wi-Fi management frames.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-20"/>
	<updated date="2022-12-20"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2022-47521/">CVE-2022-47521</cve>
	<bugzilla href="https://bugzilla.suse.com/1206516">SUSE bug 1206516</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202247938" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-47938</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-47938" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47938" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-47938" ref_url="https://www.suse.com/security/cve/CVE-2022-47938" source="SUSE CVE"/>
    <description>
    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2misc.c has an out-of-bounds read and OOPS for SMB2_TREE_CONNECT.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-24"/>
	<updated date="2022-12-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-47938/">CVE-2022-47938</cve>
	<bugzilla href="https://bugzilla.suse.com/1206658">SUSE bug 1206658</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202247939" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-47939</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-47939" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47939" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-47939" ref_url="https://www.suse.com/security/cve/CVE-2022-47939" source="SUSE CVE"/>
    <description>
    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-24"/>
	<updated date="2022-12-26"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="10/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-47939/">CVE-2022-47939</cve>
	<bugzilla href="https://bugzilla.suse.com/1206654">SUSE bug 1206654</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202247940" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-47940</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-47940" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47940" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-47940" ref_url="https://www.suse.com/security/cve/CVE-2022-47940" source="SUSE CVE"/>
    <description>
    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-26"/>
	<updated date="2022-12-26"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-47940/">CVE-2022-47940</cve>
	<bugzilla href="https://bugzilla.suse.com/1206679">SUSE bug 1206679</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202247941" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-47941</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-47941" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47941" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-47941" ref_url="https://www.suse.com/security/cve/CVE-2022-47941" source="SUSE CVE"/>
    <description>
    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-24"/>
	<updated date="2022-12-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2022-47941/">CVE-2022-47941</cve>
	<bugzilla href="https://bugzilla.suse.com/1206656">SUSE bug 1206656</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202247942" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-47942</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-47942" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47942" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-47942" ref_url="https://www.suse.com/security/cve/CVE-2022-47942" source="SUSE CVE"/>
    <description>
    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-24"/>
	<updated date="2022-12-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.5/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-47942/">CVE-2022-47942</cve>
	<bugzilla href="https://bugzilla.suse.com/1206657">SUSE bug 1206657</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202247943" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-47943</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-47943" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47943" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-47943" ref_url="https://www.suse.com/security/cve/CVE-2022-47943" source="SUSE CVE"/>
    <description>
    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is an out-of-bounds read and OOPS for SMB2_WRITE, when there is a large length in the zero DataOffset case.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-24"/>
	<updated date="2022-12-26"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-47943/">CVE-2022-47943</cve>
	<bugzilla href="https://bugzilla.suse.com/1206655">SUSE bug 1206655</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202247946" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-47946</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-47946" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47946" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-47946" ref_url="https://www.suse.com/security/cve/CVE-2022-47946" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attacker to crash the kernel, resulting in denial of service. finish_wait can be skipped. An attack can occur in some situations by forking a process and then quickly terminating it. NOTE: later kernel versions, such as the 5.15 longterm series, substantially changed the implementation of io_sqpoll_wait_sq.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-28"/>
	<updated date="2022-12-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-47946/">CVE-2022-47946</cve>
	<bugzilla href="https://bugzilla.suse.com/1206714">SUSE bug 1206714</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20224842" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-4842</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-4842" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4842" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-4842" ref_url="https://www.suse.com/security/cve/CVE-2022-4842" source="SUSE CVE"/>
    <description>
    A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user could use this flaw to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2022-12-31"/>
	<updated date="2023-01-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-4842/">CVE-2022-4842</cve>
	<bugzilla href="https://bugzilla.suse.com/1206749">SUSE bug 1206749</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202248423" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-48423</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-48423" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48423" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-48423" ref_url="https://www.suse.com/security/cve/CVE-2022-48423" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write may occur.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-21"/>
	<updated date="2023-03-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.1/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-48423/">CVE-2022-48423</cve>
	<bugzilla href="https://bugzilla.suse.com/1209479">SUSE bug 1209479</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202248424" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-48424</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-48424" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48424" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-48424" ref_url="https://www.suse.com/security/cve/CVE-2022-48424" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 6.1.3, fs/ntfs3/inode.c does not validate the attribute name offset. An unhandled page fault may occur.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-21"/>
	<updated date="2023-03-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.1/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-48424/">CVE-2022-48424</cve>
	<bugzilla href="https://bugzilla.suse.com/1209475">SUSE bug 1209475</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202248425" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-48425</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-48425" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48425" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-48425" ref_url="https://www.suse.com/security/cve/CVE-2022-48425" source="SUSE CVE"/>
    <description>
    In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-21"/>
	<updated date="2023-03-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.1/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2022-48425/">CVE-2022-48425</cve>
	<bugzilla href="https://bugzilla.suse.com/1209501">SUSE bug 1209501</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202248502" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2022-48502</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2022-48502" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48502" source="CVE"/>
    <reference ref_id="SUSE CVE-2022-48502" ref_url="https://www.suse.com/security/cve/CVE-2022-48502" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-02"/>
	<updated date="2023-06-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2022-48502/">CVE-2022-48502</cve>
	<bugzilla href="https://bugzilla.suse.com/1211887">SUSE bug 1211887</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20230030" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-0030</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-0030" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0030" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-0030" ref_url="https://www.suse.com/security/cve/CVE-2023-0030" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that causes the nvkm_vma_tail function to fail. This flaw allows a local user to crash or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-03"/>
	<updated date="2023-03-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.1/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-0030/">CVE-2023-0030</cve>
	<bugzilla href="https://bugzilla.suse.com/1206777">SUSE bug 1206777</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20230122" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-0122</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-0122" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0122" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-0122" ref_url="https://www.suse.com/security/cve/CVE-2023-0122" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:154-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:155-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013801.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference vulnerability in the Linux kernel NVMe functionality, in nvmet_setup_auth(), allows an attacker to perform a Pre-Auth Denial of Service (DoS) attack on a remote machine. Affected versions v6.0-rc1 to v6.0-rc3, fixed in v6.0-rc4.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-12"/>
	<updated date="2023-07-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-0122/">CVE-2023-0122</cve>
	<bugzilla href="https://bugzilla.suse.com/1207050">SUSE bug 1207050</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20230179" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-0179</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-0179" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0179" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-0179" ref_url="https://www.suse.com/security/cve/CVE-2023-0179" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:154-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:155-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0409-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013761.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013801.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0522-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013894.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0523-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013893.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0547-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013899.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0553-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013929.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0562-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013923.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0564-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013922.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013930.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0635-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013981.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0637-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013980.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-12"/>
	<updated date="2023-09-12"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-0179/">CVE-2023-0179</cve>
	<bugzilla href="https://bugzilla.suse.com/1207034">SUSE bug 1207034</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1207139">SUSE bug 1207139</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1215208">SUSE bug 1215208</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20230210" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-0210</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-0210" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0210" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-0210" ref_url="https://www.suse.com/security/cve/CVE-2023-0210" source="SUSE CVE"/>
    <description>
    A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-12"/>
	<updated date="2023-04-05"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-0210/">CVE-2023-0210</cve>
	<bugzilla href="https://bugzilla.suse.com/1206707">SUSE bug 1206707</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20230266" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-0266</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-0266" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0266" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-0266" ref_url="https://www.suse.com/security/cve/CVE-2023-0266" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:154-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014028.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:155-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014029.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:156-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014030.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:158-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:159-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:164-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0152-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-January/013530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0394-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013743.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0406-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013757.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0433-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013801.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0485-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-February/013878.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0618-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013976.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0634-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/013982.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1576-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1592-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014199.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1619-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028419.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1639-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028420.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1640-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028432.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1649-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014213.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1708-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028530.html" source="SUSE-SU"/>
    <description>
    A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel.?SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit?56b88b50565cd8b946a2d00b0c83927b7ebb055e

    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-26"/>
	<updated date="2023-08-19"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-0266/">CVE-2023-0266</cve>
	<bugzilla href="https://bugzilla.suse.com/1207134">SUSE bug 1207134</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1207190">SUSE bug 1207190</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1214128">SUSE bug 1214128</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20230386" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-0386</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-0386" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0386" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-0386" ref_url="https://www.suse.com/security/cve/CVE-2023-0386" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2140-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2141-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2231-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029435.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2368-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029712.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2369-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029711.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2371-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2384-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2425" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2428" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029754.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2431" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2455-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2459-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029778.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2468-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-23"/>
	<updated date="2023-09-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-0386/">CVE-2023-0386</cve>
	<bugzilla href="https://bugzilla.suse.com/1209615">SUSE bug 1209615</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1210499">SUSE bug 1210499</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20230458" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-0458</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-0458" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0458" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-0458" ref_url="https://www.suse.com/security/cve/CVE-2023-0458" source="SUSE CVE"/>
    <description>
    A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend upgrading past version 6.1.8 or commit?739790605705ddcf18f21782b9c99ad7d53a8c11
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-28"/>
	<updated date="2023-04-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2023-0458/">CVE-2023-0458</cve>
	<bugzilla href="https://bugzilla.suse.com/1210905">SUSE bug 1210905</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20230461" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-0461</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-0461" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0461" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-0461" ref_url="https://www.suse.com/security/cve/CVE-2023-0461" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1710-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1800-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1811-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1892-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2371-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2384-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029736.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2405" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2416" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2423" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2425" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015103.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2431" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015106.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2443-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015109.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2448-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029781.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2455-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029779.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2468-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015114.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS?or CONFIG_XFRM_ESPINTCP?has to be configured, but the operation does not require any privilege.

There is a use-after-free bug of icsk_ulp_data?of a struct inet_connection_sock.

When CONFIG_TLS?is enabled, user can install a tls context (struct tls_context) on a connected tcp socket. The context is not cleared if this socket is disconnected and reused as a listener. If a new socket is created from the listener, the context is inherited and vulnerable.

The setsockopt?TCP_ULP?operation does not require any privilege.

We recommend upgrading past commit?2c02d41d71f90a5168391b6a5f2954112ba2307c
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-02"/>
	<updated date="2023-07-22"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-0461/">CVE-2023-0461</cve>
	<bugzilla href="https://bugzilla.suse.com/1208787">SUSE bug 1208787</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208911">SUSE bug 1208911</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1211833">SUSE bug 1211833</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20230468" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-0468</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-0468" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0468" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-0468" ref_url="https://www.suse.com/security/cve/CVE-2023-0468" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in io_uring/poll.c in io_poll_check_events in the io_uring subcomponent in the Linux Kernel due to a race condition of poll_refs. This flaw may cause a NULL pointer dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-26"/>
	<updated date="2023-01-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-0468/">CVE-2023-0468</cve>
	<bugzilla href="https://bugzilla.suse.com/1207511">SUSE bug 1207511</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20230469" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-0469</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-0469" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0469" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-0469" ref_url="https://www.suse.com/security/cve/CVE-2023-0469" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-01-26"/>
	<updated date="2023-07-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-0469/">CVE-2023-0469</cve>
	<bugzilla href="https://bugzilla.suse.com/1207521">SUSE bug 1207521</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20230615" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-0615</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-0615" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0615" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-0615" ref_url="https://www.suse.com/security/cve/CVE-2023-0615" source="SUSE CVE"/>
    <description>
    A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test code functionality. This issue occurs when a user triggers ioctls, such as VIDIOC_S_DV_TIMINGS ioctl. This could allow a local user to crash the system if vivid test code enabled.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-04"/>
	<updated date="2023-02-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-0615/">CVE-2023-0615</cve>
	<bugzilla href="https://bugzilla.suse.com/1207844">SUSE bug 1207844</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231032" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1032</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1032" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1032" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1032" ref_url="https://www.suse.com/security/cve/CVE-2023-1032" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-15"/>
	<updated date="2023-03-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2023-1032/">CVE-2023-1032</cve>
	<bugzilla href="https://bugzilla.suse.com/1209240">SUSE bug 1209240</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231075" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1075</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1075" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1075" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1075" ref_url="https://www.suse.com/security/cve/CVE-2023-1075" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1710-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1800-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1811-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1892-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux Kernel. The tls_is_tx_ready() incorrectly checks for list emptiness, potentially accessing a type confused entry to the list_head, leaking the last byte of the confused field that overlaps with rec-&gt;tx_ready.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-01"/>
	<updated date="2023-07-22"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2023-1075/">CVE-2023-1075</cve>
	<bugzilla href="https://bugzilla.suse.com/1208598">SUSE bug 1208598</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231078" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1078</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1078" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1078" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1078" ref_url="https://www.suse.com/security/cve/CVE-2023-1078" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1574-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028374.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1576-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1591-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014173.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1592-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014175.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014201.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1605-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014198.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1610-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014196.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1621-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1639-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028420.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1645-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014210.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1649-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028437.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1651-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028436.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1708-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028530.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1710-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1800-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1811-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1892-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type confusion leads to `struct rds_msg_zcopy_info *info` actually points to something else that is potentially controlled by local user. It is known how to trigger this, which causes an out of bounds access, and a lock corruption.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-25"/>
	<updated date="2023-07-12"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-1078/">CVE-2023-1078</cve>
	<bugzilla href="https://bugzilla.suse.com/1208601">SUSE bug 1208601</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1208603">SUSE bug 1208603</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231192" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1192</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1192" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1192" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1192" ref_url="https://www.suse.com/security/cve/CVE-2023-1192" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3988-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4028-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4031-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016617.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4032-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016621.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4033-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016620.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4071-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4095-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/032196.html" source="SUSE-SU"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-08"/>
	<updated date="2023-10-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-1192/">CVE-2023-1192</cve>
	<bugzilla href="https://bugzilla.suse.com/1208995">SUSE bug 1208995</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231193" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1193</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1193" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1193" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1193" ref_url="https://www.suse.com/security/cve/CVE-2023-1193" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-22"/>
	<updated date="2023-03-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2023-1193/">CVE-2023-1193</cve>
	<bugzilla href="https://bugzilla.suse.com/1208972">SUSE bug 1208972</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231194" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1194</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1194" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1194" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1194" ref_url="https://www.suse.com/security/cve/CVE-2023-1194" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-07"/>
	<updated date="2023-07-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-1194/">CVE-2023-1194</cve>
	<bugzilla href="https://bugzilla.suse.com/1208968">SUSE bug 1208968</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231195" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1195</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1195" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1195" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1195" ref_url="https://www.suse.com/security/cve/CVE-2023-1195" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2023:0779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014076.html" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue occurs when it forgets to set the free pointer server-&gt;hostname to NULL, leading to an invalid pointer request.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-07"/>
	<updated date="2023-05-19"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.2/CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2023-1195/">CVE-2023-1195</cve>
	<bugzilla href="https://bugzilla.suse.com/1208971">SUSE bug 1208971</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231252" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1252</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1252" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1252" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1252" ref_url="https://www.suse.com/security/cve/CVE-2023-1252" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in the Linux kernel’s Ext4 File System in how a user triggers several file operations simultaneously with the overlay FS usage. This flaw allows a local user to crash or potentially escalate their privileges on the system. Only if patch 9a2544037600 ("ovl: fix use after free in struct ovl_aio_req") not applied yet, the kernel could be affected.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-10"/>
	<updated date="2023-03-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2023-1252/">CVE-2023-1252</cve>
	<bugzilla href="https://bugzilla.suse.com/1209045">SUSE bug 1209045</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231295" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1295</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1295" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1295" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1295" ref_url="https://www.suse.com/security/cve/CVE-2023-1295" source="SUSE CVE"/>
    <description>
    A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-30"/>
	<updated date="2023-06-30"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-1295/">CVE-2023-1295</cve>
	<bugzilla href="https://bugzilla.suse.com/1212836">SUSE bug 1212836</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231382" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1382</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1382" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1382" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1382" ref_url="https://www.suse.com/security/cve/CVE-2023-1382" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:476-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1800-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1811-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1892-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2500-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2653-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2782-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A data race flaw was found in the Linux kernel, between where con is allocated and con-&gt;sock is set. This issue leads to a NULL pointer dereference when accessing con-&gt;sock-&gt;sk in net/tipc/topsrv.c in the tipc protocol in the Linux kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-16"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-1382/">CVE-2023-1382</cve>
	<bugzilla href="https://bugzilla.suse.com/1209288">SUSE bug 1209288</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231476" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1476</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1476" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1476" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1476" ref_url="https://www.suse.com/security/cve/CVE-2023-1476" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-23"/>
	<updated date="2023-03-23"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-1476/">CVE-2023-1476</cve>
	<bugzilla href="https://bugzilla.suse.com/1209476">SUSE bug 1209476</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231582" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1582</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1582" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1582" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1582" ref_url="https://www.suse.com/security/cve/CVE-2023-1582" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1800-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1802-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1811-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1892-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1897-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1992-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A race problem was found in fs/proc/task_mmu.c in the memory management sub-component in the Linux kernel. This issue may allow a local attacker with user privilege to cause a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-24"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-1582/">CVE-2023-1582</cve>
	<bugzilla href="https://bugzilla.suse.com/1209636">SUSE bug 1209636</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231583" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1583</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1583" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1583" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1583" ref_url="https://www.suse.com/security/cve/CVE-2023-1583" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference was found in io_file_bitmap_get in io_uring/filetable.c in the io_uring sub-component in the Linux Kernel. When fixed files are unregistered, some context information (file_alloc_{start,end} and alloc_hint) is not cleared. A subsequent request that has auto index selection enabled via IORING_FILE_INDEX_ALLOC can cause a NULL pointer dereference. An unprivileged user can use the flaw to cause a system crash.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-24"/>
	<updated date="2023-07-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-1583/">CVE-2023-1583</cve>
	<bugzilla href="https://bugzilla.suse.com/1209637">SUSE bug 1209637</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231652" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1652</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1652" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1652" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1652" ref_url="https://www.suse.com/security/cve/CVE-2023-1652" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1802-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1897-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1975-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1977-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014567.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1978-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014566.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1992-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2031-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2032-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014586.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014590.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2043-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/029005.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2055-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014611.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-28"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-1652/">CVE-2023-1652</cve>
	<bugzilla href="https://bugzilla.suse.com/1209788">SUSE bug 1209788</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1209797">SUSE bug 1209797</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231829" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1829</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1829" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1829" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1829" ref_url="https://www.suse.com/security/cve/CVE-2023-1829" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3302-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3748-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016315.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016316.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3768-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016322.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016321.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3786-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016325.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3809-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016343.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3811-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016342.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3838-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016350.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016349.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016444.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3928-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4097-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/032194.html" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation.?The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure.?A local attacker user can use this vulnerability to elevate its privileges to root.
We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28.


    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-12"/>
	<updated date="2023-10-18"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-1829/">CVE-2023-1829</cve>
	<bugzilla href="https://bugzilla.suse.com/1210335">SUSE bug 1210335</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1210619">SUSE bug 1210619</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20231872" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-1872</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-1872" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1872" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-1872" ref_url="https://www.suse.com/security/cve/CVE-2023-1872" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2146-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2147-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2148-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2401" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029744.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2405" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029746.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2416" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029741.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2423" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015104.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2448-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029781.html" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability in the Linux Kernel io_uring system can be exploited to achieve local privilege escalation.

The io_file_get_fixed function lacks the presence of ctx-&gt;uring_lock which can lead to a Use-After-Free vulnerability due a race condition with fixed files getting unregistered.

We recommend upgrading past commit da24142b1ef9fd5d36b76e36bab328a5b27523e8.


    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-14"/>
	<updated date="2023-06-16"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-1872/">CVE-2023-1872</cve>
	<bugzilla href="https://bugzilla.suse.com/1210414">SUSE bug 1210414</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1210417">SUSE bug 1210417</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232002" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2002</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2002" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2002" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2002" ref_url="https://www.suse.com/security/cve/CVE-2023-2002" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:476-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2500-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2653-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2782-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2804-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030267.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2808-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030271.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2810-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2822-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015490.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2830-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015491.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3036-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015700.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3046-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3055-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015699.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3069-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015709.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3073-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015715.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3075-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015714.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015713.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015712.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3083-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015716.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3104-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015732.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015730.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015733.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3153-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015755.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-19"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-2002/">CVE-2023-2002</cve>
	<bugzilla href="https://bugzilla.suse.com/1210533">SUSE bug 1210533</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1210566">SUSE bug 1210566</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
			<criteria operator="OR">
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009705046" comment="kernel-rt is not affected"/>
			</criteria>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232006" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2006</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2006" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2006" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2006" ref_url="https://www.suse.com/security/cve/CVE-2023-2006" source="SUSE CVE"/>
    <description>
    A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-15"/>
	<updated date="2023-04-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-2006/">CVE-2023-2006</cve>
	<bugzilla href="https://bugzilla.suse.com/1210447">SUSE bug 1210447</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1210457">SUSE bug 1210457</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232008" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2008</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2008" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2008" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2008" ref_url="https://www.suse.com/security/cve/CVE-2023-2008" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2140-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2141-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2146-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029295.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2147-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029301.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2148-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029300.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2231-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029435.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an array. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-15"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-2008/">CVE-2023-2008</cve>
	<bugzilla href="https://bugzilla.suse.com/1210453">SUSE bug 1210453</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232019" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2019</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2019" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2019" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2019" ref_url="https://www.suse.com/security/cve/CVE-2023-2019" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2140-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2141-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2231-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029435.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-15"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.1/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-2019/">CVE-2023-2019</cve>
	<bugzilla href="https://bugzilla.suse.com/1210454">SUSE bug 1210454</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202320941" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-20941</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-20941" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-20941" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-20941" ref_url="https://www.suse.com/security/cve/CVE-2023-20941" source="SUSE CVE"/>
    <description>
    In acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-264029575References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-21"/>
	<updated date="2023-04-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-20941/">CVE-2023-20941</cve>
	<bugzilla href="https://bugzilla.suse.com/1210676">SUSE bug 1210676</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202321102" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-21102</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-21102" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21102" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-21102" ref_url="https://www.suse.com/security/cve/CVE-2023-21102" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2782-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a possible bypass of shadow stack protection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-260821414References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-10"/>
	<updated date="2023-09-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-21102/">CVE-2023-21102</cve>
	<bugzilla href="https://bugzilla.suse.com/1212155">SUSE bug 1212155</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1212346">SUSE bug 1212346</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202321106" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-21106</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-21106" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21106" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-21106" ref_url="https://www.suse.com/security/cve/CVE-2023-21106" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-265016072References: Upstream kernel
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-24"/>
	<updated date="2023-07-22"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-21106/">CVE-2023-21106</cve>
	<bugzilla href="https://bugzilla.suse.com/1211654">SUSE bug 1211654</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1211655">SUSE bug 1211655</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202321264" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-21264</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-21264" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21264" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-21264" ref_url="https://www.suse.com/security/cve/CVE-2023-21264" source="SUSE CVE"/>
    <description>
    In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.


    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-16"/>
	<updated date="2023-08-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-21264/">CVE-2023-21264</cve>
	<bugzilla href="https://bugzilla.suse.com/1214289">SUSE bug 1214289</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202321400" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-21400</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-21400" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21400" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-21400" ref_url="https://www.suse.com/security/cve/CVE-2023-21400" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:579-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3302-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3311-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3318-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3377-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016222.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016326.html" source="SUSE-SU"/>
    <description>
    In multiple functions  of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.


    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-28"/>
	<updated date="2023-09-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-21400/">CVE-2023-21400</cve>
	<bugzilla href="https://bugzilla.suse.com/1213272">SUSE bug 1213272</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232156" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2156</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2156" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2156" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2156" ref_url="https://www.suse.com/security/cve/CVE-2023-2156" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:476-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:579-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2500-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2502-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2611-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2653-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2782-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3302-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3311-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3318-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3377-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3391-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3421-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3594-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3631-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016171.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3632-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016170.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3644-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3653-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016177.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3657-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3658-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016184.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3659-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016183.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3668-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3671-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031547.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3675-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031546.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3676-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031545.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3677-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031544.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-10"/>
	<updated date="2023-09-20"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-2156/">CVE-2023-2156</cve>
	<bugzilla href="https://bugzilla.suse.com/1211131">SUSE bug 1211131</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1211395">SUSE bug 1211395</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232163" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2163</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2163" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2163" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2163" ref_url="https://www.suse.com/security/cve/CVE-2023-2163" source="SUSE CVE"/>
    <description>
    Incorrect verifier pruning?in BPF in Linux Kernel?&gt;=5.4?leads to unsafe
code paths being incorrectly marked as safe, resulting in?arbitrary read/write in
kernel memory, lateral privilege escalation, and container escape.

    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-21"/>
	<updated date="2023-09-26"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://www.suse.com/security/cve/CVE-2023-2163/">CVE-2023-2163</cve>
	<bugzilla href="https://bugzilla.suse.com/1215518">SUSE bug 1215518</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1215519">SUSE bug 1215519</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202321636" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-21636</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-21636" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21636" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-21636" ref_url="https://www.suse.com/security/cve/CVE-2023-21636" source="SUSE CVE"/>
    <description>
    Memory Corruption due to improper validation of array index in Linux while updating adn record.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-16"/>
	<updated date="2023-09-16"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-21636/">CVE-2023-21636</cve>
	<bugzilla href="https://bugzilla.suse.com/1215069">SUSE bug 1215069</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232166" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2166</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2166" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2166" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2166" ref_url="https://www.suse.com/security/cve/CVE-2023-2166" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:579-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3302-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3311-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3318-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3377-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015992.html" source="SUSE-SU"/>
    <description>
    A null pointer dereference issue was found in can protocol in net/can/af_can.c in the Linux before Linux. ml_priv may not be initialized in the receive path of CAN frames. A local user could use this flaw to crash the system or potentially cause a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-10"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-2166/">CVE-2023-2166</cve>
	<bugzilla href="https://bugzilla.suse.com/1210627">SUSE bug 1210627</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232177" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2177</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2177" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2177" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2177" ref_url="https://www.suse.com/security/cve/CVE-2023-2177" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3988-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4071-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4095-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/032196.html" source="SUSE-SU"/>
    <description>
    A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If stream_in allocation is failed, stream_out is freed which would further be accessed. A local user could use this flaw to crash the system or potentially cause a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-20"/>
	<updated date="2023-10-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-2177/">CVE-2023-2177</cve>
	<bugzilla href="https://bugzilla.suse.com/1210643">SUSE bug 1210643</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202322024" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-22024</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-22024" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22024" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-22024" ref_url="https://www.suse.com/security/cve/CVE-2023-22024" source="SUSE CVE"/>
    <description>
    In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant.  A malicious local user with CAP_NET_ADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-27"/>
	<updated date="2023-09-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-22024/">CVE-2023-22024</cve>
	<bugzilla href="https://bugzilla.suse.com/1215615">SUSE bug 1215615</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232235" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2235</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2235" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2235" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2235" ref_url="https://www.suse.com/security/cve/CVE-2023-2235" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2140-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2141-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2231-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029435.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3055-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015699.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015712.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015733.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3153-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015755.html" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privilege escalation.

The perf_group_detach function did not check the event's siblings' attach_state before calling add_event_to_groups(), but?remove_on_exec made it possible to call list_del_event() on before detaching from their group, making it possible to use a dangling pointer causing a use-after-free vulnerability.

We recommend upgrading past commit fd0815f632c24878e325821943edccc7fde947a2.


    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-12"/>
	<updated date="2023-09-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-2235/">CVE-2023-2235</cve>
	<bugzilla href="https://bugzilla.suse.com/1210986">SUSE bug 1210986</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1210987">SUSE bug 1210987</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232236" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2236</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2236" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2236" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2236" ref_url="https://www.suse.com/security/cve/CVE-2023-2236" source="SUSE CVE"/>
    <description>
    A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation.

Both?io_install_fixed_file?and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability.

We recommend upgrading past commit 9d94c04c0db024922e886c9fd429659f22f48ea4.


    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-03"/>
	<updated date="2023-05-05"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-2236/">CVE-2023-2236</cve>
	<bugzilla href="https://bugzilla.suse.com/1210990">SUSE bug 1210990</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1210991">SUSE bug 1210991</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202322995" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-22995</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-22995" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22995" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-22995" ref_url="https://www.suse.com/security/cve/CVE-2023-22995" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0796-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014087.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1710-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028529.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.17, an error path in dwc3_qcom_acpi_register_core in drivers/usb/dwc3/dwc3-qcom.c lacks certain platform_device_put and kfree calls.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-01"/>
	<updated date="2023-06-16"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2023-22995/">CVE-2023-22995</cve>
	<bugzilla href="https://bugzilla.suse.com/1208741">SUSE bug 1208741</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202322996" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-22996</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-22996" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22996" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-22996" ref_url="https://www.suse.com/security/cve/CVE-2023-22996" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 5.17.2, drivers/soc/qcom/qcom_aoss.c does not release an of_find_device_by_node reference after use, e.g., with put_device.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-02"/>
	<updated date="2023-03-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2023-22996/">CVE-2023-22996</cve>
	<bugzilla href="https://bugzilla.suse.com/1208781">SUSE bug 1208781</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202322997" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-22997</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-22997" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22997" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-22997" ref_url="https://www.suse.com/security/cve/CVE-2023-22997" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 6.1.2, kernel/module/decompress.c misinterprets the module_get_next_page return value (expects it to be NULL in the error case, whereas it is actually an error pointer).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-02"/>
	<updated date="2023-03-02"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-22997/">CVE-2023-22997</cve>
	<bugzilla href="https://bugzilla.suse.com/1208782">SUSE bug 1208782</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202322998" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-22998</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-22998" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22998" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-22998" ref_url="https://www.suse.com/security/cve/CVE-2023-22998" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1710-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 6.0.3, drivers/gpu/drm/virtio/virtgpu_object.c misinterprets the drm_gem_shmem_get_sg_table return value (expects it to be NULL in the error case, whereas it is actually an error pointer).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-02"/>
	<updated date="2023-07-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-22998/">CVE-2023-22998</cve>
	<bugzilla href="https://bugzilla.suse.com/1208776">SUSE bug 1208776</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202322999" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-22999</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-22999" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22999" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-22999" ref_url="https://www.suse.com/security/cve/CVE-2023-22999" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 5.16.3, drivers/usb/dwc3/dwc3-qcom.c misinterprets the dwc3_qcom_create_urs_usb_platdev return value (expects it to be NULL in the error case, whereas it is actually an error pointer).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-02"/>
	<updated date="2023-03-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.1/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-22999/">CVE-2023-22999</cve>
	<bugzilla href="https://bugzilla.suse.com/1208785">SUSE bug 1208785</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202323000" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-23000</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-23000" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23000" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-23000" ref_url="https://www.suse.com/security/cve/CVE-2023-23000" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1710-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.17, drivers/phy/tegra/xusb.c mishandles the tegra_xusb_find_port_node return value. Callers expect NULL in the error case, but an error pointer is used.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-03"/>
	<updated date="2023-07-22"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2023-23000/">CVE-2023-23000</cve>
	<bugzilla href="https://bugzilla.suse.com/1208816">SUSE bug 1208816</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202323001" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-23001</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-23001" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23001" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-23001" ref_url="https://www.suse.com/security/cve/CVE-2023-23001" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1897-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1992-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.16.3, drivers/scsi/ufs/ufs-mediatek.c misinterprets the regulator_get return value (expects it to be NULL in the error case, whereas it is actually an error pointer).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-03"/>
	<updated date="2023-09-15"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2023-23001/">CVE-2023-23001</cve>
	<bugzilla href="https://bugzilla.suse.com/1208829">SUSE bug 1208829</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202323002" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-23002</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-23002" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23002" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-23002" ref_url="https://www.suse.com/security/cve/CVE-2023-23002" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 5.16.3, drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (expects it to be NULL in the error case, whereas it is actually an error pointer).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-03"/>
	<updated date="2023-03-03"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.2/CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-23002/">CVE-2023-23002</cve>
	<bugzilla href="https://bugzilla.suse.com/1208840">SUSE bug 1208840</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202323003" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-23003</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-23003" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23003" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-23003" ref_url="https://www.suse.com/security/cve/CVE-2023-23003" source="SUSE CVE"/>
    <description>
    In the Linux kernel before 5.16, tools/perf/util/expr.c lacks a check for the hashmap__new return value.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-03"/>
	<updated date="2023-03-03"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-23003/">CVE-2023-23003</cve>
	<bugzilla href="https://bugzilla.suse.com/1208842">SUSE bug 1208842</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202323004" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-23004</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-23004" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23004" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-23004" ref_url="https://www.suse.com/security/cve/CVE-2023-23004" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1710-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1800-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1811-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.19, drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in the error case, whereas it is actually an error pointer).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-03"/>
	<updated date="2023-07-22"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-23004/">CVE-2023-23004</cve>
	<bugzilla href="https://bugzilla.suse.com/1208843">SUSE bug 1208843</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202323005" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-23005</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-23005" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23005" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-23005" ref_url="https://www.suse.com/security/cve/CVE-2023-23005" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-03"/>
	<updated date="2023-03-03"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="0/CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2023-23005/">CVE-2023-23005</cve>
	<bugzilla href="https://bugzilla.suse.com/1208844">SUSE bug 1208844</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202323006" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-23006</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-23006" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23006" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-23006" ref_url="https://www.suse.com/security/cve/CVE-2023-23006" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0778-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014073.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0780-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014075.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2140-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029296.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2141-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029306.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2231-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-May/029435.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel before 5.15.13, drivers/net/ethernet/mellanox/mlx5/core/steering/dr_domain.c misinterprets the mlx5_get_uars_page return value (expects it to be NULL in the error case, whereas it is actually an error pointer).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-03"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2023-23006/">CVE-2023-23006</cve>
	<bugzilla href="https://bugzilla.suse.com/1208845">SUSE bug 1208845</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202323039" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-23039</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-23039" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23039" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-23039" ref_url="https://www.suse.com/security/cve/CVE-2023-23039" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-25"/>
	<updated date="2023-03-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.7/CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-23039/">CVE-2023-23039</cve>
	<bugzilla href="https://bugzilla.suse.com/1208641">SUSE bug 1208641</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202323586" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-23586</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-23586" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23586" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-23586" ref_url="https://www.suse.com/security/cve/CVE-2023-23586" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2023:2502-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2611-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2651-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030079.html" source="SUSE-SU"/>
    <description>
    Due to a vulnerability in the io_uring subsystem, it is possible to leak kernel memory information to the user process. timens_install calls current_is_single_threaded to determine if the current process is single-threaded, but this call does not consider io_uring's io_worker threads, thus it is possible to insert a time namespace's vvar page to process's memory space via a page fault. When this time namespace is destroyed, the vvar page is also freed, but not removed from the process' memory, and a next page allocated by the kernel will be still available from the user-space process and can leak memory contents via this (read-only) use-after-free vulnerability. We recommend upgrading past version 5.10.161 or commit 788d0824269bef539fe31a785b1517882eafed93 https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/io_uring
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-21"/>
	<updated date="2023-06-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2023-23586/">CVE-2023-23586</cve>
	<bugzilla href="https://bugzilla.suse.com/1208474">SUSE bug 1208474</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232430" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2430</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2430" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2430" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2430" ref_url="https://www.suse.com/security/cve/CVE-2023-2430" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3302-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030995.html" source="SUSE-SU"/>
    <description>
    A vulnerability was found due to missing lock for IOPOLL flaw in io_cqring_event_overflow() in io_uring.c in Linux Kernel. This flaw allows a local attacker with user privilege to trigger a Denial of Service threat.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-03"/>
	<updated date="2023-08-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2023-2430/">CVE-2023-2430</cve>
	<bugzilla href="https://bugzilla.suse.com/1211014">SUSE bug 1211014</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202325012" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-25012</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-25012" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25012" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-25012" ref_url="https://www.suse.com/security/cve/CVE-2023-25012" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:219-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014438.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:220-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014439.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:221-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-April/014440.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0749-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014062.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:0779-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014076.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1608-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1609-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-March/014197.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1710-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-March/028529.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1800-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1811-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-03"/>
	<updated date="2023-07-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.8/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-25012/">CVE-2023-25012</cve>
	<bugzilla href="https://bugzilla.suse.com/1207560">SUSE bug 1207560</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1207846">SUSE bug 1207846</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232593" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2593</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2593" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2593" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2593" ref_url="https://www.suse.com/security/cve/CVE-2023-2593" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-05-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2023-2593/">CVE-2023-2593</cve>
	<bugzilla href="https://bugzilla.suse.com/1211527">SUSE bug 1211527</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232598" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2598</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2598" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2598" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2598" ref_url="https://www.suse.com/security/cve/CVE-2023-2598" source="SUSE CVE"/>
    <description>
    A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-10"/>
	<updated date="2023-06-08"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-2598/">CVE-2023-2598</cve>
	<bugzilla href="https://bugzilla.suse.com/1211046">SUSE bug 1211046</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202326083" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-26083</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-26083" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26083" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-26083" ref_url="https://www.suse.com/security/cve/CVE-2023-26083" source="SUSE CVE"/>
    <description>
    Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-04-14"/>
	<updated date="2023-04-14"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2023-26083/">CVE-2023-26083</cve>
	<bugzilla href="https://bugzilla.suse.com/1210236">SUSE bug 1210236</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232612" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2612</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2612" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2612" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2612" ref_url="https://www.suse.com/security/cve/CVE-2023-2612" source="SUSE CVE"/>
    <description>
    Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-02"/>
	<updated date="2023-06-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-2612/">CVE-2023-2612</cve>
	<bugzilla href="https://bugzilla.suse.com/1211902">SUSE bug 1211902</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202326242" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-26242</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-26242" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26242" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-26242" ref_url="https://www.suse.com/security/cve/CVE-2023-26242" source="SUSE CVE"/>
    <description>
    afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-09"/>
	<updated date="2023-05-09"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-26242/">CVE-2023-26242</cve>
	<bugzilla href="https://bugzilla.suse.com/1208518">SUSE bug 1208518</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202326544" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-26544</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-26544" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26544" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-26544" ref_url="https://www.suse.com/security/cve/CVE-2023-26544" source="SUSE CVE"/>
    <description>
    In the Linux kernel 6.0.8, there is a use-after-free in run_unpack in fs/ntfs3/run.c, related to a difference between NTFS sector size and media sector size.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-28"/>
	<updated date="2023-02-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-26544/">CVE-2023-26544</cve>
	<bugzilla href="https://bugzilla.suse.com/1208697">SUSE bug 1208697</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202326605" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-26605</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-26605" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26605" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-26605" ref_url="https://www.suse.com/security/cve/CVE-2023-26605" source="SUSE CVE"/>
    <description>
    In the Linux kernel 6.0.8, there is a use-after-free in inode_cgwb_move_to_attached in fs/fs-writeback.c, related to __list_del_entry_valid.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-02"/>
	<updated date="2023-03-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-26605/">CVE-2023-26605</cve>
	<bugzilla href="https://bugzilla.suse.com/1208699">SUSE bug 1208699</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202326606" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-26606</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-26606" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26606" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-26606" ref_url="https://www.suse.com/security/cve/CVE-2023-26606" source="SUSE CVE"/>
    <description>
    In the Linux kernel 6.0.8, there is a use-after-free in ntfs_trim_fs in fs/ntfs3/bitmap.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-28"/>
	<updated date="2023-02-28"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-26606/">CVE-2023-26606</cve>
	<bugzilla href="https://bugzilla.suse.com/1208694">SUSE bug 1208694</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202326607" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-26607</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-26607" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26607" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-26607" ref_url="https://www.suse.com/security/cve/CVE-2023-26607" source="SUSE CVE"/>
    <description>
    In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-02-28"/>
	<updated date="2023-03-05"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-26607/">CVE-2023-26607</cve>
	<bugzilla href="https://bugzilla.suse.com/1208703">SUSE bug 1208703</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202328327" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-28327</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-28327" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28327" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-28327" ref_url="https://www.suse.com/security/cve/CVE-2023-28327" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:317-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014849.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:318-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014850.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:319-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-May/014851.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:347-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015202.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:348-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015203.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:349-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-June/015204.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1800-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028739.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1802-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028740.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1811-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028747.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1892-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028848.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1897-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:1992-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-April/028974.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or potentially cause a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-03-16"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-28327/">CVE-2023-28327</cve>
	<bugzilla href="https://bugzilla.suse.com/1209290">SUSE bug 1209290</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202328410" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-28410</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-28410" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28410" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-28410" ref_url="https://www.suse.com/security/cve/CVE-2023-28410" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:476-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2500-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2653-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2782-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    Improper restriction of operations within the bounds of a memory buffer in some Intel(R) i915 Graphics drivers for linux before kernel version 6.2.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-25"/>
	<updated date="2023-09-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-28410/">CVE-2023-28410</cve>
	<bugzilla href="https://bugzilla.suse.com/1211263">SUSE bug 1211263</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1211819">SUSE bug 1211819</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202328866" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-28866</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-28866" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28866" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-28866" ref_url="https://www.suse.com/security/cve/CVE-2023-28866" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015533.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 6.2.8, net/bluetooth/hci_sync.c allows out-of-bounds access because amp_init1[] and amp_init2[] are supposed to have an intentionally invalid element, but do not.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-27"/>
	<updated date="2023-07-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2023-28866/">CVE-2023-28866</cve>
	<bugzilla href="https://bugzilla.suse.com/1209780">SUSE bug 1209780</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20232898" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-2898</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-2898" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2898" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-2898" ref_url="https://www.suse.com/security/cve/CVE-2023-2898" source="SUSE CVE"/>
    <description>
    There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-27"/>
	<updated date="2023-05-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.1/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-2898/">CVE-2023-2898</cve>
	<bugzilla href="https://bugzilla.suse.com/1211742">SUSE bug 1211742</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233022" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3022</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3022" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3022" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3022" ref_url="https://www.suse.com/security/cve/CVE-2023-3022" source="SUSE CVE"/>
    <description>
    A flaw was found in the IPv6 module of the Linux kernel. The arg.result was not used consistently in fib6_rule_lookup, sometimes holding rt6_info and other times fib6_info. This was not accounted for in other parts of the code where rt6_info was expected unconditionally, potentially leading to a kernel panic in fib6_rule_suppress.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-02"/>
	<updated date="2023-06-20"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-3022/">CVE-2023-3022</cve>
	<bugzilla href="https://bugzilla.suse.com/1211906">SUSE bug 1211906</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233106" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3106</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3106" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3106" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3106" ref_url="https://www.suse.com/security/cve/CVE-2023-3106" source="SUSE CVE"/>
		<reference ref_id="SUSE-SU-2023:3324-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031024.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is unlikely.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-13"/>
	<updated date="2023-08-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.6/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2023-3106/">CVE-2023-3106</cve>
	<bugzilla href="https://bugzilla.suse.com/1213251">SUSE bug 1213251</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202331081" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-31081</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-31081" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-31081" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-31081" ref_url="https://www.suse.com/security/cve/CVE-2023-31081" source="SUSE CVE"/>
    <description>
    An issue was discovered in drivers/media/test-drivers/vidtv/vidtv_bridge.c in the Linux kernel 6.2. There is a NULL pointer dereference in vidtv_mux_stop_thread. In vidtv_stop_streaming, after dvb-&gt;mux=NULL occurs, it executes vidtv_mux_stop_thread(dvb-&gt;mux).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-10"/>
	<updated date="2023-05-10"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-31081/">CVE-2023-31081</cve>
	<bugzilla href="https://bugzilla.suse.com/1210782">SUSE bug 1210782</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202331248" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-31248</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-31248" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-31248" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-31248" ref_url="https://www.suse.com/security/cve/CVE-2023-31248" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:579-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3171-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015772.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3172-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015771.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3180-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030786.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3182-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030784.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3302-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3318-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3391-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031135.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3421-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016321.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016320.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3928-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016475.html" source="SUSE-SU"/>
    <description>
    Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-07"/>
	<updated date="2023-10-04"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-31248/">CVE-2023-31248</cve>
	<bugzilla href="https://bugzilla.suse.com/1213061">SUSE bug 1213061</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1213064">SUSE bug 1213064</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233212" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3212</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3212" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3212" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3212" ref_url="https://www.suse.com/security/cve/CVE-2023-3212" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3302-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030995.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-15"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.3/CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-3212/">CVE-2023-3212</cve>
	<bugzilla href="https://bugzilla.suse.com/1212265">SUSE bug 1212265</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233220" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3220</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3220" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3220" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3220" ref_url="https://www.suse.com/security/cve/CVE-2023-3220" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015533.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c lacks check of the return value of kzalloc() and will cause the NULL Pointer Dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-22"/>
	<updated date="2023-07-22"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-3220/">CVE-2023-3220</cve>
	<bugzilla href="https://bugzilla.suse.com/1212556">SUSE bug 1212556</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332233" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32233</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32233" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32233" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32233" ref_url="https://www.suse.com/security/cve/CVE-2023-32233" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:476-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2500-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2502-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2611-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2651-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2653-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2782-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3594-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016141.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3595-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016143.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3607-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016155.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3612-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016163.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3620-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016161.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3623-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016162.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3627-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016169.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3628-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016168.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3630-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016172.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3644-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016180.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3647-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016179.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3648-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016178.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3668-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031548.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3671-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031547.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3675-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031546.html" source="SUSE-SU"/>
    <description>
    In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-05"/>
	<updated date="2023-09-20"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-32233/">CVE-2023-32233</cve>
	<bugzilla href="https://bugzilla.suse.com/1211043">SUSE bug 1211043</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1211187">SUSE bug 1211187</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332246" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32246</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32246" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32246" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32246" ref_url="https://www.suse.com/security/cve/CVE-2023-32246" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-05-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2023-32246/">CVE-2023-32246</cve>
	<bugzilla href="https://bugzilla.suse.com/1211528">SUSE bug 1211528</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332247" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32247</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32247" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32247" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32247" ref_url="https://www.suse.com/security/cve/CVE-2023-32247" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_SESSION_SETUP commands. The issue results from the lack of control of resource consumption. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-07-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-32247/">CVE-2023-32247</cve>
	<bugzilla href="https://bugzilla.suse.com/1211529">SUSE bug 1211529</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332248" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32248</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32248" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32248" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32248" ref_url="https://www.suse.com/security/cve/CVE-2023-32248" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-07-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-32248/">CVE-2023-32248</cve>
	<bugzilla href="https://bugzilla.suse.com/1211530">SUSE bug 1211530</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332249" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32249</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32249" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32249" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32249" ref_url="https://www.suse.com/security/cve/CVE-2023-32249" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-05-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2023-32249/">CVE-2023-32249</cve>
	<bugzilla href="https://bugzilla.suse.com/1211531">SUSE bug 1211531</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332250" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32250</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32250" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32250" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32250" ref_url="https://www.suse.com/security/cve/CVE-2023-32250" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-11"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-32250/">CVE-2023-32250</cve>
	<bugzilla href="https://bugzilla.suse.com/1211532">SUSE bug 1211532</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332251" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32251</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32251" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32251" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32251" ref_url="https://www.suse.com/security/cve/CVE-2023-32251" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-05-26"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2023-32251/">CVE-2023-32251</cve>
	<bugzilla href="https://bugzilla.suse.com/1211533">SUSE bug 1211533</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332252" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32252</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32252" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32252" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32252" ref_url="https://www.suse.com/security/cve/CVE-2023-32252" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-07-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-32252/">CVE-2023-32252</cve>
	<bugzilla href="https://bugzilla.suse.com/1211534">SUSE bug 1211534</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332253" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32253</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32253" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32253" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32253" ref_url="https://www.suse.com/security/cve/CVE-2023-32253" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-05-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2023-32253/">CVE-2023-32253</cve>
	<bugzilla href="https://bugzilla.suse.com/1211535">SUSE bug 1211535</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332254" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32254</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32254" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32254" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32254" ref_url="https://www.suse.com/security/cve/CVE-2023-32254" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-23"/>
	<updated date="2023-07-11"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-32254/">CVE-2023-32254</cve>
	<bugzilla href="https://bugzilla.suse.com/1211536">SUSE bug 1211536</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332255" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32255</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32255" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32255" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32255" ref_url="https://www.suse.com/security/cve/CVE-2023-32255" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-05-26"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2023-32255/">CVE-2023-32255</cve>
	<bugzilla href="https://bugzilla.suse.com/1211537">SUSE bug 1211537</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332256" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32256</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32256" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32256" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32256" ref_url="https://www.suse.com/security/cve/CVE-2023-32256" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-05-26"/>
	<severity>Important</severity>
	<cve impact="important" href="https://www.suse.com/security/cve/CVE-2023-32256/">CVE-2023-32256</cve>
	<bugzilla href="https://bugzilla.suse.com/1211538">SUSE bug 1211538</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332257" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32257</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32257" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32257" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32257" ref_url="https://www.suse.com/security/cve/CVE-2023-32257" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-07-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-32257/">CVE-2023-32257</cve>
	<bugzilla href="https://bugzilla.suse.com/1211539">SUSE bug 1211539</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332258" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32258</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32258" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32258" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32258" ref_url="https://www.suse.com/security/cve/CVE-2023-32258" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-26"/>
	<updated date="2023-07-25"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-32258/">CVE-2023-32258</cve>
	<bugzilla href="https://bugzilla.suse.com/1211540">SUSE bug 1211540</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202332629" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-32629</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-32629" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32629" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-32629" ref_url="https://www.suse.com/security/cve/CVE-2023-32629" source="SUSE CVE"/>
    <description>
    Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-27"/>
	<updated date="2023-07-28"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-32629/">CVE-2023-32629</cve>
	<bugzilla href="https://bugzilla.suse.com/1213685">SUSE bug 1213685</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1213707">SUSE bug 1213707</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233269" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3269</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3269" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3269" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3269" ref_url="https://www.suse.com/security/cve/CVE-2023-3269" source="SUSE CVE"/>
    <description>
    A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root privileges.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-12"/>
	<updated date="2023-07-29"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-3269/">CVE-2023-3269</cve>
	<bugzilla href="https://bugzilla.suse.com/1212395">SUSE bug 1212395</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1213760">SUSE bug 1213760</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233312" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3312</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3312" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3312" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3312" ref_url="https://www.suse.com/security/cve/CVE-2023-3312" source="SUSE CVE"/>
    <description>
    A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-21"/>
	<updated date="2023-06-21"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.4/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-3312/">CVE-2023-3312</cve>
	<bugzilla href="https://bugzilla.suse.com/1212536">SUSE bug 1212536</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202333250" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-33250</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-33250" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33250" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-33250" ref_url="https://www.suse.com/security/cve/CVE-2023-33250" source="SUSE CVE"/>
    <description>
    The Linux kernel 6.3 has a use-after-free in iopt_unmap_iova_range in drivers/iommu/iommufd/io_pagetable.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-24"/>
	<updated date="2023-05-24"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2023-33250/">CVE-2023-33250</cve>
	<bugzilla href="https://bugzilla.suse.com/1211597">SUSE bug 1211597</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202333288" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-33288</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-33288" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33288" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-33288" ref_url="https://www.suse.com/security/cve/CVE-2023-33288" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:474-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015462.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:476-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015463.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2500-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029844.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2502-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029842.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2611-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/029990.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2651-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030079.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2653-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-June/030078.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2782-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-18"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.8/CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2023-33288/">CVE-2023-33288</cve>
	<bugzilla href="https://bugzilla.suse.com/1211590">SUSE bug 1211590</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233355" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3355</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3355" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3355" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3355" ref_url="https://www.suse.com/security/cve/CVE-2023-3355" source="SUSE CVE"/>
    <description>
    A NULL pointer dereference flaw was found in the Linux kernel's drivers/gpu/drm/msm/msm_gem_submit.c code in the submit_lookup_cmds function, which fails because it lacks a check of the return value of kmalloc(). This issue allows a local user to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-28"/>
	<updated date="2023-06-29"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="1.9/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2023-3355/">CVE-2023-3355</cve>
	<bugzilla href="https://bugzilla.suse.com/1212778">SUSE bug 1212778</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233357" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3357</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3357" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3357" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3357" ref_url="https://www.suse.com/security/cve/CVE-2023-3357" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015533.html" source="SUSE-SU"/>
    <description>
    A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-23"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-3357/">CVE-2023-3357</cve>
	<bugzilla href="https://bugzilla.suse.com/1212605">SUSE bug 1212605</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233359" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3359</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3359" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3359" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3359" ref_url="https://www.suse.com/security/cve/CVE-2023-3359" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return value of kzalloc() can cause the NULL Pointer Dereference.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-23"/>
	<updated date="2023-06-29"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-3359/">CVE-2023-3359</cve>
	<bugzilla href="https://bugzilla.suse.com/1212608">SUSE bug 1212608</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233389" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3389</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3389" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3389" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3389" ref_url="https://www.suse.com/security/cve/CVE-2023-3389" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2803-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015466.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3302-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030995.html" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation.

Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer.

We recommend upgrading past commit ef7dfac51d8ed961b742218f526bd589f3900a59 (4716c73b188566865bdd79c3a6709696a224ac04 for 5.10 stable and?0e388fce7aec40992eadee654193cad345d62663 for 5.15 stable).


    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-01"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2023-3389/">CVE-2023-3389</cve>
	<bugzilla href="https://bugzilla.suse.com/1212838">SUSE bug 1212838</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202333951" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-33951</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-33951" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33951" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-33951" ref_url="https://www.suse.com/security/cve/CVE-2023-33951" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
    <description>
    A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-31"/>
	<updated date="2023-07-25"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2023-33951/">CVE-2023-33951</cve>
	<bugzilla href="https://bugzilla.suse.com/1211593">SUSE bug 1211593</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202333952" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-33952</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-33952" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33952" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-33952" ref_url="https://www.suse.com/security/cve/CVE-2023-33952" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015733.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3153-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015755.html" source="SUSE-SU"/>
    <description>
    A double-free vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of vmw_buffer_object objects. The issue results from the lack of validating the existence of an object prior to performing further free operations on the object. This flaw allows a local privileged user to escalate privileges and execute code in the context of the kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-05-31"/>
	<updated date="2023-08-03"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-33952/">CVE-2023-33952</cve>
	<bugzilla href="https://bugzilla.suse.com/1211595">SUSE bug 1211595</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1212348">SUSE bug 1212348</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202334256" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-34256</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-34256" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34256" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-34256" ref_url="https://www.suse.com/security/cve/CVE-2023-34256" source="SUSE CVE"/>
    <description>
    ** DISPUTED ** An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kernel is not intended to defend against attackers with the stated "When modifying the block device while it is mounted by the filesystem" access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-21"/>
	<updated date="2023-06-21"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="4/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2023-34256/">CVE-2023-34256</cve>
	<bugzilla href="https://bugzilla.suse.com/1211895">SUSE bug 1211895</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233439" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3439</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3439" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3439" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3439" ref_url="https://www.suse.com/security/cve/CVE-2023-3439" source="SUSE CVE"/>
    <description>
    A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However, a running routine may be unaware of this and cause the use-after-free of the mdev-&gt;addrs object, potentially leading to a denial of service.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-30"/>
	<updated date="2023-07-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-3439/">CVE-2023-3439</cve>
	<bugzilla href="https://bugzilla.suse.com/1212845">SUSE bug 1212845</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202335788" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-35788</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-35788" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35788" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-35788" ref_url="https://www.suse.com/security/cve/CVE-2023-35788" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2782-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2810-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015533.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015701.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3036-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015700.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3041-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015698.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3055-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015699.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3063-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015710.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3075-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015714.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3076-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015713.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3079-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015712.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3081-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015717.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3107-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015731.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3111-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015730.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3115-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015734.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3116-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015733.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3153-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015755.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-20"/>
	<updated date="2023-09-15"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-35788/">CVE-2023-35788</cve>
	<bugzilla href="https://bugzilla.suse.com/1212504">SUSE bug 1212504</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1212509">SUSE bug 1212509</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202335823" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-35823</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-35823" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35823" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-35823" ref_url="https://www.suse.com/security/cve/CVE-2023-35823" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2782-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2810-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015533.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-20"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-35823/">CVE-2023-35823</cve>
	<bugzilla href="https://bugzilla.suse.com/1212494">SUSE bug 1212494</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202335826" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-35826</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-35826" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35826" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-35826" ref_url="https://www.suse.com/security/cve/CVE-2023-35826" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-20"/>
	<updated date="2023-06-20"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.1/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-35826/">CVE-2023-35826</cve>
	<bugzilla href="https://bugzilla.suse.com/1212505">SUSE bug 1212505</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202335827" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-35827</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-35827" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35827" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-35827" ref_url="https://www.suse.com/security/cve/CVE-2023-35827" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel through 6.3.8. A use-after-free was found in ravb_remove in drivers/net/ethernet/renesas/ravb_main.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-20"/>
	<updated date="2023-06-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-35827/">CVE-2023-35827</cve>
	<bugzilla href="https://bugzilla.suse.com/1212514">SUSE bug 1212514</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202335828" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-35828</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-35828" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35828" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-35828" ref_url="https://www.suse.com/security/cve/CVE-2023-35828" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2782-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030185.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2810-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030273.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2834-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015496.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2859-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015533.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-20"/>
	<updated date="2023-09-15"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.7/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-35828/">CVE-2023-35828</cve>
	<bugzilla href="https://bugzilla.suse.com/1212513">SUSE bug 1212513</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202335829" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-35829</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-35829" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35829" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-35829" ref_url="https://www.suse.com/security/cve/CVE-2023-35829" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:489-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015537.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:505-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:506-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015555.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:548-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015787.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:549-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015788.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:550-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015789.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2809-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030270.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2820-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015477.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2831-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015492.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2871-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-July/030392.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:2892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-July/015533.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-06-20"/>
	<updated date="2023-08-07"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.4/CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-35829/">CVE-2023-35829</cve>
	<bugzilla href="https://bugzilla.suse.com/1212495">SUSE bug 1212495</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233610" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3610</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3610" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3610" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3610" ref_url="https://www.suse.com/security/cve/CVE-2023-3610" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3599-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3599-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3600-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031433.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3600-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3656-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3682-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3683-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031541.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3683-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3704-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3704-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3964-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/031902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3969-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/031917.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3988-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016554.html" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.

Flaw in the error handling of bound chains causes a use-after-free in the abort path of NFT_MSG_NEWRULE. The vulnerability requires CAP_NET_ADMIN to be triggered.

We recommend upgrading past commit 4bedf9eee016286c835e3d8fa981ddece5338795.


    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-25"/>
	<updated date="2023-10-17"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-3610/">CVE-2023-3610</cve>
	<bugzilla href="https://bugzilla.suse.com/1213580">SUSE bug 1213580</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1213584">SUSE bug 1213584</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202337453" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-37453</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-37453" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-37453" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-37453" ref_url="https://www.suse.com/security/cve/CVE-2023-37453" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3599-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3599-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3600-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031433.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3600-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3656-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3682-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3683-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031541.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3683-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3704-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3704-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3964-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/031902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3969-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/031917.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3988-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016554.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016647.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_descriptors in drivers/usb/core/sysfs.c.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-22"/>
	<updated date="2023-10-17"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.6/CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-37453/">CVE-2023-37453</cve>
	<bugzilla href="https://bugzilla.suse.com/1213123">SUSE bug 1213123</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233773" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3773</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3773" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3773" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3773" ref_url="https://www.suse.com/security/cve/CVE-2023-3773" source="SUSE CVE"/>
    <description>
    A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to userspace.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-27"/>
	<updated date="2023-07-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2023-3773/">CVE-2023-3773</cve>
	<bugzilla href="https://bugzilla.suse.com/1213667">SUSE bug 1213667</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233777" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3777</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3777" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3777" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3777" ref_url="https://www.suse.com/security/cve/CVE-2023-3777" source="SUSE CVE"/>
    <description>
    A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.

When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release the objects in certain circumstances.

We recommend upgrading past commit 6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8.


    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-08"/>
	<updated date="2023-09-19"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-3777/">CVE-2023-3777</cve>
	<bugzilla href="https://bugzilla.suse.com/1215095">SUSE bug 1215095</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1215097">SUSE bug 1215097</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202338409" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-38409</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-38409" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38409" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-38409" ref_url="https://www.suse.com/security/cve/CVE-2023-38409" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:579-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3302-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3311-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015987.html" source="SUSE-SU"/>
    <description>
    An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the con2fb_map points at the old fb_info).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-19"/>
	<updated date="2023-08-23"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="2.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2023-38409/">CVE-2023-38409</cve>
	<bugzilla href="https://bugzilla.suse.com/1213417">SUSE bug 1213417</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202338426" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-38426</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-38426" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38426" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-38426" ref_url="https://www.suse.com/security/cve/CVE-2023-38426" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-19"/>
	<updated date="2023-07-28"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-38426/">CVE-2023-38426</cve>
	<bugzilla href="https://bugzilla.suse.com/1213421">SUSE bug 1213421</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202338427" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-38427</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-38427" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38427" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-38427" ref_url="https://www.suse.com/security/cve/CVE-2023-38427" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-19"/>
	<updated date="2023-07-28"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-38427/">CVE-2023-38427</cve>
	<bugzilla href="https://bugzilla.suse.com/1213422">SUSE bug 1213422</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202338428" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-38428</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-38428" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38428" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-38428" ref_url="https://www.suse.com/security/cve/CVE-2023-38428" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-19"/>
	<updated date="2023-07-28"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-38428/">CVE-2023-38428</cve>
	<bugzilla href="https://bugzilla.suse.com/1213423">SUSE bug 1213423</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202338429" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-38429</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-38429" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38429" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-38429" ref_url="https://www.suse.com/security/cve/CVE-2023-38429" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-19"/>
	<updated date="2023-07-28"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-38429/">CVE-2023-38429</cve>
	<bugzilla href="https://bugzilla.suse.com/1213424">SUSE bug 1213424</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202338430" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-38430</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-38430" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38430" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-38430" ref_url="https://www.suse.com/security/cve/CVE-2023-38430" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID, leading to an out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-19"/>
	<updated date="2023-07-28"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-38430/">CVE-2023-38430</cve>
	<bugzilla href="https://bugzilla.suse.com/1213425">SUSE bug 1213425</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202338431" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-38431</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-38431" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38431" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-38431" ref_url="https://www.suse.com/security/cve/CVE-2023-38431" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationship between the NetBIOS header's length field and the SMB header sizes, via pdu_size in ksmbd_conn_handler_loop, leading to an out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-19"/>
	<updated date="2023-07-28"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-38431/">CVE-2023-38431</cve>
	<bugzilla href="https://bugzilla.suse.com/1213426">SUSE bug 1213426</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202338432" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-38432</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-38432" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38432" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-38432" ref_url="https://www.suse.com/security/cve/CVE-2023-38432" source="SUSE CVE"/>
    <description>
    An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-07-19"/>
	<updated date="2023-07-28"/>
	<severity>Critical</severity>
	<cve impact="critical" cvss3="9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-38432/">CVE-2023-38432</cve>
	<bugzilla href="https://bugzilla.suse.com/1213427">SUSE bug 1213427</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233865" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3865</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3865" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3865" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3865" ref_url="https://www.suse.com/security/cve/CVE-2023-3865" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-02"/>
	<updated date="2023-08-02"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-3865/">CVE-2023-3865</cve>
	<bugzilla href="https://bugzilla.suse.com/1213813">SUSE bug 1213813</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20233866" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-3866</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-3866" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3866" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-3866" ref_url="https://www.suse.com/security/cve/CVE-2023-3866" source="SUSE CVE"/>
    <description>
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-02"/>
	<updated date="2023-08-02"/>
	<severity>Moderate</severity>
	<cve impact="moderate" href="https://www.suse.com/security/cve/CVE-2023-3866/">CVE-2023-3866</cve>
	<bugzilla href="https://bugzilla.suse.com/1213814">SUSE bug 1213814</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202339190" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-39190</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-39190" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39190" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-39190" ref_url="https://www.suse.com/security/cve/CVE-2023-39190" source="SUSE CVE"/>
    <description>
    ** REJECT ** CVE-2023-39190 was found to be a duplicate of CVE-2023-31436. Please see https://access.redhat.com/security/cve/CVE-2023-31436 for information about affected products and security errata.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-10-10"/>
	<updated date="2023-10-10"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2023-39190/">CVE-2023-39190</cve>
	<bugzilla href="https://bugzilla.suse.com/1216056">SUSE bug 1216056</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202339191" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-39191</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-39191" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39191" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-39191" ref_url="https://www.suse.com/security/cve/CVE-2023-39191" source="SUSE CVE"/>
    <description>
    An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-10-04"/>
	<updated date="2023-10-10"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.2/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-39191/">CVE-2023-39191</cve>
	<bugzilla href="https://bugzilla.suse.com/1215863">SUSE bug 1215863</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1215887">SUSE bug 1215887</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20234004" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-4004</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-4004" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4004" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-4004" ref_url="https://www.suse.com/security/cve/CVE-2023-4004" source="SUSE CVE"/>
		<reference ref_id="SUSE-CU-2023:2960-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016146.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:577-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015968.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:578-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015969.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:579-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015970.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:602-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016082.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:603-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016083.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:604-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016084.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3302-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/030995.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3311-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031007.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3313-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015903.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3318-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-August/031011.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3376-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015987.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3377-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-August/015992.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4095-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/032196.html" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-01"/>
	<updated date="2023-10-18"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-4004/">CVE-2023-4004</cve>
	<bugzilla href="https://bugzilla.suse.com/1213812">SUSE bug 1213812</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1214812">SUSE bug 1214812</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20234015" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-4015</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-4015" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4015" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-4015" ref_url="https://www.suse.com/security/cve/CVE-2023-4015" source="SUSE CVE"/>
    <description>
    A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.

On an error when building a nftables rule, deactivating immediate expressions in nft_immediate_deactivate() can lead unbinding the chain and objects be deactivated but later used.

We recommend upgrading past commit 0a771f7b266b02d262900c75f1e175c7fe76fec2.


    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-08"/>
	<updated date="2023-09-19"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-4015/">CVE-2023-4015</cve>
	<bugzilla href="https://bugzilla.suse.com/1215104">SUSE bug 1215104</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1215106">SUSE bug 1215106</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202340791" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-40791</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-40791" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40791" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-40791" ref_url="https://www.suse.com/security/cve/CVE-2023-40791" source="SUSE CVE"/>
    <description>
    extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-10-17"/>
	<updated date="2023-10-17"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2023-40791/">CVE-2023-40791</cve>
	<bugzilla href="https://bugzilla.suse.com/1216255">SUSE bug 1216255</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20234147" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-4147</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-4147" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4147" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-4147" ref_url="https://www.suse.com/security/cve/CVE-2023-4147" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3599-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3599-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3600-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031433.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3600-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3656-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3682-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3683-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031541.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3683-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3704-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3704-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3964-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/031902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3969-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/031917.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3988-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016554.html" source="SUSE-SU"/>
    <description>
    A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-05"/>
	<updated date="2023-10-17"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-4147/">CVE-2023-4147</cve>
	<bugzilla href="https://bugzilla.suse.com/1213968">SUSE bug 1213968</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1215118">SUSE bug 1215118</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20234155" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-4155</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-4155" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4155" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-4155" ref_url="https://www.suse.com/security/cve/CVE-2023-4155" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4071-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016702.html" source="SUSE-SU"/>
    <description>
    A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the `VMGEXIT` handler recursively. If an attacker manages to call the handler multiple times, they can trigger a stack overflow and cause a denial of service or potentially guest-to-host escape in kernel configurations without stack guard pages (`CONFIG_VMAP_STACK`).
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-08"/>
	<updated date="2023-10-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-4155/">CVE-2023-4155</cve>
	<bugzilla href="https://bugzilla.suse.com/1214022">SUSE bug 1214022</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20234205" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-4205</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-4205" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4205" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-4205" ref_url="https://www.suse.com/security/cve/CVE-2023-4205" source="SUSE CVE"/>
    <description>
    ** REJECT ** This was deemed as a false positive both by the reporter and upstream kernel.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-12"/>
	<updated date="2023-08-12"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="0/CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N" href="https://www.suse.com/security/cve/CVE-2023-4205/">CVE-2023-4205</cve>
	<bugzilla href="https://bugzilla.suse.com/1214050">SUSE bug 1214050</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20234273" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-4273</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-4273" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4273" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-4273" ref_url="https://www.suse.com/security/cve/CVE-2023-4273" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3599-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3599-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3600-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031433.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3600-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3656-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3682-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3683-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031541.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3683-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3684-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016211.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3687-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016222.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3704-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3704-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3772-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016321.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3773-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016320.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3783-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016324.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3784-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016323.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3785-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016326.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3788-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016329.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3806-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016344.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3812-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016341.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3844-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016349.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3846-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016378.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3889-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016445.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3891-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016444.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3892-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016443.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3893-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016459.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3912-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016474.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3922-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016473.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3923-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016472.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3924-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016471.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3928-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016475.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3929-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016470.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3964-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/031902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3969-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/031917.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3988-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016554.html" source="SUSE-SU"/>
    <description>
    A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file name characters are copied into a stack variable, a local privileged attacker could use this flaw to overflow the kernel stack.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-10"/>
	<updated date="2023-10-17"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-4273/">CVE-2023-4273</cve>
	<bugzilla href="https://bugzilla.suse.com/1214120">SUSE bug 1214120</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1214123">SUSE bug 1214123</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202342752" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-42752</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-42752" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42752" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-42752" ref_url="https://www.suse.com/security/cve/CVE-2023-42752" source="SUSE CVE"/>
    <description>
    An integer overflow flaw was found in the Linux kernel. This issue leads to the kernel allocating `skb_shared_info` in the userspace, which is exploitable in systems without SMAP protection since `skb_shared_info` contains references to function pointers.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-20"/>
	<updated date="2023-10-13"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-42752/">CVE-2023-42752</cve>
	<bugzilla href="https://bugzilla.suse.com/1215146">SUSE bug 1215146</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1215468">SUSE bug 1215468</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202342756" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-42756</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-42756" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42756" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-42756" ref_url="https://www.suse.com/security/cve/CVE-2023-42756" source="SUSE CVE"/>
    <description>
    A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-10-09"/>
	<updated date="2023-10-09"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-42756/">CVE-2023-42756</cve>
	<bugzilla href="https://bugzilla.suse.com/1215767">SUSE bug 1215767</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20234389" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-4389</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-4389" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4389" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-4389" ref_url="https://www.suse.com/security/cve/CVE-2023-4389" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4030-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016618.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4071-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016702.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4095-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/032196.html" source="SUSE-SU"/>
    <description>
    A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked internal kernel information.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-18"/>
	<updated date="2023-10-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="5.8/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H" href="https://www.suse.com/security/cve/CVE-2023-4389/">CVE-2023-4389</cve>
	<bugzilla href="https://bugzilla.suse.com/1214351">SUSE bug 1214351</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20234394" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-4394</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-4394" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4394" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-4394" ref_url="https://www.suse.com/security/cve/CVE-2023-4394" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in btrfs_get_dev_args_from_path in fs/btrfs/volumes.c in btrfs file-system in the Linux Kernel. This flaw allows a local attacker with special privileges to cause a system crash or leak internal kernel information
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-18"/>
	<updated date="2023-08-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-4394/">CVE-2023-4394</cve>
	<bugzilla href="https://bugzilla.suse.com/1214352">SUSE bug 1214352</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202344466" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-44466</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-44466" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44466" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-44466" ref_url="https://www.suse.com/security/cve/CVE-2023-44466" source="SUSE CVE"/>
    <description>
    An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-10-04"/>
	<updated date="2023-10-04"/>
	<severity>Important</severity>
	<cve impact="important" cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-44466/">CVE-2023-44466</cve>
	<bugzilla href="https://bugzilla.suse.com/1215871">SUSE bug 1215871</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20234569" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-4569</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-4569" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4569" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-4569" ref_url="https://www.suse.com/security/cve/CVE-2023-4569" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3599-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031434.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3599-2" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-September/016283.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3600-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031433.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3600-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031622.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3656-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031498.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3682-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031542.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3683-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031541.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3683-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031627.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3704-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031565.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3704-2" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-September/031625.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3964-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/031902.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3969-1" ref_url="https://lists.suse.com/pipermail/sle-updates/2023-October/031917.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3971-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016512.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:3988-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016554.html" source="SUSE-SU"/>
    <description>
    A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause a double-deactivations of catchall elements, which results in a memory leak.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-08-30"/>
	<updated date="2023-10-17"/>
	<severity>Low</severity>
	<cve impact="low" cvss3="3.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" href="https://www.suse.com/security/cve/CVE-2023-4569/">CVE-2023-4569</cve>
	<bugzilla href="https://bugzilla.suse.com/1214729">SUSE bug 1214729</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:202345898" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-45898</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-45898" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45898" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-45898" ref_url="https://www.suse.com/security/cve/CVE-2023-45898" source="SUSE CVE"/>
    <description>
    The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-10-17"/>
	<updated date="2023-10-17"/>
	<severity>Low</severity>
	<cve impact="low" href="https://www.suse.com/security/cve/CVE-2023-45898/">CVE-2023-45898</cve>
	<bugzilla href="https://bugzilla.suse.com/1216262">SUSE bug 1216262</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20234611" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-4611</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-4611" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4611" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-4611" ref_url="https://www.suse.com/security/cve/CVE-2023-4611" source="SUSE CVE"/>
    <description>
    A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-08"/>
	<updated date="2023-09-08"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-4611/">CVE-2023-4611</cve>
	<bugzilla href="https://bugzilla.suse.com/1214772">SUSE bug 1214772</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20234732" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-4732</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-4732" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4732" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-4732" ref_url="https://www.suse.com/security/cve/CVE-2023-4732" source="SUSE CVE"/>
    <description>
    A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG statement referencing pmd_t x.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-12"/>
	<updated date="2023-10-05"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="4.7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-4732/">CVE-2023-4732</cve>
	<bugzilla href="https://bugzilla.suse.com/1214926">SUSE bug 1214926</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20235158" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-5158</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-5158" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5158" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-5158" ref_url="https://www.suse.com/security/cve/CVE-2023-5158" source="SUSE CVE"/>
    <description>
    A flaw was found in vringh_kiov_advance in drivers/vhost/vringh.c in the host side of a virtio ring in the Linux Kernel. This issue may result in a denial of service from guest to host via zero length descriptor.
    </description>
<advisory from="security@suse.de">
	<issued date="2023-09-27"/>
	<updated date="2023-09-27"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="6.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" href="https://www.suse.com/security/cve/CVE-2023-5158/">CVE-2023-5158</cve>
	<bugzilla href="https://bugzilla.suse.com/1215710">SUSE bug 1215710</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
<definition id="oval:org.opensuse.security:def:20235345" version="1" class="vulnerability">
 <metadata>
 <title>CVE-2023-5345</title>
    <affected family="unix">
            <platform>SUSE Linux Enterprise Micro 5.0</platform>
    </affected>
    <reference ref_id="Mitre CVE-2023-5345" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5345" source="CVE"/>
    <reference ref_id="SUSE CVE-2023-5345" ref_url="https://www.suse.com/security/cve/CVE-2023-5345" source="SUSE CVE"/>
		<reference ref_id="SUSE-IU-2023:731-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016689.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:732-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016690.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-IU-2023:733-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016691.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4035-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016616.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4057-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016648.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4058-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016647.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4071-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016678.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4072-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016677.html" source="SUSE-SU"/>
		<reference ref_id="SUSE-SU-2023:4093-1" ref_url="https://lists.suse.com/pipermail/sle-security-updates/2023-October/016702.html" source="SUSE-SU"/>
    <description>
    A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation.

In case of an error in smb3_fs_context_parse_param, ctx-&gt;password was freed but the field was not set to NULL which could lead to double free.

We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705.


    </description>
<advisory from="security@suse.de">
	<issued date="2023-10-04"/>
	<updated date="2023-10-18"/>
	<severity>Moderate</severity>
	<cve impact="moderate" cvss3="7/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" href="https://www.suse.com/security/cve/CVE-2023-5345/">CVE-2023-5345</cve>
	<bugzilla href="https://bugzilla.suse.com/1215899">SUSE bug 1215899</bugzilla>
	<bugzilla href="https://bugzilla.suse.com/1215971">SUSE bug 1215971</bugzilla>
	<affected_cpe_list>
		<cpe>cpe:/o:suse:suse-microos:5.0</cpe>
	</affected_cpe_list>
</advisory>
 </metadata>
		<criteria operator="AND">
			<criterion test_ref="oval:org.opensuse.security:tst:2009704855" comment="SUSE Linux Enterprise Micro 5.0 is installed"/>
				<criterion test_ref="oval:org.opensuse.security:tst:2009334017" comment="kernel-default is not affected"/>
		</criteria>
</definition>
</definitions>
<tests>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334017" version="1" comment="kernel-default is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704855" version="1" comment="SUSE-MicroOS-release is ==5.0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059372"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167699"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009732558" version="1" comment="rpcbind is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038994"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009333942" version="1" comment="openssl is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030588"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334866" version="1" comment="libopenssl1_1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042548"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009333944" version="1" comment="openssl-1_1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042550"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667767" version="1" comment="nfs-client is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034590"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667769" version="1" comment="nfs-kernel-server is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034592"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009333977" version="1" comment="curl is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030596"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335173" version="1" comment="libcurl4 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030964"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705046" version="1" comment="kernel-rt is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009333996" version="1" comment="openssh is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030403"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760817" version="1" comment="libnm0 is &lt;1.22.10-3.3.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041030"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180708"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760818" version="1" comment="typelib-1_0-NM-1_0 is &lt;1.22.10-3.3.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180708"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481533" version="1" comment="libvorbis0 is &lt;1.3.6-4.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034804"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111799"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481534" version="1" comment="libvorbisenc2 is &lt;1.3.6-4.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034806"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111799"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009337751" version="1" comment="libxml2-2 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035409"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009337752" version="1" comment="libxml2-tools is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035414"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760864" version="1" comment="vim-data-common is &lt;8.0.1568-5.11.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180734"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760865" version="1" comment="vim-small is &lt;8.0.1568-5.11.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052260"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180734"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481128" version="1" comment="fuse is &lt;2.9.7-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033599"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111729"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481131" version="1" comment="libfuse2 is &lt;2.9.7-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033600"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111729"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480757" version="1" comment="libthai-data is &lt;0.1.27-1.16" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041085"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480758" version="1" comment="libthai0 is &lt;0.1.27-1.16" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041086"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760786" version="1" comment="glibc is &lt;2.26-13.51.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031926"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180695"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760787" version="1" comment="glibc-locale is &lt;2.26-13.51.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031925"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180695"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760788" version="1" comment="glibc-locale-base is &lt;2.26-13.51.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047237"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180695"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481663" version="1" comment="tar is &lt;1.30-3.3.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030401"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111843"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480190" version="1" comment="dbus-1-glib is &lt;0.108-1.29" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111455"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334290" version="1" comment="sudo is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481596" version="1" comment="logrotate is &lt;3.13.0-4.3.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034546"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111810"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480325" version="1" comment="hardlink is &lt;1.0+git.e66999f-1.25" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040987"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480071" version="1" comment="augeas is &lt;1.10.1-1.11" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111426"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480073" version="1" comment="augeas-lenses is &lt;1.10.1-1.11" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038073"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111426"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480074" version="1" comment="libaugeas0 is &lt;1.10.1-1.11" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038075"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111426"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481944" version="1" comment="libexpat1 is &lt;2.2.5-3.6.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111899"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480927" version="1" comment="squashfs is &lt;4.3-1.29" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041022"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111664"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482387" version="1" comment="libruby2_5-2_5 is &lt;2.5.8-4.11.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047596"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111981"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482388" version="1" comment="ruby2.5 is &lt;2.5.8-4.11.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111981"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482391" version="1" comment="ruby2.5-stdlib is &lt;2.5.8-4.11.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047600"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111981"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480143" version="1" comment="coreutils is &lt;8.29-2.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111443"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480415" version="1" comment="libXext6 is &lt;1.3.3-1.30" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036075"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111512"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480433" version="1" comment="libXrender1 is &lt;0.9.10-1.30" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111520"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480441" version="1" comment="libXv1 is &lt;1.0.11-1.23" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036115"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111523"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760869" version="1" comment="xen-libs is &lt;4.13.2_06-3.22.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180737"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760828" version="1" comment="libspice-server1 is &lt;0.14.2-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180714"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334933" version="1" comment="libvirt-daemon is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334936" version="1" comment="libvirt-daemon-driver-interface is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037566"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334939" version="1" comment="libvirt-daemon-driver-network is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037568"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334940" version="1" comment="libvirt-daemon-driver-nodedev is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037569"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334941" version="1" comment="libvirt-daemon-driver-nwfilter is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334942" version="1" comment="libvirt-daemon-driver-qemu is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334943" version="1" comment="libvirt-daemon-driver-secret is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037572"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334944" version="1" comment="libvirt-daemon-driver-storage is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037573"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336191" version="1" comment="libvirt-daemon-driver-storage-core is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336192" version="1" comment="libvirt-daemon-driver-storage-disk is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041753"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336193" version="1" comment="libvirt-daemon-driver-storage-iscsi is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336194" version="1" comment="libvirt-daemon-driver-storage-logical is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336195" version="1" comment="libvirt-daemon-driver-storage-mpath is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336196" version="1" comment="libvirt-daemon-driver-storage-rbd is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041757"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336197" version="1" comment="libvirt-daemon-driver-storage-scsi is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041758"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334946" version="1" comment="libvirt-daemon-qemu is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037577"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336198" version="1" comment="libvirt-libs is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041759"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480594" version="1" comment="libjson-c3 is &lt;0.13-1.19" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042541"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111550"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480828" version="1" comment="libyaml-0-2 is &lt;0.1.7-1.17" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111613"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711319" version="1" comment="kernel-default is ==3.12.38-44.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169740"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711320" version="1" comment="kgraft-patch-3_12_38-44-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038577"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711323" version="1" comment="kernel-default is ==3.12.39-47.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169743"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711324" version="1" comment="kgraft-patch-3_12_39-47-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038604"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711326" version="1" comment="kernel-default is ==3.12.43-52.6.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169744"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711327" version="1" comment="kgraft-patch-3_12_43-52_6-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038757"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711329" version="1" comment="kernel-default is ==3.12.44-52.10.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169745"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711330" version="1" comment="kgraft-patch-3_12_44-52_10-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038814"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711332" version="1" comment="kernel-default is ==3.12.44-52.18.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169747"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711333" version="1" comment="kgraft-patch-3_12_44-52_18-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038981"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711335" version="1" comment="kernel-default is ==3.12.48-52.27.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169748"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711336" version="1" comment="kgraft-patch-3_12_48-52_27-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038995"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714891" version="1" comment="kernel-default is ==3.12.49-11.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170444"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711338" version="1" comment="kgraft-patch-3_12_49-11-default is &gt;=5-14.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039764"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169750"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711340" version="1" comment="kernel-default is ==3.12.51-52.31.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169751"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711341" version="1" comment="kgraft-patch-3_12_51-52_31-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039432"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711343" version="1" comment="kernel-default is ==3.12.51-52.34.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169752"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711344" version="1" comment="kgraft-patch-3_12_51-52_34-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039760"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711346" version="1" comment="kernel-default is ==3.12.51-52.39.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169753"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711347" version="1" comment="kgraft-patch-3_12_51-52_39-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039793"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711349" version="1" comment="kernel-default is ==3.12.51-60.20.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169754"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711350" version="1" comment="kgraft-patch-3_12_51-60_20-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039537"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711352" version="1" comment="kernel-default is ==3.12.51-60.25.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169755"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711353" version="1" comment="kgraft-patch-3_12_51-60_25-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711355" version="1" comment="kernel-default is ==3.12.53-60.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169756"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711356" version="1" comment="kgraft-patch-3_12_53-60_30-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039845"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711358" version="1" comment="kernel-default is ==3.12.57-60.35.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711359" version="1" comment="kgraft-patch-3_12_57-60_35-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711361" version="1" comment="kernel-default is ==3.12.59-60.41.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169759"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711362" version="1" comment="kgraft-patch-3_12_59-60_41-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711364" version="1" comment="kernel-default is ==3.12.59-60.45.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169760"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711365" version="1" comment="kgraft-patch-3_12_59-60_45-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009129402" version="1" comment="kernel-default is &lt;3.12.59-60.45.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009047758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481633" version="1" comment="python3-Jinja2 is &lt;2.10.1-3.5.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042709"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111824"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628925" version="1" comment="libxml2-2 is &lt;2.9.7-3.28.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035409"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148189"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628928" version="1" comment="libxml2-tools is &lt;2.9.7-3.28.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035414"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148189"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760852" version="1" comment="qemu is &lt;4.2.1-11.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180728"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760853" version="1" comment="qemu-arm is &lt;4.2.1-11.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038462"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180728"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760854" version="1" comment="qemu-ipxe is &lt;1.0.0+-11.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037631"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180729"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760855" version="1" comment="qemu-ppc is &lt;4.2.1-11.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038466"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180728"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760856" version="1" comment="qemu-s390 is &lt;4.2.1-11.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038467"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180728"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760857" version="1" comment="qemu-seabios is &lt;1.12.1+-11.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037633"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180730"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760858" version="1" comment="qemu-sgabios is &lt;8-11.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180731"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760859" version="1" comment="qemu-tools is &lt;4.2.1-11.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036248"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180728"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760860" version="1" comment="qemu-vgabios is &lt;1.12.1+-11.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037635"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180730"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760861" version="1" comment="qemu-x86 is &lt;4.2.1-11.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180728"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628729" version="1" comment="libfreebl3 is &lt;3.53.1-3.51.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148142"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628731" version="1" comment="libsoftokn3 is &lt;3.53.1-3.51.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148142"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628733" version="1" comment="mozilla-nss is &lt;3.53.1-3.51.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032440"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148142"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628735" version="1" comment="mozilla-nss-certs is &lt;3.53.1-3.51.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033978"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148142"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628448" version="1" comment="libfreetype6 is &lt;2.10.1-4.8.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033880"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148109"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760819" version="1" comment="libopenssl1_1 is &lt;1.1.1d-11.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042548"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180709"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482336" version="1" comment="openssl is &lt;1.1.1d-1.46" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030588"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111967"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760820" version="1" comment="openssl-1_1 is &lt;1.1.1d-11.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042550"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180709"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482233" version="1" comment="libgcrypt20 is &lt;1.8.2-8.36.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038771"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111939"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481908" version="1" comment="dbus-1 is &lt;1.12.2-8.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111893"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481911" version="1" comment="libdbus-1-3 is &lt;1.12.2-8.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111893"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760862" version="1" comment="shim is &lt;15+git47-3.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038277"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180732"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760868" version="1" comment="wpa_supplicant is &lt;2.9-4.23.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034744"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180736"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711368" version="1" comment="kernel-default is ==3.12.32-33.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169762"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711369" version="1" comment="kgraft-patch-3_12_32-33-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038950"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009105317" version="1" comment="kernel-default is &lt;3.12.32-33.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009044422"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628435" version="1" comment="file is &lt;5.32-7.11.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030456"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148106"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628437" version="1" comment="file-magic is &lt;5.32-7.11.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037852"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148106"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628438" version="1" comment="libmagic1 is &lt;5.32-7.11.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037850"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148106"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760847" version="1" comment="powerpc-utils is &lt;1.3.7.1-3.27.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038161"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180725"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480611" version="1" comment="liblzo2-2 is &lt;2.10-2.22" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038032"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111555"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760824" version="1" comment="libpython3_6m1_0 is &lt;3.6.12-3.75.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042555"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180712"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760825" version="1" comment="python3 is &lt;3.6.12-3.75.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037061"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180712"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760826" version="1" comment="python3-base is &lt;3.6.12-3.75.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036916"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180712"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009678603" version="1" comment="liblz4-1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009629068" version="1" comment="docker is &lt;19.03.15_ce-6.46.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038208"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148262"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628540" version="1" comment="krb5 is &lt;1.16.3-3.15.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031044"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148131"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480525" version="1" comment="libevent-2_1-8 is &lt;2.1.8-2.23" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042533"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111534"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628931" version="1" comment="libzmq5 is &lt;4.2.3-3.15.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042706"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148191"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711371" version="1" comment="kernel-default is ==3.12.36-38.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169763"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711372" version="1" comment="kgraft-patch-3_12_36-38-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009105748" version="1" comment="kernel-default is &lt;3.12.36-38.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009044478"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760835" version="1" comment="libvirt-libs is &lt;6.0.0-13.8.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041759"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180717"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482409" version="1" comment="libssh4 is &lt;0.8.7-10.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035367"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111987"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760774" version="1" comment="curl is &lt;7.66.0-4.11.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030596"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180690"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760775" version="1" comment="libcurl4 is &lt;7.66.0-4.11.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030964"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180690"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711374" version="1" comment="kgraft-patch-3_12_38-44-default is &gt;=2-7.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038577"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169764"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711376" version="1" comment="kgraft-patch-3_12_39-47-default is &gt;=2-10.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038604"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169765"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009108369" version="1" comment="kernel-default is &lt;3.12.39-47.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009044800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482539" version="1" comment="rsync is &lt;3.1.3-4.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030761"/>
		<state state_ref="oval:org.opensuse.security:ste:2009112044"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760814" version="1" comment="libgnutls30 is &lt;3.6.7-14.7.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042507"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180706"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480657" version="1" comment="libpcre1 is &lt;8.41-4.20" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038688"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111570"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480667" version="1" comment="libpcre2-8-0 is &lt;10.31-1.14" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040850"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111571"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480597" version="1" comment="libksba8 is &lt;1.3.5-2.14" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038301"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111551"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628779" version="1" comment="libjpeg8 is &lt;8.1.2-5.15.7" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038279"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148151"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481843" version="1" comment="cpio is &lt;2.12-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030506"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111884"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760806" version="1" comment="libblkid1 is &lt;2.33.1-4.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031455"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180703"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760807" version="1" comment="libfdisk1 is &lt;2.33.1-4.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040900"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180703"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760808" version="1" comment="libmount1 is &lt;2.33.1-4.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038354"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180703"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760809" version="1" comment="libsmartcols1 is &lt;2.33.1-4.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038362"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180703"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760810" version="1" comment="libuuid1 is &lt;2.33.1-4.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031465"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180703"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760811" version="1" comment="util-linux is &lt;2.33.1-4.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180703"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760812" version="1" comment="util-linux-systemd is &lt;2.33.1-4.13.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038357"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180704"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481929" version="1" comment="elfutils is &lt;0.168-4.5.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038055"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111898"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481932" version="1" comment="libasm1 is &lt;0.168-4.5.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038057"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111898"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481934" version="1" comment="libdw1 is &lt;0.168-4.5.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038060"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111898"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481937" version="1" comment="libebl-plugins is &lt;0.168-4.5.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042483"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111898"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481940" version="1" comment="libelf1 is &lt;0.168-4.5.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038067"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111898"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480353" version="1" comment="less is &lt;530-1.6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038591"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482310" version="1" comment="libmspack0 is &lt;0.6-3.8.19" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760863" version="1" comment="sudo is &lt;1.8.22-4.15.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180733"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009337724" version="1" comment="libpixman-1-0 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037297"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760777" version="1" comment="e2fsprogs is &lt;1.43.8-4.23.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180692"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760778" version="1" comment="libcom_err2 is &lt;1.43.8-4.23.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031459"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180692"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760779" version="1" comment="libext2fs2 is &lt;1.43.8-4.23.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031461"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180692"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480953" version="1" comment="update-alternatives is &lt;1.19.0.4-2.48" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036437"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111680"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482006" version="1" comment="grep is &lt;3.1-4.3.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032486"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111912"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711378" version="1" comment="kgraft-patch-3_12_32-33-default is &gt;=2-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038950"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169766"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711380" version="1" comment="kgraft-patch-3_12_36-38-default is &gt;=2-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169766"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760815" version="1" comment="libldap-2_4-2 is &lt;2.4.46-9.45.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180707"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760816" version="1" comment="libldap-data is &lt;2.4.46-9.45.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041076"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180707"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628874" version="1" comment="libssh2-1 is &lt;1.9.0-4.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038580"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148177"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711382" version="1" comment="kgraft-patch-3_12_43-52_6-default is &gt;=2-6.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038757"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169767"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009110507" version="1" comment="kernel-default is &lt;3.12.43-52.6.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009045120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009342637" version="1" comment="chrony is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041095"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009348255" version="1" comment="chrony-pool-suse is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049458"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482248" version="1" comment="libidn11 is &lt;1.34-3.2.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038785"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111945"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628747" version="1" comment="libidn2-0 is &lt;2.2.0-3.6.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041929"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148146"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482524" version="1" comment="python3-requests is &lt;2.20.1-6.6.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041052"/>
		<state state_ref="oval:org.opensuse.security:ste:2009112037"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482427" version="1" comment="libtasn1 is &lt;4.13-4.5.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038046"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111991"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482428" version="1" comment="libtasn1-6 is &lt;4.13-4.5.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038681"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111991"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711384" version="1" comment="kgraft-patch-3_12_32-33-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038950"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711386" version="1" comment="kgraft-patch-3_12_36-38-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711388" version="1" comment="kgraft-patch-3_12_38-44-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038577"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711390" version="1" comment="kgraft-patch-3_12_39-47-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038604"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711392" version="1" comment="kgraft-patch-3_12_43-52_6-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038757"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711394" version="1" comment="kgraft-patch-3_12_44-52_10-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038814"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711396" version="1" comment="kgraft-patch-3_12_44-52_18-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038981"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711398" version="1" comment="kgraft-patch-3_12_48-52_27-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038995"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711400" version="1" comment="kgraft-patch-3_12_49-11-default is &gt;=2-5.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039764"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169768"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009141891" version="1" comment="kernel-default is &lt;3.12.49-11.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009050202"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009654598" version="1" comment="libpcre2-8-0 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040850"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482356" version="1" comment="libpolkit0 is &lt;0.116-1.51" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111974"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482357" version="1" comment="polkit is &lt;0.116-1.51" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111974"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628960" version="1" comment="pam is &lt;1.3.0-6.29.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032521"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148202"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760834" version="1" comment="libunwind is &lt;1.2.1-4.2.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038780"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180716"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009624167" version="1" comment="libsqlite3-0 is &lt;3.36.0-3.12.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040582"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147219"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335190" version="1" comment="libsqlite3-0 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040582"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334819" version="1" comment="xen-libs is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760804" version="1" comment="libaudit1 is &lt;2.8.1-12.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042523"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180702"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760805" version="1" comment="libauparse0 is &lt;2.8.1-12.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042525"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180702"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760836" version="1" comment="libvmtools0 is &lt;11.2.5-4.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034560"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180718"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760837" version="1" comment="open-vm-tools is &lt;11.2.5-4.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034562"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180718"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335684" version="1" comment="librados2 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041228"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335686" version="1" comment="librbd1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041232"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711402" version="1" comment="kgraft-patch-3_12_32-33-default is &gt;=4-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038950"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169769"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711404" version="1" comment="kgraft-patch-3_12_36-38-default is &gt;=4-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169769"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711406" version="1" comment="kgraft-patch-3_12_38-44-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038577"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711408" version="1" comment="kgraft-patch-3_12_39-47-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038604"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711410" version="1" comment="kgraft-patch-3_12_43-52_6-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038757"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711412" version="1" comment="kgraft-patch-3_12_44-52_10-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038814"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711414" version="1" comment="kgraft-patch-3_12_44-52_18-default is &gt;=2-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038981"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169770"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009114432" version="1" comment="kernel-default is &lt;3.12.44-52.18.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009045676"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009654580" version="1" comment="libevent-2_1-8 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042533"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760840" version="1" comment="mozilla-nspr is &lt;4.25.1-3.15.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032358"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180721"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482535" version="1" comment="rpcbind is &lt;0.2.3-5.9.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038994"/>
		<state state_ref="oval:org.opensuse.security:ste:2009112042"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760829" version="1" comment="libsystemd0 is &lt;246.10-2.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041083"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180715"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760830" version="1" comment="libudev1 is &lt;246.10-2.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037378"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180715"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760831" version="1" comment="systemd is &lt;246.10-2.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036874"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180715"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760832" version="1" comment="systemd-sysvinit is &lt;246.10-2.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036879"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180715"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760833" version="1" comment="udev is &lt;246.10-2.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031048"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180715"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482467" version="1" comment="libxslt1 is &lt;1.1.32-3.8.24" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035829"/>
		<state state_ref="oval:org.opensuse.security:ste:2009112006"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009121536" version="1" comment="kernel-default is &lt;3.12.51-60.25.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009046807"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482352" version="1" comment="libpng16-16 is &lt;1.6.34-3.9.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037593"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111973"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760841" version="1" comment="openssh is &lt;8.1p1-5.12.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030403"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180722"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760789" version="1" comment="grub2 is &lt;2.04-9.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039506"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180696"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760790" version="1" comment="grub2-arm64-efi is &lt;2.04-9.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041109"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180696"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760791" version="1" comment="grub2-i386-pc is &lt;2.04-9.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039507"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180696"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760792" version="1" comment="grub2-powerpc-ieee1275 is &lt;2.04-9.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180696"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760793" version="1" comment="grub2-s390x-emu is &lt;2.04-9.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039513"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180696"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760794" version="1" comment="grub2-snapper-plugin is &lt;2.04-9.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180696"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760795" version="1" comment="grub2-x86_64-efi is &lt;2.04-9.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180696"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760796" version="1" comment="grub2-x86_64-xen is &lt;2.04-9.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180696"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711416" version="1" comment="kgraft-patch-3_12_51-52_31-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039432"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711418" version="1" comment="kgraft-patch-3_12_51-60_20-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039537"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009118983" version="1" comment="kernel-default is &lt;3.12.51-60.20.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009046552"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711420" version="1" comment="kgraft-patch-3_12_49-11-default is &gt;=3-8.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039764"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169771"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711422" version="1" comment="kgraft-patch-3_12_51-60_20-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039537"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711424" version="1" comment="kgraft-patch-3_12_51-60_25-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711426" version="1" comment="kgraft-patch-3_12_39-47-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038604"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711428" version="1" comment="kgraft-patch-3_12_43-52_6-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038757"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711430" version="1" comment="kgraft-patch-3_12_44-52_10-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038814"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711432" version="1" comment="kgraft-patch-3_12_44-52_18-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038981"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711434" version="1" comment="kgraft-patch-3_12_48-52_27-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038995"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711436" version="1" comment="kgraft-patch-3_12_49-11-default is &gt;=4-11.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039764"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169772"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711438" version="1" comment="kgraft-patch-3_12_51-52_31-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039432"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711440" version="1" comment="kgraft-patch-3_12_51-52_34-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039760"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711442" version="1" comment="kgraft-patch-3_12_51-52_39-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039793"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711444" version="1" comment="kgraft-patch-3_12_51-60_20-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039537"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711446" version="1" comment="kgraft-patch-3_12_51-60_25-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711448" version="1" comment="kgraft-patch-3_12_53-60_30-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039845"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009123221" version="1" comment="kernel-default is &lt;3.12.53-60.30.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009047048"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482241" version="1" comment="libhogweed4 is &lt;3.4.1-4.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042537"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111943"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482244" version="1" comment="libnettle6 is &lt;3.4.1-4.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042538"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111943"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009333938" version="1" comment="glibc is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031926"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334828" version="1" comment="glibc-locale is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031925"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009339499" version="1" comment="glibc-locale-base is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047237"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009669024" version="1" comment="glibc is &lt;2.26-13.65.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031926"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009669032" version="1" comment="glibc-locale is &lt;2.26-13.65.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031925"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009669033" version="1" comment="glibc-locale-base is &lt;2.26-13.65.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047237"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336128" version="1" comment="libfreetype6 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033880"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711450" version="1" comment="kgraft-patch-3_12_51-52_34-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039760"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711452" version="1" comment="kernel-default is ==4.4.21-69.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169773"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711453" version="1" comment="kgraft-patch-4_4_21-69-default is &gt;=3-8.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169771"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711454" version="1" comment="kernel-default is ==4.4.21-81.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169774"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711455" version="1" comment="kgraft-patch-4_4_21-81-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711456" version="1" comment="kernel-default is ==4.4.21-84.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169775"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711457" version="1" comment="kgraft-patch-4_4_21-84-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040921"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711458" version="1" comment="kernel-default is ==4.4.21-90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169776"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711459" version="1" comment="kgraft-patch-4_4_21-90-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041143"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711460" version="1" comment="kernel-default is ==4.4.38-93.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169777"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711461" version="1" comment="kgraft-patch-4_4_38-93-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041387"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009147227" version="1" comment="kernel-default is &lt;4.4.38-93.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009050993"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482016" version="1" comment="gstreamer is &lt;1.16.2-1.53" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041486"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111914"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482018" version="1" comment="libgstreamer-1_0-0 is &lt;1.16.2-1.53" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111914"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009488549" version="1" comment="libvirglrenderer0 is &lt;0.6.0-4.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009115626"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704997" version="1" comment="glibc is &lt;2.26-13.62.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031926"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167755"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704998" version="1" comment="glibc-locale is &lt;2.26-13.62.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031925"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167755"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704999" version="1" comment="glibc-locale-base is &lt;2.26-13.62.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047237"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167755"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334114" version="1" comment="perl is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030410"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336057" version="1" comment="perl-base is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031056"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480302" version="1" comment="libgraphite2-3 is &lt;1.3.11-2.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039086"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111482"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482322" version="1" comment="libnghttp2-14 is &lt;1.40.0-1.15" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040283"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111964"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628349" version="1" comment="chrony is &lt;3.2-9.18.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041095"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148090"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628351" version="1" comment="chrony-pool-suse is &lt;3.2-9.18.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049458"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148090"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009125799" version="1" comment="kernel-default is &lt;3.12.57-60.35.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009047354"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760848" version="1" comment="python3-salt is &lt;3000-24.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042407"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180726"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760849" version="1" comment="salt is &lt;3000-24.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040290"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180726"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760850" version="1" comment="salt-minion is &lt;3000-24.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040297"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180726"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481775" version="1" comment="libbz2-1 is &lt;1.0.6-5.9.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031657"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111876"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009655181" version="1" comment="dosfstools is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032484"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482486" version="1" comment="openslp is &lt;2.0.0-6.12.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033994"/>
		<state state_ref="oval:org.opensuse.security:ste:2009112015"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711462" version="1" comment="kgraft-patch-3_12_49-11-default is &gt;=6-17.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039764"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169778"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711464" version="1" comment="kgraft-patch-3_12_51-60_20-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039537"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711466" version="1" comment="kgraft-patch-3_12_51-60_25-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711468" version="1" comment="kgraft-patch-3_12_53-60_30-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039845"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711470" version="1" comment="kgraft-patch-3_12_57-60_35-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711472" version="1" comment="kgraft-patch-3_12_59-60_41-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009129344" version="1" comment="kernel-default is &lt;3.12.59-60.41.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009047745"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711474" version="1" comment="kgraft-patch-3_12_49-11-default is &gt;=7-20.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039764"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169779"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711476" version="1" comment="kgraft-patch-3_12_51-60_20-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039537"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711478" version="1" comment="kgraft-patch-3_12_51-60_25-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711480" version="1" comment="kgraft-patch-3_12_53-60_30-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039845"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711482" version="1" comment="kgraft-patch-3_12_57-60_35-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711484" version="1" comment="kgraft-patch-3_12_59-60_41-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711486" version="1" comment="kgraft-patch-3_12_59-60_45-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711488" version="1" comment="kernel-default is ==3.12.62-60.62.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169781"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711489" version="1" comment="kgraft-patch-3_12_62-60_62-default is &gt;=3-5.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040636"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169782"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009131004" version="1" comment="kernel-default is &lt;3.12.62-60.62.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009047935"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481122" version="1" comment="firewalld is &lt;0.5.5-4.24.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042486"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111727"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481124" version="1" comment="python3-firewall is &lt;0.5.5-4.24.9" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042488"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111727"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760797" version="1" comment="kdump is &lt;0.9.0-11.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180697"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711491" version="1" comment="kgraft-patch-3_12_59-60_45-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628370" version="1" comment="cracklib is &lt;2.9.7-11.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040610"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148095"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628372" version="1" comment="cracklib-dict-small is &lt;2.9.7-11.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040611"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148095"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628373" version="1" comment="libcrack2 is &lt;2.9.7-11.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040619"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148095"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711493" version="1" comment="kgraft-patch-3_12_62-60_62-default is &gt;=2-9.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040636"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169783"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711495" version="1" comment="kernel-default is ==3.12.62-60.64.8.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169784"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711496" version="1" comment="kgraft-patch-3_12_62-60_64_8-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009131270" version="1" comment="kernel-default is &lt;3.12.62-60.64.8.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009047945"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711498" version="1" comment="kgraft-patch-3_12_49-11-default is &gt;=8-23.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039764"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169785"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711500" version="1" comment="kgraft-patch-3_12_51-60_20-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039537"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711502" version="1" comment="kgraft-patch-3_12_51-60_25-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711504" version="1" comment="kgraft-patch-3_12_53-60_30-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039845"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711506" version="1" comment="kgraft-patch-3_12_57-60_35-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760844" version="1" comment="policycoreutils is &lt;3.1-1.25" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041418"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180724"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760845" version="1" comment="policycoreutils-python-utils is &lt;3.1-1.25" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009053613"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180724"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760846" version="1" comment="python3-policycoreutils is &lt;3.1-1.25" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047412"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180724"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336474" version="1" comment="libbluetooth3 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041999"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711508" version="1" comment="kgraft-patch-3_12_51-60_25-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711510" version="1" comment="kgraft-patch-3_12_53-60_30-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039845"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711512" version="1" comment="kgraft-patch-3_12_57-60_35-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711514" version="1" comment="kgraft-patch-3_12_59-60_41-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711516" version="1" comment="kgraft-patch-3_12_59-60_45-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711518" version="1" comment="kgraft-patch-3_12_62-60_62-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040636"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711520" version="1" comment="kgraft-patch-3_12_62-60_64_8-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711522" version="1" comment="kernel-default is ==3.12.67-60.64.18.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169786"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711523" version="1" comment="kgraft-patch-3_12_67-60_64_18-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040879"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715596" version="1" comment="kernel-default is &lt;4.4.21-81.3" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170603"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760776" version="1" comment="dracut is &lt;049.1+suse.186.g320cc3d1-1.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180691"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711525" version="1" comment="kgraft-patch-3_12_59-60_41-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711527" version="1" comment="kgraft-patch-3_12_59-60_45-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711529" version="1" comment="kgraft-patch-3_12_62-60_62-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040636"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711531" version="1" comment="kgraft-patch-3_12_62-60_64_8-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711533" version="1" comment="kgraft-patch-3_12_67-60_64_18-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040879"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711535" version="1" comment="kgraft-patch-4_4_21-69-default is &gt;=2-5.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169768"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711536" version="1" comment="kgraft-patch-4_4_21-81-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760851" version="1" comment="python3-urllib3 is &lt;1.24-9.10.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180727"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481783" version="1" comment="libcairo2 is &lt;1.16.0-1.55" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040390"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111878"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481750" version="1" comment="bash is &lt;4.4-9.10.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111870"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481754" version="1" comment="libreadline7 is &lt;7.0-9.10.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042463"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111871"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711537" version="1" comment="kernel-default is ==3.12.67-60.64.21.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169787"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711538" version="1" comment="kgraft-patch-3_12_67-60_64_21-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040918"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009136647" version="1" comment="kernel-default is &lt;4.4.21-84.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009048707"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760813" version="1" comment="libbluetooth3 is &lt;5.48-13.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041999"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180705"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760838" version="1" comment="libz1 is &lt;1.2.11-3.18.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041210"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180719"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009629067" version="1" comment="containerd is &lt;1.3.9-5.29.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148261"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009629072" version="1" comment="docker-runc is &lt;1.0.0rc10+gitr3981_dc9208a3303f-6.45.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042189"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148264"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482602" version="1" comment="runc is &lt;1.0.0~rc10-1.9.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040911"/>
		<state state_ref="oval:org.opensuse.security:ste:2009112087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628819" version="1" comment="libopus0 is &lt;1.3.1-3.6.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041430"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148162"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009654583" version="1" comment="libnl-config is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050145"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009654584" version="1" comment="libnl3-200 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050144"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711540" version="1" comment="kernel-default is ==4.4.103-6.33.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169788"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711541" version="1" comment="kgraft-patch-4_4_103-6_33-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711542" version="1" comment="kernel-default is ==4.4.103-6.38.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169790"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711543" version="1" comment="kgraft-patch-4_4_103-6_38-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042107"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711544" version="1" comment="kernel-default is ==4.4.82-6.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169791"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711545" version="1" comment="kgraft-patch-4_4_82-6_3-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041885"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711546" version="1" comment="kernel-default is ==4.4.82-6.6.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169793"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711547" version="1" comment="kgraft-patch-4_4_82-6_6-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041959"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711548" version="1" comment="kernel-default is ==4.4.82-6.9.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169795"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711549" version="1" comment="kgraft-patch-4_4_82-6_9-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711550" version="1" comment="kernel-default is ==4.4.92-6.18.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169796"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711551" version="1" comment="kgraft-patch-4_4_92-6_18-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711552" version="1" comment="kernel-default is ==4.4.92-6.30.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169798"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711553" version="1" comment="kgraft-patch-4_4_92-6_30-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009167761" version="1" comment="kernel-default is &lt;4.4.92-6.30.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009053338"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711554" version="1" comment="kgraft-patch-4_4_21-69-default is &gt;=9-18.10.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169799"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711555" version="1" comment="kgraft-patch-4_4_21-81-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711556" version="1" comment="kgraft-patch-4_4_21-84-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040921"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711557" version="1" comment="kgraft-patch-4_4_21-90-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041143"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711558" version="1" comment="kgraft-patch-4_4_38-93-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041387"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711559" version="1" comment="kernel-default is ==4.4.49-92.11.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169801"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711560" version="1" comment="kgraft-patch-4_4_49-92_11-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041484"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711561" version="1" comment="kernel-default is ==4.4.49-92.14.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169802"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711562" version="1" comment="kgraft-patch-4_4_49-92_14-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041522"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711563" version="1" comment="kernel-default is ==4.4.59-92.17.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169803"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711564" version="1" comment="kgraft-patch-4_4_59-92_17-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711565" version="1" comment="kernel-default is ==4.4.59-92.20.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169804"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711566" version="1" comment="kgraft-patch-4_4_59-92_20-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041642"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711567" version="1" comment="kernel-default is ==4.4.59-92.24.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169805"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711568" version="1" comment="kgraft-patch-4_4_59-92_24-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041661"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711569" version="1" comment="kernel-default is ==4.4.74-92.29.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169806"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711570" version="1" comment="kgraft-patch-4_4_74-92_29-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041737"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711571" version="1" comment="kernel-default is ==4.4.74-92.32.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169807"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711572" version="1" comment="kgraft-patch-4_4_74-92_32-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041816"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711573" version="1" comment="kernel-default is ==4.4.74-92.35.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169808"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711574" version="1" comment="kgraft-patch-4_4_74-92_35-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041849"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711575" version="1" comment="kernel-default is ==4.4.74-92.38.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169809"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711576" version="1" comment="kgraft-patch-4_4_74-92_38-default is &gt;=2-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041957"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169770"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009164286" version="1" comment="kernel-default is &lt;4.4.74-92.38.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009052944"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711577" version="1" comment="kgraft-patch-4_4_21-69-default is &gt;=10-18.13.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169810"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711578" version="1" comment="kgraft-patch-4_4_21-81-default is &gt;=10-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169811"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711579" version="1" comment="kgraft-patch-4_4_21-84-default is &gt;=9-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040921"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169812"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711580" version="1" comment="kgraft-patch-4_4_21-90-default is &gt;=9-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041143"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169812"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711581" version="1" comment="kgraft-patch-4_4_38-93-default is &gt;=9-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041387"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169812"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711582" version="1" comment="kgraft-patch-4_4_49-92_11-default is &gt;=7-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041484"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169813"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711583" version="1" comment="kgraft-patch-4_4_49-92_14-default is &gt;=6-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041522"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169814"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711584" version="1" comment="kgraft-patch-4_4_59-92_17-default is &gt;=5-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169815"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711585" version="1" comment="kgraft-patch-4_4_59-92_20-default is &gt;=5-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041642"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169815"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711586" version="1" comment="kgraft-patch-4_4_59-92_24-default is &gt;=4-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041661"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169816"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711587" version="1" comment="kgraft-patch-4_4_74-92_29-default is &gt;=4-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041737"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169816"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711588" version="1" comment="kgraft-patch-4_4_74-92_32-default is &gt;=3-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041816"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169817"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711589" version="1" comment="kgraft-patch-4_4_74-92_35-default is &gt;=3-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041849"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169817"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009161762" version="1" comment="kernel-default is &lt;4.4.74-92.35.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009052706"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711590" version="1" comment="kgraft-patch-4_4_82-6_3-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041885"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009162427" version="1" comment="kernel-default is &lt;4.4.82-6.3.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009052798"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760798" version="1" comment="kernel-default is &lt;5.3.18-24.49.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180698"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760800" version="1" comment="kernel-rt is &lt;5.3.18-8.3.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180700"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711591" version="1" comment="kgraft-patch-4_4_21-69-default is &gt;=7-21.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169818"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711592" version="1" comment="kgraft-patch-4_4_21-81-default is &gt;=7-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169819"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711593" version="1" comment="kgraft-patch-4_4_21-84-default is &gt;=6-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040921"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169820"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711594" version="1" comment="kgraft-patch-4_4_21-90-default is &gt;=6-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041143"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169820"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711595" version="1" comment="kgraft-patch-4_4_38-93-default is &gt;=6-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041387"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169820"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711596" version="1" comment="kgraft-patch-4_4_49-92_11-default is &gt;=4-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041484"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169821"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711597" version="1" comment="kgraft-patch-4_4_49-92_14-default is &gt;=3-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041522"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169822"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711598" version="1" comment="kgraft-patch-4_4_59-92_17-default is &gt;=2-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169766"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711599" version="1" comment="kgraft-patch-4_4_59-92_20-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041642"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009156965" version="1" comment="kernel-default is &lt;4.4.59-92.20.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009051911"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711600" version="1" comment="kgraft-patch-4_4_59-92_17-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711601" version="1" comment="kgraft-patch-4_4_59-92_20-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041642"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711602" version="1" comment="kgraft-patch-4_4_59-92_24-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041661"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711603" version="1" comment="kgraft-patch-4_4_74-92_29-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041737"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711604" version="1" comment="kgraft-patch-4_4_74-92_32-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041816"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711605" version="1" comment="kgraft-patch-4_4_74-92_35-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041849"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711606" version="1" comment="kgraft-patch-4_4_74-92_38-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041957"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711607" version="1" comment="kernel-default is ==4.4.90-92.45.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169823"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711608" version="1" comment="kgraft-patch-4_4_90-92_45-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042005"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009166113" version="1" comment="kernel-default is &lt;4.4.90-92.45.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009053130"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711609" version="1" comment="kgraft-patch-4_4_82-6_3-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041885"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711610" version="1" comment="kgraft-patch-4_4_82-6_6-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041959"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711611" version="1" comment="kgraft-patch-4_4_82-6_9-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711612" version="1" comment="kgraft-patch-4_4_92-6_18-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009166003" version="1" comment="kernel-default is &lt;4.4.92-6.18.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009053116"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711613" version="1" comment="kernel-default is ==4.12.14-95.40.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169824"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711614" version="1" comment="kgraft-patch-4_12_14-95_40-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048207"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711615" version="1" comment="kernel-default is &lt;4.12.14-95.40.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169825"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711616" version="1" comment="kernel-default is ==4.12.14-120.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169826"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711617" version="1" comment="kgraft-patch-4_12_14-120-default is &gt;=8-21.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048551"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169827"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711618" version="1" comment="kernel-default is ==4.12.14-122.7.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169828"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711619" version="1" comment="kgraft-patch-4_12_14-122_7-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048384"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711620" version="1" comment="kernel-default is &lt;4.12.14-122.7.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169829"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711621" version="1" comment="kernel-default is ==4.12.14-150.41.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169830"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711622" version="1" comment="kernel-livepatch-4_12_14-150_41-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711623" version="1" comment="kernel-default is &lt;4.12.14-150.41.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169831"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711624" version="1" comment="kernel-default is ==4.12.14-197.26.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169832"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711625" version="1" comment="kernel-livepatch-4_12_14-197_26-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711626" version="1" comment="kernel-default is &lt;4.12.14-197.26.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169833"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711627" version="1" comment="kgraft-patch-4_4_21-84-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040921"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711628" version="1" comment="kgraft-patch-4_4_21-90-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041143"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711629" version="1" comment="kgraft-patch-4_4_38-93-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041387"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711630" version="1" comment="kgraft-patch-4_4_49-92_11-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041484"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711631" version="1" comment="kgraft-patch-4_4_49-92_14-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041522"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009157580" version="1" comment="kernel-default is &lt;4.4.59-92.24.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009051976"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009333988" version="1" comment="qemu is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335414" version="1" comment="qemu-arm is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038462"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335214" version="1" comment="qemu-ipxe is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037631"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335244" version="1" comment="qemu-seabios is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037633"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335245" version="1" comment="qemu-sgabios is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335217" version="1" comment="qemu-tools is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036248"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335218" version="1" comment="qemu-vgabios is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037635"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335246" version="1" comment="qemu-x86 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711632" version="1" comment="kgraft-patch-4_4_82-6_3-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041885"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711633" version="1" comment="kgraft-patch-4_4_82-6_6-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041959"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711634" version="1" comment="kgraft-patch-4_4_82-6_9-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711635" version="1" comment="kernel-default is &lt;4.4.82-6.9.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169835"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338955" version="1" comment="libfreebl3 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338959" version="1" comment="libsoftokn3 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338881" version="1" comment="mozilla-nss is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032440"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338964" version="1" comment="mozilla-nss-certs is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033978"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760842" version="1" comment="perl is &lt;5.26.1-7.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030410"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180723"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760843" version="1" comment="perl-base is &lt;5.26.1-7.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031056"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180723"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711636" version="1" comment="kgraft-patch-4_4_21-84-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040921"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711637" version="1" comment="kgraft-patch-4_4_21-90-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041143"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711638" version="1" comment="kgraft-patch-4_4_38-93-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041387"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711639" version="1" comment="kgraft-patch-4_4_49-92_11-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041484"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711640" version="1" comment="kgraft-patch-4_4_49-92_14-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041522"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711641" version="1" comment="kgraft-patch-4_4_59-92_17-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711642" version="1" comment="kgraft-patch-4_4_59-92_20-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041642"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711643" version="1" comment="kgraft-patch-4_4_59-92_24-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041661"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711644" version="1" comment="kgraft-patch-4_4_74-92_29-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041737"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711645" version="1" comment="kgraft-patch-4_4_74-92_32-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041816"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711646" version="1" comment="kgraft-patch-4_4_74-92_35-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041849"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711647" version="1" comment="kgraft-patch-4_4_74-92_38-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041957"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711648" version="1" comment="kgraft-patch-4_4_82-6_3-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041885"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711649" version="1" comment="kgraft-patch-4_4_82-6_6-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041959"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711650" version="1" comment="kgraft-patch-4_4_82-6_9-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760799" version="1" comment="kernel-firmware is &lt;20200107-3.15.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042041"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180699"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711651" version="1" comment="kgraft-patch-4_4_103-6_33-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711652" version="1" comment="kgraft-patch-4_4_103-6_38-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042107"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711653" version="1" comment="kernel-default is ==4.4.114-94.11.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169836"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711654" version="1" comment="kgraft-patch-4_4_114-94_11-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042186"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711655" version="1" comment="kernel-default is ==4.4.114-94.14.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169837"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711656" version="1" comment="kgraft-patch-4_4_114-94_14-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042375"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711657" version="1" comment="kgraft-patch-4_4_82-6_3-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041885"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711658" version="1" comment="kgraft-patch-4_4_82-6_6-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041959"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711659" version="1" comment="kgraft-patch-4_4_82-6_9-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711660" version="1" comment="kgraft-patch-4_4_92-6_18-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711661" version="1" comment="kgraft-patch-4_4_92-6_30-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009140695" version="1" comment="kernel-default is &lt;4.4.21-69.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009049850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711662" version="1" comment="kgraft-patch-4_4_49-92_11-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041484"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711663" version="1" comment="kgraft-patch-4_4_49-92_14-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041522"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711664" version="1" comment="kgraft-patch-4_4_59-92_17-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711665" version="1" comment="kgraft-patch-4_4_59-92_20-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041642"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711666" version="1" comment="kgraft-patch-4_4_59-92_24-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041661"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711667" version="1" comment="kgraft-patch-4_4_74-92_29-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041737"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711668" version="1" comment="kgraft-patch-4_4_74-92_32-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041816"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711669" version="1" comment="kgraft-patch-4_4_74-92_35-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041849"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711670" version="1" comment="kgraft-patch-4_4_74-92_38-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041957"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711671" version="1" comment="kgraft-patch-4_4_90-92_45-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042005"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711672" version="1" comment="kgraft-patch-4_4_82-6_3-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041885"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711673" version="1" comment="kgraft-patch-4_4_82-6_6-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041959"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711674" version="1" comment="kgraft-patch-4_4_82-6_9-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711675" version="1" comment="kgraft-patch-4_4_92-6_18-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009475442" version="1" comment="vim-data-common is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009655960" version="1" comment="vim-small is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052260"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711676" version="1" comment="kernel-default is ==4.4.103-92.53.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169838"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711677" version="1" comment="kgraft-patch-4_4_103-92_53-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042101"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711678" version="1" comment="kernel-default is ==4.4.103-92.56.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169839"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711679" version="1" comment="kgraft-patch-4_4_103-92_56-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042105"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711680" version="1" comment="kernel-default is ==4.4.90-92.50.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169840"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711681" version="1" comment="kgraft-patch-4_4_90-92_50-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042047"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009167754" version="1" comment="kernel-default is &lt;4.4.90-92.50.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009053337"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711682" version="1" comment="kgraft-patch-4_4_103-6_33-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711683" version="1" comment="kgraft-patch-4_4_103-6_38-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042107"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711684" version="1" comment="kgraft-patch-4_4_92-6_30-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659871" version="1" comment="iscsiuio is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050199"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659872" version="1" comment="libopeniscsiusr0_2_0 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659873" version="1" comment="open-iscsi is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032231"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711685" version="1" comment="kgraft-patch-4_4_103-92_53-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042101"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711686" version="1" comment="kgraft-patch-4_4_103-92_56-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042105"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711687" version="1" comment="kgraft-patch-4_4_49-92_11-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041484"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711688" version="1" comment="kgraft-patch-4_4_49-92_14-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041522"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711689" version="1" comment="kgraft-patch-4_4_59-92_17-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711690" version="1" comment="kgraft-patch-4_4_59-92_20-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041642"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711691" version="1" comment="kgraft-patch-4_4_59-92_24-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041661"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711692" version="1" comment="kgraft-patch-4_4_74-92_29-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041737"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711693" version="1" comment="kgraft-patch-4_4_74-92_32-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041816"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711694" version="1" comment="kgraft-patch-4_4_74-92_35-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041849"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711695" version="1" comment="kgraft-patch-4_4_74-92_38-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041957"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711696" version="1" comment="kgraft-patch-4_4_90-92_45-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042005"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711697" version="1" comment="kgraft-patch-4_4_90-92_50-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042047"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711698" version="1" comment="kgraft-patch-4_4_103-6_33-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711699" version="1" comment="kgraft-patch-4_4_103-6_38-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042107"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711700" version="1" comment="kgraft-patch-4_4_82-6_3-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041885"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711701" version="1" comment="kgraft-patch-4_4_82-6_6-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041959"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711702" version="1" comment="kgraft-patch-4_4_82-6_9-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711703" version="1" comment="kgraft-patch-4_4_92-6_18-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711704" version="1" comment="kgraft-patch-4_4_92-6_30-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482516" version="1" comment="python3-PyYAML is &lt;5.1.2-6.6.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048670"/>
		<state state_ref="oval:org.opensuse.security:ste:2009112030"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711705" version="1" comment="kgraft-patch-4_4_103-6_33-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711706" version="1" comment="kgraft-patch-4_4_103-6_38-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042107"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711707" version="1" comment="kgraft-patch-4_4_114-94_11-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042186"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711708" version="1" comment="kgraft-patch-4_4_114-94_14-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042375"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711709" version="1" comment="kgraft-patch-4_4_92-6_18-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711710" version="1" comment="kgraft-patch-4_4_92-6_30-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714892" version="1" comment="kernel-default is ==4.12.14-23.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170445"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711711" version="1" comment="kernel-livepatch-4_12_14-23-default is &gt;=2-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046680"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169770"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711712" version="1" comment="kernel-default is ==4.12.14-25.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169841"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711713" version="1" comment="kernel-livepatch-4_12_14-25_3-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714893" version="1" comment="kernel-default is &lt;4.12.14-25.3.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170446"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711714" version="1" comment="kgraft-patch-4_4_21-69-default is &gt;=8-18.7.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169842"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711715" version="1" comment="kgraft-patch-4_4_21-81-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711716" version="1" comment="kgraft-patch-4_4_21-84-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040921"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711717" version="1" comment="kgraft-patch-4_4_21-90-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041143"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711718" version="1" comment="kgraft-patch-4_4_38-93-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041387"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711719" version="1" comment="kgraft-patch-4_4_49-92_11-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041484"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009149009" version="1" comment="kernel-default is &lt;4.4.49-92.11.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009051331"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009347405" version="1" comment="python3-salt is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042407"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009347406" version="1" comment="salt is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040290"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009347413" version="1" comment="salt-minion is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040297"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009656852" version="1" comment="salt-transactional-update is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051618"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009629040" version="1" comment="ucode-intel is &lt;20210216-2.19.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042104"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148246"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628930" version="1" comment="libyaml-cpp0_6 is &lt;0.6.1-4.2.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046389"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148190"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711720" version="1" comment="kgraft-patch-3_12_57-60_35-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711722" version="1" comment="kgraft-patch-3_12_59-60_41-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711724" version="1" comment="kgraft-patch-3_12_59-60_45-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711726" version="1" comment="kgraft-patch-3_12_62-60_62-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040636"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711728" version="1" comment="kgraft-patch-3_12_62-60_64_8-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711730" version="1" comment="kgraft-patch-3_12_67-60_64_18-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040879"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711732" version="1" comment="kgraft-patch-3_12_67-60_64_21-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040918"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711734" version="1" comment="kernel-default is ==3.12.67-60.64.24.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169843"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711735" version="1" comment="kgraft-patch-3_12_67-60_64_24-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711737" version="1" comment="kernel-default is ==3.12.69-60.64.29.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169844"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711738" version="1" comment="kgraft-patch-3_12_69-60_64_29-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711740" version="1" comment="kgraft-patch-4_4_21-69-default is &gt;=4-11.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169845"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711741" version="1" comment="kgraft-patch-4_4_21-81-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711742" version="1" comment="kgraft-patch-4_4_21-84-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040921"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711743" version="1" comment="kgraft-patch-4_4_21-90-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041143"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711744" version="1" comment="kgraft-patch-4_4_38-93-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041387"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760773" version="1" comment="apparmor-parser is &lt;2.13.4-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040405"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180689"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009655543" version="1" comment="libgnutls30 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042507"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334127" version="1" comment="libtasn1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038046"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336122" version="1" comment="libtasn1-6 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038681"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711745" version="1" comment="kgraft-patch-3_12_57-60_35-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711747" version="1" comment="kgraft-patch-3_12_59-60_41-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711749" version="1" comment="kgraft-patch-3_12_59-60_45-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711751" version="1" comment="kgraft-patch-3_12_62-60_62-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040636"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711753" version="1" comment="kgraft-patch-3_12_62-60_64_8-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711755" version="1" comment="kgraft-patch-3_12_67-60_64_18-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040879"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711757" version="1" comment="kgraft-patch-3_12_67-60_64_21-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040918"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711759" version="1" comment="kgraft-patch-3_12_67-60_64_24-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711761" version="1" comment="kgraft-patch-3_12_69-60_64_29-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711763" version="1" comment="kernel-default is ==3.12.69-60.64.32.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169846"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711764" version="1" comment="kgraft-patch-3_12_69-60_64_32-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041470"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711766" version="1" comment="kgraft-patch-4_4_21-69-default is &gt;=5-14.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169750"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711767" version="1" comment="kgraft-patch-4_4_21-81-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711768" version="1" comment="kgraft-patch-4_4_21-84-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040921"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711769" version="1" comment="kgraft-patch-4_4_21-90-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041143"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711770" version="1" comment="kgraft-patch-4_4_38-93-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041387"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711771" version="1" comment="kgraft-patch-4_4_49-92_11-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041484"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711772" version="1" comment="kgraft-patch-3_12_59-60_41-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711774" version="1" comment="kgraft-patch-3_12_59-60_45-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711776" version="1" comment="kgraft-patch-3_12_62-60_62-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040636"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711778" version="1" comment="kgraft-patch-3_12_62-60_64_8-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711780" version="1" comment="kgraft-patch-3_12_67-60_64_18-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040879"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711782" version="1" comment="kgraft-patch-3_12_67-60_64_21-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040918"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711784" version="1" comment="kgraft-patch-3_12_67-60_64_24-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711786" version="1" comment="kgraft-patch-3_12_69-60_64_29-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711788" version="1" comment="kgraft-patch-3_12_69-60_64_32-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041470"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711790" version="1" comment="kernel-default is ==3.12.69-60.64.35.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169847"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711791" version="1" comment="kgraft-patch-3_12_69-60_64_35-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041519"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711793" version="1" comment="kgraft-patch-4_4_21-69-default is &gt;=6-17.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169778"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711794" version="1" comment="kgraft-patch-4_4_21-81-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711795" version="1" comment="kgraft-patch-4_4_21-84-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040921"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711796" version="1" comment="kgraft-patch-4_4_21-90-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041143"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711797" version="1" comment="kgraft-patch-4_4_38-93-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041387"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711798" version="1" comment="kgraft-patch-4_4_49-92_11-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041484"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711799" version="1" comment="kgraft-patch-4_4_49-92_14-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041522"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009150055" version="1" comment="kernel-default is &lt;4.4.49-92.14.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009051455"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760839" version="1" comment="libzypp is &lt;17.25.6-3.28.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031757"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180720"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760870" version="1" comment="zypper is &lt;1.14.42-3.17.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047330"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180738"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760871" version="1" comment="zypper-needs-restarting is &lt;1.14.42-3.17.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180738"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482536" version="1" comment="rpm is &lt;4.14.1-20.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032541"/>
		<state state_ref="oval:org.opensuse.security:ste:2009112043"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009347616" version="1" comment="rpm is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032541"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711800" version="1" comment="kgraft-patch-4_4_49-92_14-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041522"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711801" version="1" comment="kgraft-patch-4_4_59-92_17-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711802" version="1" comment="kgraft-patch-4_4_59-92_20-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041642"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711803" version="1" comment="kgraft-patch-4_4_59-92_24-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041661"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711804" version="1" comment="kgraft-patch-4_4_74-92_29-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041737"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009158776" version="1" comment="kernel-default is &lt;4.4.74-92.29.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009052066"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711805" version="1" comment="kernel-default is ==4.4.73-5.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169848"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711806" version="1" comment="kgraft-patch-4_4_73-5-default is &gt;=2-2.3.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041827"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169849"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009159035" version="1" comment="kernel-default is &lt;4.4.73-5.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009052125"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482151" version="1" comment="libcroco-0_6-3 is &lt;0.6.13-1.26" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111936"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009348236" version="1" comment="libruby2_5-2_5 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047596"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009348228" version="1" comment="ruby2.5 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009348239" version="1" comment="ruby2.5-stdlib is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047600"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009373564" version="1" comment="zypper is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047330"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009654588" version="1" comment="zypper-needs-restarting is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711807" version="1" comment="kgraft-patch-4_4_103-6_33-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711808" version="1" comment="kgraft-patch-4_4_103-6_38-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042107"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711809" version="1" comment="kgraft-patch-4_4_82-6_3-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041885"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711810" version="1" comment="kgraft-patch-4_4_82-6_6-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041959"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711811" version="1" comment="kgraft-patch-4_4_82-6_9-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711812" version="1" comment="kgraft-patch-4_4_92-6_18-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711813" version="1" comment="kgraft-patch-4_4_92-6_30-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711814" version="1" comment="kgraft-patch-4_4_103-6_33-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711815" version="1" comment="kgraft-patch-4_4_103-6_38-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042107"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711816" version="1" comment="kgraft-patch-4_4_114-94_11-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042186"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711817" version="1" comment="kgraft-patch-4_4_114-94_14-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042375"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711818" version="1" comment="kgraft-patch-4_4_82-6_6-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041959"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711819" version="1" comment="kgraft-patch-4_4_82-6_9-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711820" version="1" comment="kgraft-patch-4_4_92-6_18-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711821" version="1" comment="kgraft-patch-4_4_92-6_30-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711822" version="1" comment="kgraft-patch-4_4_114-94_11-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042186"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711823" version="1" comment="kgraft-patch-4_4_114-94_14-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042375"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711824" version="1" comment="kernel-default is ==4.4.120-94.17.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169851"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711825" version="1" comment="kgraft-patch-4_4_120-94_17-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711826" version="1" comment="kernel-default is ==4.4.126-94.22.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169852"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711827" version="1" comment="kgraft-patch-4_4_126-94_22-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042385"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711828" version="1" comment="kernel-default is ==4.12.14-95.19.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169853"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711829" version="1" comment="kgraft-patch-4_12_14-95_19-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711830" version="1" comment="kernel-default is ==4.12.14-95.24.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169854"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711831" version="1" comment="kgraft-patch-4_12_14-95_24-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711832" version="1" comment="kernel-default is ==4.12.14-95.29.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169855"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711833" version="1" comment="kgraft-patch-4_12_14-95_29-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047745"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711834" version="1" comment="kernel-default is ==4.12.14-95.32.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169856"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711835" version="1" comment="kgraft-patch-4_12_14-95_32-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047922"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711836" version="1" comment="kernel-default is ==4.12.14-95.37.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169857"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711837" version="1" comment="kgraft-patch-4_12_14-95_37-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711838" version="1" comment="kgraft-patch-4_12_14-95_40-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048207"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711839" version="1" comment="kernel-default is ==4.12.14-95.45.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169858"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711840" version="1" comment="kgraft-patch-4_12_14-95_45-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048408"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711841" version="1" comment="kernel-default is ==4.12.14-95.48.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169859"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711842" version="1" comment="kgraft-patch-4_12_14-95_48-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048683"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711843" version="1" comment="kernel-default is ==4.12.14-95.51.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169860"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711844" version="1" comment="kgraft-patch-4_12_14-95_51-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048796"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711845" version="1" comment="kernel-default is &lt;4.12.14-95.51.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169861"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711846" version="1" comment="kgraft-patch-4_12_14-120-default is &gt;=5-12.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048551"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169862"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711847" version="1" comment="kernel-default is ==4.12.14-122.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169863"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711848" version="1" comment="kgraft-patch-4_12_14-122_12-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711849" version="1" comment="kernel-default is ==4.12.14-122.17.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169864"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711850" version="1" comment="kgraft-patch-4_12_14-122_17-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048685"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711851" version="1" comment="kernel-default is ==4.12.14-122.20.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169865"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711852" version="1" comment="kgraft-patch-4_12_14-122_20-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048798"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711853" version="1" comment="kgraft-patch-4_12_14-122_7-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048384"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711854" version="1" comment="kernel-default is ==4.12.14-150.22.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169866"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711855" version="1" comment="kernel-livepatch-4_12_14-150_22-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711856" version="1" comment="kernel-default is ==4.12.14-150.27.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169867"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711857" version="1" comment="kernel-livepatch-4_12_14-150_27-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047610"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711858" version="1" comment="kernel-default is ==4.12.14-150.32.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169868"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711859" version="1" comment="kernel-livepatch-4_12_14-150_32-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047743"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711860" version="1" comment="kernel-default is ==4.12.14-150.35.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169869"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711861" version="1" comment="kernel-livepatch-4_12_14-150_35-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047918"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711862" version="1" comment="kernel-default is ==4.12.14-150.38.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169870"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711863" version="1" comment="kernel-livepatch-4_12_14-150_38-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048154"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711864" version="1" comment="kernel-livepatch-4_12_14-150_41-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711865" version="1" comment="kernel-default is ==4.12.14-150.47.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169871"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711866" version="1" comment="kernel-livepatch-4_12_14-150_47-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048480"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711867" version="1" comment="kernel-default is &lt;4.12.14-150.47.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169872"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714895" version="1" comment="kernel-default is ==4.12.14-195.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170447"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711868" version="1" comment="kernel-livepatch-4_12_14-195-default is &gt;=12-34.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169873"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711869" version="1" comment="kernel-default is ==4.12.14-197.10.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169874"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711870" version="1" comment="kernel-livepatch-4_12_14-197_10-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047612"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711871" version="1" comment="kernel-default is ==4.12.14-197.15.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169875"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711872" version="1" comment="kernel-livepatch-4_12_14-197_15-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048066"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711873" version="1" comment="kernel-default is ==4.12.14-197.18.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169876"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711874" version="1" comment="kernel-livepatch-4_12_14-197_18-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047920"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711875" version="1" comment="kernel-default is ==4.12.14-197.21.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169877"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711876" version="1" comment="kernel-livepatch-4_12_14-197_21-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048156"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711877" version="1" comment="kernel-livepatch-4_12_14-197_26-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711878" version="1" comment="kernel-default is ==4.12.14-197.29.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169878"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711879" version="1" comment="kernel-livepatch-4_12_14-197_29-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048401"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711880" version="1" comment="kernel-default is ==4.12.14-197.34.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169879"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711881" version="1" comment="kernel-livepatch-4_12_14-197_34-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048662"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711882" version="1" comment="kernel-default is ==4.12.14-197.37.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169880"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711883" version="1" comment="kernel-livepatch-4_12_14-197_37-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048742"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711884" version="1" comment="kernel-default is ==4.12.14-197.4.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169881"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711885" version="1" comment="kernel-livepatch-4_12_14-197_4-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711886" version="1" comment="kernel-default is ==4.12.14-197.40.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169882"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711887" version="1" comment="kernel-livepatch-4_12_14-197_40-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048794"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711888" version="1" comment="kernel-default is ==4.12.14-197.7.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169883"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711889" version="1" comment="kernel-livepatch-4_12_14-197_7-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712211" version="1" comment="kernel-default is &lt;4.12.14-197.7.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169960"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009656853" version="1" comment="python3-pyOpenSSL is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482000" version="1" comment="gpg2 is &lt;2.2.5-4.14.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030602"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111910"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711890" version="1" comment="kgraft-patch-4_4_114-94_11-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042186"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711891" version="1" comment="kgraft-patch-4_4_114-94_14-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042375"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711892" version="1" comment="kgraft-patch-4_4_120-94_17-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711893" version="1" comment="kgraft-patch-4_4_126-94_22-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042385"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711894" version="1" comment="kernel-default is ==4.4.131-94.29.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169884"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711895" version="1" comment="kgraft-patch-4_4_131-94_29-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711896" version="1" comment="kernel-default is ==4.4.132-94.33.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169885"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711897" version="1" comment="kgraft-patch-4_4_132-94_33-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711898" version="1" comment="kernel-default is ==4.12.14-25.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169886"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711899" version="1" comment="kernel-livepatch-4_12_14-25_13-default is &gt;=3-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046840"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167192"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711900" version="1" comment="kernel-default is ==4.12.14-25.6.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169887"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711901" version="1" comment="kernel-livepatch-4_12_14-25_6-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712098" version="1" comment="kernel-default is &lt;4.12.14-25.6.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169943"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009629073" version="1" comment="podman is &lt;2.1.1-4.28.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148265"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009629074" version="1" comment="podman-cni-config is &lt;2.1.1-4.28.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047418"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148265"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711902" version="1" comment="kgraft-patch-4_4_120-94_17-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711903" version="1" comment="kgraft-patch-4_4_120-94_17-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711904" version="1" comment="kgraft-patch-4_4_126-94_22-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042385"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711905" version="1" comment="kgraft-patch-4_4_131-94_29-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711906" version="1" comment="kgraft-patch-4_4_132-94_33-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711907" version="1" comment="kernel-default is ==4.4.138-94.39.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169888"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711908" version="1" comment="kgraft-patch-4_4_138-94_39-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046471"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711909" version="1" comment="kernel-default is ==4.4.140-94.42.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169889"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711910" version="1" comment="kgraft-patch-4_4_140-94_42-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046561"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711911" version="1" comment="kernel-default is ==4.4.143-94.47.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169890"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711912" version="1" comment="kgraft-patch-4_4_143-94_47-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711913" version="1" comment="kernel-livepatch-4_12_14-23-default is &gt;=4-10.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046680"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169891"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711914" version="1" comment="kernel-livepatch-4_12_14-25_3-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009654591" version="1" comment="liblldp_clif1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058502"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009654592" version="1" comment="open-lldp is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711915" version="1" comment="kernel-default is ==4.12.14-25.16.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169892"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711916" version="1" comment="kernel-livepatch-4_12_14-25_16-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046688"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711917" version="1" comment="kernel-livepatch-4_12_14-25_6-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760821" version="1" comment="libprocps7 is &lt;3.3.15-7.13.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048169"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180710"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760822" version="1" comment="procps is &lt;3.3.15-7.13.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038823"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180710"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711918" version="1" comment="kernel-livepatch-4_12_14-23-default is &gt;=9-25.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046680"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169893"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711919" version="1" comment="kernel-livepatch-4_12_14-25_3-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009480339" version="1" comment="kernel-default is &lt;4.12.14-23.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111398"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336008" version="1" comment="libpng16-16 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037593"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760801" version="1" comment="libX11-6 is &lt;1.6.5-3.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180701"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760802" version="1" comment="libX11-data is &lt;1.6.5-3.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036218"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180701"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760803" version="1" comment="libX11-xcb1 is &lt;1.6.5-3.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036222"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180701"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711920" version="1" comment="kgraft-patch-4_4_103-6_33-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711921" version="1" comment="kgraft-patch-4_4_103-6_38-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042107"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711922" version="1" comment="kgraft-patch-4_4_114-94_11-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042186"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711923" version="1" comment="kgraft-patch-4_4_114-94_14-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042375"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711924" version="1" comment="kgraft-patch-4_4_120-94_17-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711925" version="1" comment="kgraft-patch-4_4_126-94_22-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042385"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711926" version="1" comment="kgraft-patch-4_4_131-94_29-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711927" version="1" comment="kgraft-patch-4_4_132-94_33-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711928" version="1" comment="kgraft-patch-4_4_138-94_39-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046471"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711929" version="1" comment="kgraft-patch-4_4_140-94_42-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046561"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711930" version="1" comment="kgraft-patch-4_4_143-94_47-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711931" version="1" comment="kernel-default is ==4.4.155-94.50.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169894"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711932" version="1" comment="kgraft-patch-4_4_155-94_50-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711933" version="1" comment="kernel-default is ==4.4.156-94.57.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169895"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711934" version="1" comment="kgraft-patch-4_4_156-94_57-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046853"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711935" version="1" comment="kernel-default is ==4.4.156-94.61.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169896"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711936" version="1" comment="kgraft-patch-4_4_156-94_61-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046887"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711937" version="1" comment="kernel-default is ==4.4.156-94.64.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169897"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711938" version="1" comment="kgraft-patch-4_4_156-94_64-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046993"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711939" version="1" comment="kgraft-patch-4_4_92-6_18-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711940" version="1" comment="kgraft-patch-4_4_92-6_30-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711941" version="1" comment="kernel-livepatch-4_12_14-23-default is &gt;=5-13.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046680"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169898"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711942" version="1" comment="kernel-livepatch-4_12_14-25_13-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046840"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711943" version="1" comment="kernel-livepatch-4_12_14-25_16-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046688"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711944" version="1" comment="kernel-default is ==4.12.14-25.19.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169899"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711945" version="1" comment="kernel-livepatch-4_12_14-25_19-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046851"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711946" version="1" comment="kernel-livepatch-4_12_14-25_3-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711947" version="1" comment="kernel-livepatch-4_12_14-25_6-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704936" version="1" comment="libmspack0 is &lt;0.6-3.11.1 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147681"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481038" version="1" comment="btrfsmaintenance is &lt;0.4.2-1.11" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047402"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111711"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711948" version="1" comment="kgraft-patch-4_4_132-94_33-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711949" version="1" comment="kgraft-patch-4_4_138-94_39-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046471"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711950" version="1" comment="kgraft-patch-4_4_140-94_42-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046561"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711951" version="1" comment="kernel-default is &lt;4.4.140-94.42.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169900"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711952" version="1" comment="kernel-livepatch-4_12_14-23-default is &gt;=10-28.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046680"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169901"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711953" version="1" comment="kernel-livepatch-4_12_14-25_3-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482345" version="1" comment="libpango-1_0-0 is &lt;1.44.7+11-1.25" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041004"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111971"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711954" version="1" comment="kernel-livepatch-4_12_14-23-default is &gt;=3-7.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046680"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169902"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711955" version="1" comment="kernel-livepatch-4_12_14-25_3-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628652" version="1" comment="libcontainers-common is &lt;20200727-3.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047795"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148139"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009494057" version="1" comment="python3-distro is &lt;1.5.0-3.5.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051616"/>
		<state state_ref="oval:org.opensuse.security:ste:2009116937"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009504114" version="1" comment="python3-salt is &lt;3002.2-37.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042407"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119168"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009504115" version="1" comment="salt is &lt;3002.2-37.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040290"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119168"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009504120" version="1" comment="salt-minion is &lt;3002.2-37.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040297"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119168"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009504125" version="1" comment="salt-transactional-update is &lt;3002.2-37.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051618"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119168"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481580" version="1" comment="libxkbcommon0 is &lt;0.8.2-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046922"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111804"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760781" version="1" comment="glib2-tools is &lt;2.62.6-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040978"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180694"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760782" version="1" comment="libgio-2_0-0 is &lt;2.62.6-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030896"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180694"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760783" version="1" comment="libglib-2_0-0 is &lt;2.62.6-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030899"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180694"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760784" version="1" comment="libgmodule-2_0-0 is &lt;2.62.6-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030902"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180694"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760785" version="1" comment="libgobject-2_0-0 is &lt;2.62.6-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030905"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180694"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711956" version="1" comment="kernel-default is ==4.12.14-94.41.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169903"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711957" version="1" comment="kgraft-patch-4_12_14-94_41-default is &gt;=9-2.25.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169904"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711958" version="1" comment="kernel-default is ==4.12.14-95.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169905"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711959" version="1" comment="kgraft-patch-4_12_14-95_3-default is &gt;=8-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047020"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169906"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711960" version="1" comment="kernel-default is ==4.12.14-95.6.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169907"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711961" version="1" comment="kgraft-patch-4_12_14-95_6-default is &gt;=7-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047080"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169908"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711962" version="1" comment="kernel-default is &lt;4.12.14-95.6.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169909"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711963" version="1" comment="kernel-default is ==4.12.14-25.28.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169910"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711964" version="1" comment="kernel-livepatch-4_12_14-25_28-default is &gt;=7-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047083"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167185"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711965" version="1" comment="kernel-default is &lt;4.12.14-25.28.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169911"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009629071" version="1" comment="docker-libnetwork is &lt;0.7.0.1+gitr2908_55e924b8a842-4.31.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042188"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148263"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659879" version="1" comment="cni-plugins is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048723"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711966" version="1" comment="kgraft-patch-4_4_114-94_11-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042186"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711967" version="1" comment="kgraft-patch-4_4_114-94_14-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042375"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711968" version="1" comment="kgraft-patch-4_4_120-94_17-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711969" version="1" comment="kgraft-patch-4_4_126-94_22-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042385"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711970" version="1" comment="kgraft-patch-4_4_131-94_29-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711971" version="1" comment="kgraft-patch-4_4_132-94_33-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711972" version="1" comment="kgraft-patch-4_4_138-94_39-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046471"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711973" version="1" comment="kgraft-patch-4_4_140-94_42-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046561"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711974" version="1" comment="kgraft-patch-4_4_143-94_47-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711975" version="1" comment="kgraft-patch-4_4_155-94_50-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711976" version="1" comment="kgraft-patch-4_4_156-94_57-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046853"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711977" version="1" comment="kgraft-patch-4_4_156-94_61-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046887"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711978" version="1" comment="kgraft-patch-4_4_156-94_64-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046993"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711979" version="1" comment="kernel-default is ==4.4.162-94.69.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169912"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711980" version="1" comment="kgraft-patch-4_4_162-94_69-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046939"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711981" version="1" comment="kernel-default is ==4.4.162-94.72.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169913"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711982" version="1" comment="kgraft-patch-4_4_162-94_72-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047097"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711983" version="1" comment="kernel-default is &lt;4.4.162-94.72.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169914"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711984" version="1" comment="kgraft-patch-4_12_14-94_41-default is &gt;=3-2.7.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169915"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711985" version="1" comment="kgraft-patch-4_12_14-95_3-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047020"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711986" version="1" comment="kernel-default is &lt;4.12.14-95.3.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169916"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711987" version="1" comment="kernel-livepatch-4_12_14-23-default is &gt;=8-22.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046680"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169917"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711988" version="1" comment="kernel-livepatch-4_12_14-25_13-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046840"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711989" version="1" comment="kernel-livepatch-4_12_14-25_16-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046688"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711990" version="1" comment="kernel-livepatch-4_12_14-25_19-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046851"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711991" version="1" comment="kernel-default is ==4.12.14-25.22.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169918"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711992" version="1" comment="kernel-livepatch-4_12_14-25_22-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046880"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711993" version="1" comment="kernel-default is ==4.12.14-25.25.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169919"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711994" version="1" comment="kernel-livepatch-4_12_14-25_25-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711995" version="1" comment="kernel-livepatch-4_12_14-25_3-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711996" version="1" comment="kernel-livepatch-4_12_14-25_6-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009339036" version="1" comment="libcairo2 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040390"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711997" version="1" comment="kgraft-patch-4_4_103-6_33-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711998" version="1" comment="kgraft-patch-4_4_103-6_38-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042107"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711999" version="1" comment="kgraft-patch-4_4_92-6_30-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712000" version="1" comment="kernel-livepatch-4_12_14-23-default is &gt;=6-16.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046680"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169920"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667510" version="1" comment="libmspack0 is &lt;0.6-3.14.1 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156457"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760780" version="1" comment="gettext-runtime is &lt;0.19.8.1-4.11.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049063"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180693"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482311" version="1" comment="libncurses6 is &lt;6.1-5.6.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041698"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111962"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482314" version="1" comment="ncurses-utils is &lt;6.1-5.6.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111962"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482316" version="1" comment="terminfo is &lt;6.1-5.6.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032551"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111962"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482317" version="1" comment="terminfo-base is &lt;6.1-5.6.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111962"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482553" version="1" comment="supportutils is &lt;3.1.9-5.24.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034036"/>
		<state state_ref="oval:org.opensuse.security:ste:2009112052"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482404" version="1" comment="libsqlite3-0 is &lt;3.28.0-3.9.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040582"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111986"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705032" version="1" comment="tar is &lt;1.34-150000.3.12.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030401"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167774"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760827" version="1" comment="libsolv-tools is &lt;0.7.16-3.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046714"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180713"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705024" version="1" comment="libyaml-cpp0_6 is &lt;0.6.1-4.5.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046389"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167770"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712001" version="1" comment="kernel-default is ==4.12.14-95.68.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169921"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712002" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712003" version="1" comment="kernel-default is ==4.12.14-95.71.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169923"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712004" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698690" version="1" comment="kernel-default is ==4.12.14-95.74.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166484"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712005" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698692" version="1" comment="kernel-default is ==4.12.14-95.77.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166486"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712006" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698694" version="1" comment="kernel-default is ==4.12.14-95.80.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166488"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712007" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698696" version="1" comment="kernel-default is ==4.12.14-95.83.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166490"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712008" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698698" version="1" comment="kernel-default is &lt;4.12.14-95.83.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166492"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712009" version="1" comment="kernel-default is ==4.12.14-150.66.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169927"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712010" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712011" version="1" comment="kernel-default is ==4.12.14-150.69.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169928"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712012" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698720" version="1" comment="kernel-default is ==4.12.14-150.72.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166508"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712013" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698722" version="1" comment="kernel-default is ==4.12.14-150.75.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166510"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712014" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698724" version="1" comment="kernel-default is ==4.12.14-150.78.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166512"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712015" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698726" version="1" comment="kernel-default is &lt;4.12.14-150.78.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166514"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009676998" version="1" comment="libz1 is &lt;1.2.11-150000.3.30.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041210"/>
		<state state_ref="oval:org.opensuse.security:ste:2009159468"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712016" version="1" comment="kernel-livepatch-4_12_14-25_6-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712017" version="1" comment="kgraft-patch-4_4_103-6_33-default is &gt;=7-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169908"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712018" version="1" comment="kgraft-patch-4_4_103-6_38-default is &gt;=7-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042107"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169908"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712019" version="1" comment="kgraft-patch-4_4_114-94_11-default is &gt;=5-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042186"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169929"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712020" version="1" comment="kgraft-patch-4_4_114-94_14-default is &gt;=5-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042375"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169929"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712021" version="1" comment="kgraft-patch-4_4_120-94_17-default is &gt;=4-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169930"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712022" version="1" comment="kgraft-patch-4_4_126-94_22-default is &gt;=4-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042385"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169930"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712023" version="1" comment="kgraft-patch-4_4_131-94_29-default is &gt;=2-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169931"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712024" version="1" comment="kgraft-patch-4_4_132-94_33-default is &gt;=2-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169931"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712025" version="1" comment="kgraft-patch-4_4_82-6_3-default is &gt;=10-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041885"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169932"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712026" version="1" comment="kgraft-patch-4_4_82-6_6-default is &gt;=9-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041959"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169933"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712027" version="1" comment="kgraft-patch-4_4_82-6_9-default is &gt;=9-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169933"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712028" version="1" comment="kgraft-patch-4_4_92-6_18-default is &gt;=8-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169906"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712029" version="1" comment="kgraft-patch-4_4_92-6_30-default is &gt;=7-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169908"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712030" version="1" comment="kgraft-patch-4_4_114-94_11-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042186"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712031" version="1" comment="kgraft-patch-4_4_114-94_14-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042375"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712032" version="1" comment="kgraft-patch-4_4_120-94_17-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712033" version="1" comment="kgraft-patch-4_4_126-94_22-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042385"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712034" version="1" comment="kgraft-patch-4_4_131-94_29-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712035" version="1" comment="kgraft-patch-4_4_132-94_33-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712036" version="1" comment="kgraft-patch-4_4_138-94_39-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046471"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712037" version="1" comment="kgraft-patch-4_4_140-94_42-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046561"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712038" version="1" comment="kernel-livepatch-4_12_14-25_3-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712039" version="1" comment="kernel-livepatch-4_12_14-25_6-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712040" version="1" comment="kgraft-patch-4_4_103-6_33-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712041" version="1" comment="kgraft-patch-4_4_103-6_38-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042107"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712042" version="1" comment="kgraft-patch-4_4_114-94_11-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042186"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712043" version="1" comment="kgraft-patch-4_4_114-94_14-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042375"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712044" version="1" comment="kgraft-patch-4_4_120-94_17-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712045" version="1" comment="kgraft-patch-4_4_126-94_22-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042385"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712046" version="1" comment="kgraft-patch-4_4_131-94_29-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712047" version="1" comment="kgraft-patch-4_4_132-94_33-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712048" version="1" comment="kernel-default is &lt;4.4.132-94.33.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169934"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712049" version="1" comment="kernel-livepatch-4_12_14-23-default is &gt;=7-19.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046680"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169935"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335465" version="1" comment="libgcrypt20 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038771"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482541" version="1" comment="shadow is &lt;4.6-3.5.6" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009112046"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334073" version="1" comment="elfutils is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038055"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335871" version="1" comment="libasm1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038057"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335872" version="1" comment="libdw1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038060"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659704" version="1" comment="libebl-plugins is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042483"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335876" version="1" comment="libelf1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038067"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712050" version="1" comment="kgraft-patch-4_12_14-95_32-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047922"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712051" version="1" comment="kgraft-patch-4_12_14-95_37-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712052" version="1" comment="kgraft-patch-4_12_14-95_40-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048207"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712053" version="1" comment="kgraft-patch-4_12_14-120-default is &gt;=6-15.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048551"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169936"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009512974" version="1" comment="kernel-default is &lt;4.12.14-120.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009121033"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712054" version="1" comment="kernel-livepatch-4_12_14-150_35-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047918"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712055" version="1" comment="kernel-livepatch-4_12_14-150_38-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048154"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712056" version="1" comment="kernel-livepatch-4_12_14-150_41-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712057" version="1" comment="kernel-livepatch-4_12_14-197_18-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047920"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712058" version="1" comment="kernel-livepatch-4_12_14-197_21-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048156"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712059" version="1" comment="kernel-livepatch-4_12_14-197_26-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712060" version="1" comment="kernel-default is ==4.12.14-95.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169937"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712061" version="1" comment="kgraft-patch-4_12_14-95_13-default is &gt;=6-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047209"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169938"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712062" version="1" comment="kernel-default is ==4.12.14-95.16.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169939"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712063" version="1" comment="kgraft-patch-4_12_14-95_16-default is &gt;=6-2.5" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047380"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169938"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712064" version="1" comment="kgraft-patch-4_12_14-95_19-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712065" version="1" comment="kgraft-patch-4_12_14-95_24-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712066" version="1" comment="kgraft-patch-4_12_14-95_29-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047745"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712067" version="1" comment="kgraft-patch-4_12_14-95_32-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047922"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712068" version="1" comment="kgraft-patch-4_12_14-95_37-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712069" version="1" comment="kgraft-patch-4_12_14-120-default is &gt;=2-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048551"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169766"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712070" version="1" comment="kernel-default is ==4.12.14-150.14.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169940"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712071" version="1" comment="kernel-livepatch-4_12_14-150_14-default is &gt;=6-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047218"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167108"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712072" version="1" comment="kernel-default is ==4.12.14-150.17.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169941"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712073" version="1" comment="kernel-livepatch-4_12_14-150_17-default is &gt;=6-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167108"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712074" version="1" comment="kernel-livepatch-4_12_14-150_22-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712075" version="1" comment="kernel-livepatch-4_12_14-150_27-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047610"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712076" version="1" comment="kernel-livepatch-4_12_14-150_32-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047743"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712077" version="1" comment="kernel-livepatch-4_12_14-150_35-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047918"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712078" version="1" comment="kernel-livepatch-4_12_14-150_38-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048154"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712079" version="1" comment="kernel-livepatch-4_12_14-25_25-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712080" version="1" comment="kernel-livepatch-4_12_14-195-default is &gt;=8-22.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169917"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712081" version="1" comment="kernel-livepatch-4_12_14-197_10-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047612"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712082" version="1" comment="kernel-livepatch-4_12_14-197_15-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048066"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712083" version="1" comment="kernel-livepatch-4_12_14-197_18-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047920"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712084" version="1" comment="kernel-livepatch-4_12_14-197_21-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048156"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712085" version="1" comment="kernel-livepatch-4_12_14-197_4-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712086" version="1" comment="kernel-livepatch-4_12_14-197_7-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712087" version="1" comment="kgraft-patch-4_12_14-94_41-default is &gt;=5-2.13.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169942"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712088" version="1" comment="kgraft-patch-4_12_14-95_3-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047020"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712089" version="1" comment="kgraft-patch-4_12_14-95_6-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047080"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712090" version="1" comment="kernel-livepatch-4_12_14-25_13-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046840"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712091" version="1" comment="kernel-livepatch-4_12_14-25_16-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046688"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712092" version="1" comment="kernel-livepatch-4_12_14-25_19-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046851"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712093" version="1" comment="kernel-livepatch-4_12_14-25_22-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046880"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712094" version="1" comment="kernel-livepatch-4_12_14-25_25-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712095" version="1" comment="kernel-livepatch-4_12_14-25_28-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047083"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712096" version="1" comment="kernel-livepatch-4_12_14-25_3-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712097" version="1" comment="kernel-livepatch-4_12_14-25_6-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712099" version="1" comment="kgraft-patch-4_4_138-94_39-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046471"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712100" version="1" comment="kgraft-patch-4_4_140-94_42-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046561"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712101" version="1" comment="kgraft-patch-4_4_143-94_47-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712102" version="1" comment="kgraft-patch-4_4_155-94_50-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712103" version="1" comment="kgraft-patch-4_4_156-94_57-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046853"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712104" version="1" comment="kgraft-patch-4_4_156-94_61-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046887"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712105" version="1" comment="kgraft-patch-4_4_156-94_64-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046993"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712106" version="1" comment="kgraft-patch-4_4_162-94_69-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046939"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712107" version="1" comment="kgraft-patch-4_4_162-94_72-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047097"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712108" version="1" comment="kernel-default is ==4.4.175-94.79.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169944"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712109" version="1" comment="kgraft-patch-4_4_175-94_79-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047163"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712110" version="1" comment="kernel-default is ==4.4.176-94.88.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169945"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712111" version="1" comment="kgraft-patch-4_4_176-94_88-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712112" version="1" comment="kernel-default is ==4.4.178-94.91.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169946"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712113" version="1" comment="kgraft-patch-4_4_178-94_91-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047378"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712114" version="1" comment="kernel-default is &lt;4.4.178-94.91.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169947"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712115" version="1" comment="kgraft-patch-4_12_14-94_41-default is &gt;=6-2.16.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169948"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712116" version="1" comment="kgraft-patch-4_12_14-95_13-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047209"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712117" version="1" comment="kgraft-patch-4_12_14-95_16-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047380"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712118" version="1" comment="kgraft-patch-4_12_14-95_3-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047020"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712119" version="1" comment="kgraft-patch-4_12_14-95_6-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047080"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712120" version="1" comment="kernel-livepatch-4_12_14-150_14-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047218"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712121" version="1" comment="kernel-livepatch-4_12_14-150_17-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712122" version="1" comment="kernel-livepatch-4_12_14-25_13-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046840"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712123" version="1" comment="kernel-livepatch-4_12_14-25_16-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046688"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712124" version="1" comment="kernel-livepatch-4_12_14-25_19-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046851"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712125" version="1" comment="kernel-livepatch-4_12_14-25_22-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046880"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712126" version="1" comment="kernel-livepatch-4_12_14-25_25-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712127" version="1" comment="kernel-livepatch-4_12_14-25_28-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047083"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712128" version="1" comment="kernel-livepatch-4_12_14-25_3-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712129" version="1" comment="kernel-livepatch-4_12_14-25_6-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712130" version="1" comment="kernel-livepatch-4_12_14-195-default is &gt;=4-10.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169949"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481199" version="1" comment="kernel-default is &lt;4.12.14-195.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111410"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712131" version="1" comment="kgraft-patch-4_12_14-95_19-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712132" version="1" comment="kernel-livepatch-4_12_14-150_22-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712133" version="1" comment="kernel-livepatch-4_12_14-197_4-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712134" version="1" comment="kernel-livepatch-4_12_14-197_7-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712135" version="1" comment="kernel-default is ==4.4.180-94.97.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169950"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712136" version="1" comment="kgraft-patch-4_4_180-94_97-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047480"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712137" version="1" comment="kernel-default is &lt;4.4.180-94.97.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169951"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712138" version="1" comment="kgraft-patch-4_12_14-95_13-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047209"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712139" version="1" comment="kgraft-patch-4_12_14-95_16-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047380"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712140" version="1" comment="kernel-livepatch-4_12_14-150_14-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047218"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712141" version="1" comment="kernel-livepatch-4_12_14-150_17-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712142" version="1" comment="kernel-livepatch-4_12_14-195-default is &gt;=2-4.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169770"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482471" version="1" comment="libzstd1 is &lt;1.4.4-1.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009112008"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712143" version="1" comment="kernel-livepatch-4_12_14-195-default is &gt;=3-7.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169952"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712144" version="1" comment="kernel-livepatch-4_12_14-197_4-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714896" version="1" comment="kernel-default is &lt;4.12.14-197.4.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170448"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335952" version="1" comment="libssh2-1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038580"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712145" version="1" comment="kernel-livepatch-4_12_14-195-default is &gt;=5-13.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169898"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712146" version="1" comment="kernel-livepatch-4_12_14-197_4-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712147" version="1" comment="kernel-livepatch-4_12_14-197_7-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338972" version="1" comment="dnsmasq is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031669"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712148" version="1" comment="kgraft-patch-4_12_14-94_41-default is &gt;=7-2.19.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169953"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712149" version="1" comment="kgraft-patch-4_12_14-95_13-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047209"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712150" version="1" comment="kgraft-patch-4_12_14-95_16-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047380"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712151" version="1" comment="kgraft-patch-4_12_14-95_19-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712152" version="1" comment="kgraft-patch-4_12_14-95_24-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712153" version="1" comment="kgraft-patch-4_12_14-95_29-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047745"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712154" version="1" comment="kgraft-patch-4_12_14-95_3-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047020"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712155" version="1" comment="kgraft-patch-4_12_14-95_6-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047080"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712156" version="1" comment="kernel-livepatch-4_12_14-150_14-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047218"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712157" version="1" comment="kernel-livepatch-4_12_14-150_17-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712158" version="1" comment="kernel-livepatch-4_12_14-150_22-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712159" version="1" comment="kernel-livepatch-4_12_14-150_27-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047610"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712160" version="1" comment="kernel-livepatch-4_12_14-150_32-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047743"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712161" version="1" comment="kernel-livepatch-4_12_14-25_19-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046851"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712162" version="1" comment="kernel-livepatch-4_12_14-25_22-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046880"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712163" version="1" comment="kernel-livepatch-4_12_14-25_25-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712164" version="1" comment="kernel-livepatch-4_12_14-25_28-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047083"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712165" version="1" comment="kernel-livepatch-4_12_14-195-default is &gt;=6-16.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169954"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712166" version="1" comment="kernel-livepatch-4_12_14-197_10-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047612"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712167" version="1" comment="kernel-livepatch-4_12_14-197_15-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048066"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712168" version="1" comment="kernel-livepatch-4_12_14-197_4-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712169" version="1" comment="kernel-livepatch-4_12_14-197_7-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712170" version="1" comment="kgraft-patch-4_12_14-95_45-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048408"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712171" version="1" comment="kernel-default is &lt;4.12.14-95.45.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169955"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712172" version="1" comment="kgraft-patch-4_12_14-122_12-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712173" version="1" comment="kgraft-patch-4_12_14-122_7-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048384"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712174" version="1" comment="kernel-livepatch-4_12_14-150_47-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048480"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712175" version="1" comment="kernel-livepatch-4_12_14-197_29-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048401"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712176" version="1" comment="kernel-default is &lt;4.12.14-197.29.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169956"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712177" version="1" comment="kgraft-patch-4_12_14-95_13-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047209"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712178" version="1" comment="kgraft-patch-4_12_14-95_16-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047380"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712179" version="1" comment="kgraft-patch-4_12_14-95_19-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712180" version="1" comment="kgraft-patch-4_12_14-95_24-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712181" version="1" comment="kgraft-patch-4_12_14-95_29-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047745"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712182" version="1" comment="kgraft-patch-4_12_14-95_32-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047922"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712183" version="1" comment="kgraft-patch-4_12_14-95_37-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712184" version="1" comment="kgraft-patch-4_12_14-95_40-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048207"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712185" version="1" comment="kgraft-patch-4_12_14-95_45-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048408"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712186" version="1" comment="kgraft-patch-4_12_14-95_6-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047080"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712187" version="1" comment="kgraft-patch-4_12_14-122_12-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712188" version="1" comment="kgraft-patch-4_12_14-122_7-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048384"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712189" version="1" comment="kernel-livepatch-4_12_14-150_14-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047218"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712190" version="1" comment="kernel-livepatch-4_12_14-150_17-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712191" version="1" comment="kernel-livepatch-4_12_14-150_22-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712192" version="1" comment="kernel-livepatch-4_12_14-150_27-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047610"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712193" version="1" comment="kernel-livepatch-4_12_14-150_32-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047743"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712194" version="1" comment="kernel-livepatch-4_12_14-150_35-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047918"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712195" version="1" comment="kernel-livepatch-4_12_14-150_38-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048154"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712196" version="1" comment="kernel-livepatch-4_12_14-150_41-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712197" version="1" comment="kernel-livepatch-4_12_14-150_47-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048480"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712198" version="1" comment="kernel-livepatch-4_12_14-25_28-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047083"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712199" version="1" comment="kernel-livepatch-4_12_14-195-default is &gt;=9-25.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169893"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712200" version="1" comment="kernel-livepatch-4_12_14-197_10-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047612"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712201" version="1" comment="kernel-livepatch-4_12_14-197_15-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048066"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712202" version="1" comment="kernel-livepatch-4_12_14-197_18-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047920"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712203" version="1" comment="kernel-livepatch-4_12_14-197_21-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048156"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712204" version="1" comment="kernel-livepatch-4_12_14-197_26-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712205" version="1" comment="kernel-livepatch-4_12_14-197_29-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048401"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712206" version="1" comment="kernel-livepatch-4_12_14-197_4-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712207" version="1" comment="kernel-livepatch-4_12_14-197_7-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712208" version="1" comment="kernel-default is &lt;4.12.14-197.18.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169957"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009658281" version="1" comment="kernel-firmware is &lt;20200107-3.23.1 for noarch" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042041"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155674"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009658282" version="1" comment="ucode-amd is &lt;20200107-3.23.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042042"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155674"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712209" version="1" comment="kernel-default is &lt;4.12.14-95.29.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169958"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712210" version="1" comment="kernel-default is &lt;4.12.14-150.32.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169959"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704898" version="1" comment="qemu is &lt;4.2.1-11.19.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167721"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499897" version="1" comment="qemu-arm is &lt;4.2.1-11.19.2 for aarch64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038462"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118535"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499905" version="1" comment="qemu-ipxe is &lt;1.0.0+-11.19.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037631"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118537"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499911" version="1" comment="qemu-seabios is &lt;1.12.1+-11.19.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037633"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118542"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499912" version="1" comment="qemu-sgabios is &lt;8-11.19.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118543"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704899" version="1" comment="qemu-tools is &lt;4.2.1-11.19.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036248"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167721"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499916" version="1" comment="qemu-vgabios is &lt;1.12.1+-11.19.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037635"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118542"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499917" version="1" comment="qemu-x86 is &lt;4.2.1-11.19.2 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118536"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712212" version="1" comment="kgraft-patch-4_12_14-95_48-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048683"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712213" version="1" comment="kgraft-patch-4_12_14-95_51-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048796"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712214" version="1" comment="kernel-default is ==4.12.14-95.54.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169962"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712215" version="1" comment="kgraft-patch-4_12_14-95_54-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048888"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712216" version="1" comment="kernel-default is &lt;4.12.14-95.54.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169963"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712217" version="1" comment="kernel-default is ==4.12.14-150.52.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169964"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712218" version="1" comment="kernel-livepatch-4_12_14-150_52-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048927"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712219" version="1" comment="kernel-default is &lt;4.12.14-150.52.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169965"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712220" version="1" comment="kgraft-patch-4_12_14-94_41-default is &gt;=8-2.22.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169966"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712221" version="1" comment="kgraft-patch-4_12_14-95_13-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047209"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712222" version="1" comment="kgraft-patch-4_12_14-95_16-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047380"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712223" version="1" comment="kgraft-patch-4_12_14-95_19-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712224" version="1" comment="kgraft-patch-4_12_14-95_24-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712225" version="1" comment="kgraft-patch-4_12_14-95_29-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047745"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712226" version="1" comment="kgraft-patch-4_12_14-95_3-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047020"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712227" version="1" comment="kgraft-patch-4_12_14-95_32-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047922"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712228" version="1" comment="kgraft-patch-4_12_14-95_6-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047080"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712229" version="1" comment="kernel-livepatch-4_12_14-150_14-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047218"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712230" version="1" comment="kernel-livepatch-4_12_14-150_17-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712231" version="1" comment="kernel-livepatch-4_12_14-150_22-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712232" version="1" comment="kernel-livepatch-4_12_14-150_27-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047610"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712233" version="1" comment="kernel-livepatch-4_12_14-150_32-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047743"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712234" version="1" comment="kernel-livepatch-4_12_14-150_35-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047918"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712235" version="1" comment="kernel-livepatch-4_12_14-150_38-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048154"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712236" version="1" comment="kernel-livepatch-4_12_14-25_28-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047083"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712237" version="1" comment="kernel-livepatch-4_12_14-195-default is &gt;=7-19.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169967"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712238" version="1" comment="kernel-livepatch-4_12_14-197_10-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047612"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712239" version="1" comment="kernel-livepatch-4_12_14-197_18-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047920"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712240" version="1" comment="kernel-livepatch-4_12_14-197_21-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048156"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712241" version="1" comment="kernel-livepatch-4_12_14-197_4-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712242" version="1" comment="kernel-livepatch-4_12_14-197_7-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482293" version="1" comment="liblz4-1 is &lt;1.8.0-3.5.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111954"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704876" version="1" comment="libfribidi0 is &lt;1.0.5-3.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050455"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167712"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704857" version="1" comment="kernel-default is &lt;5.3.18-24.61.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009116835"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704858" version="1" comment="kernel-default-base is &lt;5.3.18-24.61.1.9.26.4 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167701"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009620089" version="1" comment="kernel-rt is &lt;5.3.18-8.7.1 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009146725"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009655560" version="1" comment="python3-psutil is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058585"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336106" version="1" comment="libsolv-tools is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046714"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760866" version="1" comment="wicked is &lt;0.6.64-3.3.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048558"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180735"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760867" version="1" comment="wicked-service is &lt;0.6.64-3.3.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048559"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180735"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009629441" version="1" comment="libesmtp is &lt;1.0.6-150.4.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033739"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148358"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482145" version="1" comment="libbsd0 is &lt;0.8.7-3.3.17" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048836"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111933"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009339120" version="1" comment="iproute2 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030404"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704972" version="1" comment="libpcre1 is &lt;8.45-20.10.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038688"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167751"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009629000" version="1" comment="python3-setuptools is &lt;40.5.0-6.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047019"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148224"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009624613" version="1" comment="kernel-rt is &lt;4.12.14-10.49.1 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147344"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628975" version="1" comment="permissions is &lt;20181224-23.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032191"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148208"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628947" version="1" comment="nfs-client is &lt;2.1.1-10.10.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034590"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148197"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481717" version="1" comment="libgbm1 is &lt;19.3.4-45.23" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035914"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111860"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712243" version="1" comment="kgraft-patch-4_12_14-95_16-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047380"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712244" version="1" comment="kgraft-patch-4_12_14-95_19-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712245" version="1" comment="kgraft-patch-4_12_14-95_24-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712246" version="1" comment="kgraft-patch-4_12_14-95_29-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047745"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712247" version="1" comment="kgraft-patch-4_12_14-95_32-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047922"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712248" version="1" comment="kgraft-patch-4_12_14-95_37-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712249" version="1" comment="kgraft-patch-4_12_14-95_40-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048207"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712250" version="1" comment="kgraft-patch-4_12_14-95_45-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048408"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712251" version="1" comment="kgraft-patch-4_12_14-120-default is &gt;=3-6.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048551"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169968"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712252" version="1" comment="kgraft-patch-4_12_14-122_12-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712253" version="1" comment="kgraft-patch-4_12_14-122_7-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048384"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712254" version="1" comment="kernel-livepatch-4_12_14-150_14-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047218"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712255" version="1" comment="kernel-livepatch-4_12_14-150_17-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712256" version="1" comment="kernel-livepatch-4_12_14-150_22-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712257" version="1" comment="kernel-livepatch-4_12_14-150_27-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047610"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712258" version="1" comment="kernel-livepatch-4_12_14-150_32-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047743"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712259" version="1" comment="kernel-livepatch-4_12_14-150_35-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047918"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712260" version="1" comment="kernel-livepatch-4_12_14-150_38-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048154"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712261" version="1" comment="kernel-livepatch-4_12_14-150_41-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712262" version="1" comment="kernel-livepatch-4_12_14-150_47-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048480"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712263" version="1" comment="kernel-livepatch-4_12_14-195-default is &gt;=10-28.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169969"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712264" version="1" comment="kernel-livepatch-4_12_14-197_10-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047612"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712265" version="1" comment="kernel-livepatch-4_12_14-197_15-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048066"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712266" version="1" comment="kernel-livepatch-4_12_14-197_18-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047920"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712267" version="1" comment="kernel-livepatch-4_12_14-197_21-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048156"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712268" version="1" comment="kernel-livepatch-4_12_14-197_26-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712269" version="1" comment="kernel-livepatch-4_12_14-197_29-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048401"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712270" version="1" comment="kernel-livepatch-4_12_14-197_4-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712271" version="1" comment="kernel-livepatch-4_12_14-197_7-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334285" version="1" comment="openslp is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033994"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009481427" version="1" comment="liblua5_3-5 is &lt;5.3.4-3.3.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047091"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111770"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009629075" version="1" comment="slirp4netns is &lt;0.4.7-3.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047799"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148266"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712272" version="1" comment="kgraft-patch-4_4_120-94_17-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712273" version="1" comment="kgraft-patch-4_4_126-94_22-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042385"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712274" version="1" comment="kgraft-patch-4_4_131-94_29-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712275" version="1" comment="kgraft-patch-4_4_132-94_33-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712276" version="1" comment="kgraft-patch-4_4_138-94_39-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046471"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712277" version="1" comment="kgraft-patch-4_4_140-94_42-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046561"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712278" version="1" comment="kgraft-patch-4_4_143-94_47-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712279" version="1" comment="kgraft-patch-4_4_155-94_50-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712280" version="1" comment="kgraft-patch-4_4_156-94_57-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046853"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712281" version="1" comment="kgraft-patch-4_4_156-94_61-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046887"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712282" version="1" comment="kgraft-patch-4_4_156-94_64-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046993"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712283" version="1" comment="kgraft-patch-4_4_162-94_69-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046939"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712284" version="1" comment="kgraft-patch-4_4_162-94_72-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047097"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712285" version="1" comment="kgraft-patch-4_12_14-94_41-default is &gt;=4-2.10.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047099"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169970"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712286" version="1" comment="kgraft-patch-4_12_14-95_3-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047020"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712287" version="1" comment="kgraft-patch-4_12_14-95_6-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047080"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712288" version="1" comment="kernel-livepatch-4_12_14-25_13-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046840"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712289" version="1" comment="kernel-livepatch-4_12_14-25_16-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046688"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712290" version="1" comment="kernel-livepatch-4_12_14-25_19-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046851"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712291" version="1" comment="kernel-livepatch-4_12_14-25_22-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046880"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712292" version="1" comment="kernel-livepatch-4_12_14-25_25-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712293" version="1" comment="kernel-livepatch-4_12_14-25_28-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047083"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712294" version="1" comment="kernel-livepatch-4_12_14-25_6-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712295" version="1" comment="kgraft-patch-4_4_175-94_79-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047163"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712296" version="1" comment="kernel-default is &lt;4.4.175-94.79.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169971"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712297" version="1" comment="kernel-default is &lt;4.12.14-95.48.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169972"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712298" version="1" comment="kgraft-patch-4_12_14-122_17-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048685"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712299" version="1" comment="kernel-livepatch-4_12_14-197_34-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048662"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712300" version="1" comment="kernel-livepatch-4_12_14-197_37-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048742"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712301" version="1" comment="kernel-default is &lt;4.12.14-197.37.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169973"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482393" version="1" comment="libseccomp2 is &lt;2.4.1-3.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048063"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111982"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482020" version="1" comment="gstreamer-plugins-base is &lt;1.16.2-2.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111915"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482022" version="1" comment="libgstallocators-1_0-0 is &lt;1.16.2-2.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111915"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482023" version="1" comment="libgstapp-1_0-0 is &lt;1.16.2-2.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111915"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482024" version="1" comment="libgstaudio-1_0-0 is &lt;1.16.2-2.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111915"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482026" version="1" comment="libgstgl-1_0-0 is &lt;1.16.2-2.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041162"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111915"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482027" version="1" comment="libgstpbutils-1_0-0 is &lt;1.16.2-2.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041350"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111915"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482028" version="1" comment="libgstriff-1_0-0 is &lt;1.16.2-2.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041352"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111915"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482032" version="1" comment="libgsttag-1_0-0 is &lt;1.16.2-2.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041360"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111915"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482033" version="1" comment="libgstvideo-1_0-0 is &lt;1.16.2-2.12" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041362"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111915"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712302" version="1" comment="kgraft-patch-4_12_14-95_45-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048408"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712303" version="1" comment="kgraft-patch-4_12_14-95_48-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048683"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712304" version="1" comment="kgraft-patch-4_12_14-95_51-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048796"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712305" version="1" comment="kgraft-patch-4_12_14-95_54-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048888"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712306" version="1" comment="kernel-default is ==4.12.14-95.57.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169974"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712307" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712308" version="1" comment="kernel-default is ==4.12.14-95.60.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169975"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712309" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712310" version="1" comment="kernel-default is &lt;4.12.14-95.60.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169976"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712311" version="1" comment="kernel-livepatch-4_12_14-150_47-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048480"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712312" version="1" comment="kernel-livepatch-4_12_14-150_52-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048927"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712313" version="1" comment="kernel-default is ==4.12.14-150.55.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169977"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712314" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712315" version="1" comment="kernel-default is ==4.12.14-150.58.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169978"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712316" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712317" version="1" comment="kernel-default is &lt;4.12.14-150.58.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169979"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712318" version="1" comment="kgraft-patch-4_12_14-95_37-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712319" version="1" comment="kgraft-patch-4_12_14-95_40-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048207"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712320" version="1" comment="kgraft-patch-4_12_14-95_45-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048408"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712321" version="1" comment="kgraft-patch-4_12_14-95_48-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048683"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712322" version="1" comment="kgraft-patch-4_12_14-95_51-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048796"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712323" version="1" comment="kgraft-patch-4_12_14-120-default is &gt;=7-18.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048551"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169980"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712324" version="1" comment="kgraft-patch-4_12_14-122_12-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712325" version="1" comment="kgraft-patch-4_12_14-122_17-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048685"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712326" version="1" comment="kgraft-patch-4_12_14-122_20-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048798"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712327" version="1" comment="kgraft-patch-4_12_14-122_7-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048384"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712328" version="1" comment="kernel-livepatch-4_12_14-150_41-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712329" version="1" comment="kernel-livepatch-4_12_14-150_47-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048480"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712330" version="1" comment="kernel-livepatch-4_12_14-150_52-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048927"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712331" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712332" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712333" version="1" comment="kernel-livepatch-4_12_14-197_26-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712334" version="1" comment="kernel-livepatch-4_12_14-197_29-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048401"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712335" version="1" comment="kernel-livepatch-4_12_14-197_34-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048662"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712336" version="1" comment="kernel-livepatch-4_12_14-197_37-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048742"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712337" version="1" comment="kernel-livepatch-4_12_14-197_40-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048794"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712338" version="1" comment="kernel-default is &lt;4.12.14-197.40.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712339" version="1" comment="kernel-livepatch-4_12_14-150_52-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048927"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712340" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712341" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712342" version="1" comment="kernel-default is ==4.12.14-150.63.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169981"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712343" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712344" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712345" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712346" version="1" comment="kernel-default is &lt;4.12.14-150.69.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169982"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712347" version="1" comment="kgraft-patch-4_12_14-95_48-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048683"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712348" version="1" comment="kgraft-patch-4_12_14-95_51-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048796"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712349" version="1" comment="kgraft-patch-4_12_14-95_54-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048888"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712350" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712351" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712352" version="1" comment="kernel-default is ==4.12.14-95.65.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169983"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712353" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712354" version="1" comment="kernel-default is &lt;4.12.14-95.65.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169984"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712355" version="1" comment="kgraft-patch-4_12_14-122_17-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048685"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712356" version="1" comment="kgraft-patch-4_12_14-122_20-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048798"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712357" version="1" comment="kernel-default is ==4.12.14-122.23.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169985"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712358" version="1" comment="kgraft-patch-4_12_14-122_23-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712359" version="1" comment="kernel-default is ==4.12.14-122.26.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169986"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712360" version="1" comment="kgraft-patch-4_12_14-122_26-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048929"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712361" version="1" comment="kernel-default is ==4.12.14-122.29.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169987"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712362" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712363" version="1" comment="kernel-default is ==4.12.14-122.32.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169988"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712364" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712365" version="1" comment="kernel-default is ==4.12.14-122.37.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169989"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712366" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712367" version="1" comment="kernel-default is ==4.12.14-122.41.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169990"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712368" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712369" version="1" comment="kernel-default is ==4.12.14-122.46.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169991"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712370" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712371" version="1" comment="kernel-default is ==4.12.14-122.51.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169992"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712372" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712373" version="1" comment="kernel-default is ==4.12.14-122.54.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169993"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712374" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712375" version="1" comment="kernel-default is &lt;4.12.14-122.54.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169994"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712376" version="1" comment="kernel-livepatch-4_12_14-150_52-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048927"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712377" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712378" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712379" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712380" version="1" comment="kernel-default is &lt;4.12.14-150.63.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169995"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712381" version="1" comment="kernel-livepatch-4_12_14-197_34-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048662"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712382" version="1" comment="kernel-livepatch-4_12_14-197_37-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048742"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712383" version="1" comment="kernel-livepatch-4_12_14-197_40-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048794"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712384" version="1" comment="kernel-default is ==4.12.14-197.45.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169996"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712385" version="1" comment="kernel-livepatch-4_12_14-197_45-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048886"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712386" version="1" comment="kernel-default is ==4.12.14-197.48.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169997"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712387" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712388" version="1" comment="kernel-default is ==4.12.14-197.51.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169998"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712389" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712390" version="1" comment="kernel-default is ==4.12.14-197.56.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169999"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712391" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712392" version="1" comment="kernel-default is ==4.12.14-197.61.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170000"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712393" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712394" version="1" comment="kernel-default is ==4.12.14-197.64.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170001"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712395" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712396" version="1" comment="kernel-default is ==4.12.14-197.67.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170002"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712397" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712398" version="1" comment="kernel-default is ==4.12.14-197.72.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170003"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712399" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712400" version="1" comment="kernel-default is ==4.12.14-197.75.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170004"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712401" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712402" version="1" comment="kernel-default is &lt;4.12.14-197.75.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170005"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714897" version="1" comment="kernel-default is ==5.3.18-22.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170449"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712403" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=7-5.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170006"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712404" version="1" comment="kernel-default is ==5.3.18-24.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170007"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712405" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712406" version="1" comment="kernel-default is ==5.3.18-24.15.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170008"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712407" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712408" version="1" comment="kernel-default is ==5.3.18-24.9.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170009"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712409" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714898" version="1" comment="kernel-default is &lt;5.3.18-24.9.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170450"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712410" version="1" comment="kernel-default is ==5.3.18-24.24.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170010"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712411" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712412" version="1" comment="kernel-default is ==5.3.18-24.29.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170011"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712413" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712414" version="1" comment="kernel-default is ==5.3.18-24.34.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170012"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712415" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712416" version="1" comment="kernel-default is ==5.3.18-24.37.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170013"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712417" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712418" version="1" comment="kernel-default is ==5.3.18-24.43.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170014"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712419" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009629066" version="1" comment="cni-plugins is &lt;0.8.6-3.8.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048723"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148260"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705014" version="1" comment="libnghttp2-14 is &lt;1.40.0-3.5.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040283"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167763"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712420" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712421" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704937" version="1" comment="dbus-1 is &lt;1.12.2-8.11.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167734"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704938" version="1" comment="libdbus-1-3 is &lt;1.12.2-8.11.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167734"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712422" version="1" comment="kgraft-patch-4_12_14-122_12-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712423" version="1" comment="kgraft-patch-4_12_14-122_17-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048685"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712424" version="1" comment="kgraft-patch-4_12_14-122_20-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048798"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712425" version="1" comment="kgraft-patch-4_12_14-122_23-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712426" version="1" comment="kgraft-patch-4_12_14-122_26-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048929"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712427" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712428" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712429" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712430" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712431" version="1" comment="kernel-livepatch-4_12_14-197_29-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048401"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712432" version="1" comment="kernel-livepatch-4_12_14-197_34-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048662"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712433" version="1" comment="kernel-livepatch-4_12_14-197_37-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048742"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712434" version="1" comment="kernel-livepatch-4_12_14-197_40-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048794"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712435" version="1" comment="kernel-livepatch-4_12_14-197_45-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048886"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712436" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712437" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712438" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712439" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712440" version="1" comment="kernel-default is &lt;4.12.14-197.61.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170015"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712441" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=4-11.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169772"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712442" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712443" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712444" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712445" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705005" version="1" comment="kernel-default is &lt;5.3.18-24.52.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009116992"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705006" version="1" comment="kernel-default-base is &lt;5.3.18-24.52.1.9.24.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167760"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009632956" version="1" comment="libfreebl3 is &lt;3.68-3.56.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009149102"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009632960" version="1" comment="libsoftokn3 is &lt;3.68-3.56.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009149102"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009632964" version="1" comment="mozilla-nspr is &lt;4.32-3.20.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032358"/>
		<state state_ref="oval:org.opensuse.security:ste:2009149104"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009632967" version="1" comment="mozilla-nss is &lt;3.68-3.56.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032440"/>
		<state state_ref="oval:org.opensuse.security:ste:2009149102"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009632969" version="1" comment="mozilla-nss-certs is &lt;3.68-3.56.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033978"/>
		<state state_ref="oval:org.opensuse.security:ste:2009149102"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712446" version="1" comment="kgraft-patch-4_12_14-95_16-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047380"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712447" version="1" comment="kgraft-patch-4_12_14-95_19-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712448" version="1" comment="kgraft-patch-4_12_14-95_24-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047614"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712449" version="1" comment="kgraft-patch-4_12_14-95_29-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047745"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712450" version="1" comment="kgraft-patch-4_12_14-95_32-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047922"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712451" version="1" comment="kgraft-patch-4_12_14-95_37-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712452" version="1" comment="kgraft-patch-4_12_14-95_40-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048207"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712453" version="1" comment="kgraft-patch-4_12_14-95_45-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048408"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712454" version="1" comment="kgraft-patch-4_12_14-95_48-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048683"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712455" version="1" comment="kgraft-patch-4_12_14-95_51-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048796"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712456" version="1" comment="kgraft-patch-4_12_14-120-default is &gt;=4-9.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048551"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170016"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712457" version="1" comment="kgraft-patch-4_12_14-122_12-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712458" version="1" comment="kgraft-patch-4_12_14-122_17-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048685"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712459" version="1" comment="kgraft-patch-4_12_14-122_20-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048798"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712460" version="1" comment="kgraft-patch-4_12_14-122_7-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048384"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712461" version="1" comment="kernel-livepatch-4_12_14-150_17-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047376"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712462" version="1" comment="kernel-livepatch-4_12_14-150_22-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712463" version="1" comment="kernel-livepatch-4_12_14-150_27-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047610"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712464" version="1" comment="kernel-livepatch-4_12_14-150_32-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047743"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712465" version="1" comment="kernel-livepatch-4_12_14-150_35-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047918"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712466" version="1" comment="kernel-livepatch-4_12_14-150_38-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048154"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712467" version="1" comment="kernel-livepatch-4_12_14-150_41-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712468" version="1" comment="kernel-livepatch-4_12_14-150_47-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048480"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712469" version="1" comment="kernel-livepatch-4_12_14-195-default is &gt;=11-31.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170017"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712470" version="1" comment="kernel-livepatch-4_12_14-197_10-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047612"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712471" version="1" comment="kernel-livepatch-4_12_14-197_15-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048066"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712472" version="1" comment="kernel-livepatch-4_12_14-197_18-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047920"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712473" version="1" comment="kernel-livepatch-4_12_14-197_21-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048156"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712474" version="1" comment="kernel-livepatch-4_12_14-197_26-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712475" version="1" comment="kernel-livepatch-4_12_14-197_29-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048401"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712476" version="1" comment="kernel-livepatch-4_12_14-197_34-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048662"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712477" version="1" comment="kernel-livepatch-4_12_14-197_37-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048742"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712478" version="1" comment="kernel-livepatch-4_12_14-197_4-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712479" version="1" comment="kernel-livepatch-4_12_14-197_40-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048794"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712480" version="1" comment="kernel-livepatch-4_12_14-197_7-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009664167" version="1" comment="libjson-c3 is &lt;0.13-3.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042541"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156735"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704945" version="1" comment="libcroco-0_6-3 is &lt;0.6.13-3.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042528"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167739"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704859" version="1" comment="qemu is &lt;4.2.1-11.16.3 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167702"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499829" version="1" comment="qemu-arm is &lt;4.2.1-11.16.3 for aarch64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038462"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118518"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499837" version="1" comment="qemu-ipxe is &lt;1.0.0+-11.16.3 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037631"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118520"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499843" version="1" comment="qemu-seabios is &lt;1.12.1+-11.16.3 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037633"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118525"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499844" version="1" comment="qemu-sgabios is &lt;8-11.16.3 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118526"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704860" version="1" comment="qemu-tools is &lt;4.2.1-11.16.3 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036248"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167702"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499848" version="1" comment="qemu-vgabios is &lt;1.12.1+-11.16.3 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037635"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118525"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499849" version="1" comment="qemu-x86 is &lt;4.2.1-11.16.3 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118519"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705033" version="1" comment="qemu is &lt;4.2.1-11.34.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167775"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705034" version="1" comment="qemu-arm is &lt;4.2.1-11.34.2 for aarch64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038462"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167776"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667529" version="1" comment="qemu-ipxe is &lt;1.0.0+-11.34.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037631"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157350"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667533" version="1" comment="qemu-seabios is &lt;1.12.1+-11.34.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037633"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157352"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667534" version="1" comment="qemu-sgabios is &lt;8-11.34.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157353"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705035" version="1" comment="qemu-tools is &lt;4.2.1-11.34.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036248"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167775"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667539" version="1" comment="qemu-vgabios is &lt;1.12.1+-11.34.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037635"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157352"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667540" version="1" comment="qemu-x86 is &lt;4.2.1-11.34.2 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157349"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705002" version="1" comment="glib-networking is &lt;2.62.4-3.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050291"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628610" version="1" comment="libgcc_s1 is &lt;10.2.1+git583-1.3.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040358"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148136"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628625" version="1" comment="libstdc++6 is &lt;10.2.1+git583-1.3.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040364"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148136"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705047" version="1" comment="iscsiuio is &lt;0.7.8.6-22.14.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050199"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167783"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705048" version="1" comment="libopeniscsiusr0_2_0 is &lt;2.1.4-22.14.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167784"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705049" version="1" comment="open-iscsi is &lt;2.1.4-22.14.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032231"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167784"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009653320" version="1" comment="dnsmasq is &lt;2.86-7.14.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031669"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154953"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712481" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712482" version="1" comment="kernel-default is &lt;4.12.14-95.57.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170018"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712483" version="1" comment="kgraft-patch-4_12_14-122_20-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048798"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712484" version="1" comment="kgraft-patch-4_12_14-122_23-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712485" version="1" comment="kgraft-patch-4_12_14-122_26-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048929"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712486" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712487" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712488" version="1" comment="kernel-default is &lt;4.12.14-150.55.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170019"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712489" version="1" comment="kernel-livepatch-4_12_14-197_40-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048794"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712490" version="1" comment="kernel-livepatch-4_12_14-197_45-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048886"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712491" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712492" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712493" version="1" comment="kernel-default is &lt;4.12.14-197.51.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170020"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712494" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=2-5.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170021"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712495" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=2-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170022"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009511395" version="1" comment="python3-PyYAML is &lt;5.3.1-6.10.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048670"/>
		<state state_ref="oval:org.opensuse.security:ste:2009120651"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712496" version="1" comment="kgraft-patch-4_12_14-95_54-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048888"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712497" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712498" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712499" version="1" comment="kgraft-patch-4_12_14-122_23-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712500" version="1" comment="kgraft-patch-4_12_14-122_26-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048929"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712501" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712502" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712503" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712504" version="1" comment="kernel-livepatch-4_12_14-197_45-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048886"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712505" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712506" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712507" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712508" version="1" comment="kernel-default is &lt;4.12.14-197.56.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170023"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712509" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=3-8.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169771"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712510" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712511" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712512" version="1" comment="kernel-default is &lt;4.12.14-197.45.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170024"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009482053" version="1" comment="kernel-default is &lt;5.3.18-22.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009111923"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009348261" version="1" comment="liblua5_3-5 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047091"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712513" version="1" comment="kgraft-patch-4_12_14-95_48-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048683"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712514" version="1" comment="kgraft-patch-4_12_14-122_17-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048685"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712515" version="1" comment="kernel-livepatch-4_12_14-197_34-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048662"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712516" version="1" comment="kernel-livepatch-4_12_14-197_37-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048742"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704903" version="1" comment="libjpeg8 is &lt;8.1.2-5.18.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038279"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167724"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704904" version="1" comment="liblua5_3-5 is &lt;5.3.6-3.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047091"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167725"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009494035" version="1" comment="ucode-intel is &lt;20210525-7.1 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042104"/>
		<state state_ref="oval:org.opensuse.security:ste:2009116922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704896" version="1" comment="kernel-default is &lt;5.3.18-24.67.3 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167719"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704897" version="1" comment="kernel-default-base is &lt;5.3.18-24.67.3.9.30.2 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167720"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009498554" version="1" comment="kernel-rt is &lt;5.3.18-8.13.1 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712517" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712518" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009760823" version="1" comment="libproxy1 is &lt;0.4.15-4.3.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036471"/>
		<state state_ref="oval:org.opensuse.security:ste:2009180711"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503809" version="1" comment="libruby2_5-2_5 is &lt;2.5.8-4.14.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047596"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119123"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503810" version="1" comment="ruby2.5 is &lt;2.5.8-4.14.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119123"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503813" version="1" comment="ruby2.5-stdlib is &lt;2.5.8-4.14.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047600"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119123"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712519" version="1" comment="kgraft-patch-4_12_14-95_45-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048408"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712520" version="1" comment="kgraft-patch-4_12_14-95_48-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048683"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712521" version="1" comment="kgraft-patch-4_12_14-95_51-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048796"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712522" version="1" comment="kgraft-patch-4_12_14-95_54-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048888"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712523" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712524" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712525" version="1" comment="kgraft-patch-4_12_14-120-default is &gt;=9-3.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048551"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170025"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712526" version="1" comment="kgraft-patch-4_12_14-122_12-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712527" version="1" comment="kgraft-patch-4_12_14-122_17-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048685"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712528" version="1" comment="kgraft-patch-4_12_14-122_20-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048798"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712529" version="1" comment="kgraft-patch-4_12_14-122_23-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712530" version="1" comment="kgraft-patch-4_12_14-122_26-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048929"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712531" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712532" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712533" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712534" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712535" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712536" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712537" version="1" comment="kgraft-patch-4_12_14-122_7-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048384"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712538" version="1" comment="kernel-livepatch-4_12_14-150_47-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048480"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712539" version="1" comment="kernel-livepatch-4_12_14-150_52-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048927"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712540" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712541" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712542" version="1" comment="kernel-livepatch-4_12_14-197_29-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048401"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712543" version="1" comment="kernel-livepatch-4_12_14-197_34-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048662"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712544" version="1" comment="kernel-livepatch-4_12_14-197_37-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048742"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712545" version="1" comment="kernel-livepatch-4_12_14-197_40-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048794"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712546" version="1" comment="kernel-livepatch-4_12_14-197_45-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048886"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712547" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712548" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712549" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712550" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712551" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712552" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712553" version="1" comment="kernel-default is &lt;4.12.14-197.67.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170026"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712554" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=5-5.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170027"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712555" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712556" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712557" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712558" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712559" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712560" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712561" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712562" version="1" comment="kernel-default is &lt;4.12.14-95.71.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170028"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712563" version="1" comment="kernel-default is ==4.12.14-122.60.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170029"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712564" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712565" version="1" comment="kernel-default is ==4.12.14-122.63.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170030"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712566" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712567" version="1" comment="kernel-default is &lt;4.12.14-122.63.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170031"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712568" version="1" comment="kernel-default is ==4.12.14-197.83.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170032"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712569" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712570" version="1" comment="kernel-default is ==4.12.14-197.86.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170033"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712571" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712572" version="1" comment="kernel-default is &lt;4.12.14-197.86.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170034"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712573" version="1" comment="kernel-default is ==5.3.18-24.49.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170035"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712574" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712575" version="1" comment="kernel-default is ==5.3.18-24.52.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170036"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712576" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712577" version="1" comment="kernel-default is &lt;5.3.18-24.52.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170037"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698763" version="1" comment="kernel-default is ==5.3.18-57.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166547"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712578" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=10-3.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170038"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628531" version="1" comment="kernel-default is &lt;5.3.18-57.3" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148129"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626945" version="1" comment="python3-asn1crypto is &lt;0.24.0-3.2.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048667"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147861"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704939" version="1" comment="python3-cffi is &lt;1.13.2-3.2.5 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048729"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167735"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704940" version="1" comment="python3-cryptography is &lt;2.8-10.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009046896"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167736"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626950" version="1" comment="python3-pyOpenSSL is &lt;17.5.0-8.3.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147866"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626951" version="1" comment="python3-pyasn1 is &lt;0.4.2-3.2.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052216"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147867"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626952" version="1" comment="python3-pycparser is &lt;2.17-3.2.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052217"/>
		<state state_ref="oval:org.opensuse.security:ste:2009117701"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626953" version="1" comment="python3-urllib3 is &lt;1.25.10-9.14.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147868"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704907" version="1" comment="kernel-default is &lt;5.3.18-24.70.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147251"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704908" version="1" comment="kernel-default-base is &lt;5.3.18-24.70.1.9.32.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167727"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712579" version="1" comment="kgraft-patch-4_12_14-95_48-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048683"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712580" version="1" comment="kgraft-patch-4_12_14-95_51-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048796"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712581" version="1" comment="kgraft-patch-4_12_14-95_54-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048888"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712582" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712583" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712584" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712585" version="1" comment="kgraft-patch-4_12_14-122_17-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048685"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712586" version="1" comment="kgraft-patch-4_12_14-122_20-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048798"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712587" version="1" comment="kgraft-patch-4_12_14-122_23-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712588" version="1" comment="kgraft-patch-4_12_14-122_26-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048929"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712589" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712590" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712591" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712592" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712593" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712594" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712595" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712596" version="1" comment="kernel-default is ==4.12.14-122.57.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170040"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712597" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712598" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712599" version="1" comment="kernel-default is &lt;4.12.14-122.60.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170041"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712600" version="1" comment="kernel-livepatch-4_12_14-150_52-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048927"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712601" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712602" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712603" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712604" version="1" comment="kernel-livepatch-4_12_14-197_34-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048662"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712605" version="1" comment="kernel-livepatch-4_12_14-197_37-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048742"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712606" version="1" comment="kernel-livepatch-4_12_14-197_40-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048794"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712607" version="1" comment="kernel-livepatch-4_12_14-197_45-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048886"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712608" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712609" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712610" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712611" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712612" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712613" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712614" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712615" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712616" version="1" comment="kernel-default is ==4.12.14-197.78.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170042"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712617" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712618" version="1" comment="kernel-default is &lt;4.12.14-197.78.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170043"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009664563" version="1" comment="kernel-default is &lt;5.3.18-24.99.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156840"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009664564" version="1" comment="kernel-default-base is &lt;5.3.18-24.99.1.9.46.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156841"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009658974" version="1" comment="kernel-rt is &lt;5.3.18-62.2 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155784"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712619" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=8-5.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170044"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712620" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712621" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712622" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712623" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712624" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712625" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712626" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712627" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009672628" version="1" comment="slirp4netns is &lt;0.4.7-3.15.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047799"/>
		<state state_ref="oval:org.opensuse.security:ste:2009158159"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659809" version="1" comment="libp11-kit0 is &lt;0.23.2-4.13.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047355"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155941"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659810" version="1" comment="p11-kit is &lt;0.23.2-4.13.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047357"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155941"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659813" version="1" comment="p11-kit-tools is &lt;0.23.2-4.13.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047360"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155941"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712628" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712629" version="1" comment="kernel-default is &lt;4.12.14-95.68.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170045"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712630" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712631" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712632" version="1" comment="kernel-default is &lt;4.12.14-150.66.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170046"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712633" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712634" version="1" comment="kernel-default is &lt;4.12.14-197.83.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170047"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712635" version="1" comment="kernel-default is ==5.3.18-24.46.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170048"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712636" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712637" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712638" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=6-5.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170049"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712639" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712640" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712641" version="1" comment="kernel-default is &lt;4.12.14-122.57.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170050"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712642" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009494015" version="1" comment="python3-py is &lt;1.8.1-5.6.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050228"/>
		<state state_ref="oval:org.opensuse.security:ste:2009116910"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704934" version="1" comment="qemu is &lt;4.2.1-11.28.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167733"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009630345" version="1" comment="qemu-arm is &lt;4.2.1-11.28.1 for aarch64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038462"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148472"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009630353" version="1" comment="qemu-ipxe is &lt;1.0.0+-11.28.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037631"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148474"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009630359" version="1" comment="qemu-seabios is &lt;1.12.1+-11.28.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037633"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148479"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009630360" version="1" comment="qemu-sgabios is &lt;8-11.28.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148480"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704935" version="1" comment="qemu-tools is &lt;4.2.1-11.28.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036248"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167733"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009630364" version="1" comment="qemu-vgabios is &lt;1.12.1+-11.28.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037635"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148479"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009630365" version="1" comment="qemu-x86 is &lt;4.2.1-11.28.1 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148473"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009615809" version="1" comment="dbus-1 is &lt;1.12.2-8.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009145986"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009615812" version="1" comment="libdbus-1-3 is &lt;1.12.2-8.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009145986"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712643" version="1" comment="kgraft-patch-4_12_14-95_54-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048888"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712644" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712645" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712646" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712647" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712648" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712649" version="1" comment="kgraft-patch-4_12_14-122_23-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712650" version="1" comment="kgraft-patch-4_12_14-122_26-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048929"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712651" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712652" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712653" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712654" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712655" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712656" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712657" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712658" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712659" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712660" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712661" version="1" comment="kernel-default is ==4.12.14-122.66.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170052"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712662" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712663" version="1" comment="kernel-default is &lt;4.12.14-122.66.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170053"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712664" version="1" comment="kernel-livepatch-4_12_14-197_45-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048886"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712665" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712666" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712667" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712668" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712669" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712670" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712671" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712672" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712673" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712674" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712675" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712676" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=11-5.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170054"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712677" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712678" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712679" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712680" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712681" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712682" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712683" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712684" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712685" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712686" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698736" version="1" comment="kernel-default is ==5.3.18-24.53.4.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166524"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712687" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712688" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712689" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=2-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169766"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712690" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712691" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712692" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712693" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712694" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712695" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712696" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712697" version="1" comment="kernel-default is &lt;4.12.14-95.77.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170055"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712698" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712699" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712700" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712701" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712702" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712703" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712704" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712705" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712706" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712707" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712708" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698703" version="1" comment="kernel-default is ==4.12.14-122.71.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166496"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712709" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698705" version="1" comment="kernel-default is ==4.12.14-122.74.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166497"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712710" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698707" version="1" comment="kernel-default is ==4.12.14-122.77.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166499"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712711" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712712" version="1" comment="kernel-default is &lt;4.12.14-122.77.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170057"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712713" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712714" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712715" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712716" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712717" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712718" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712719" version="1" comment="kernel-default is &lt;4.12.14-150.72.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170058"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712720" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712721" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712722" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712723" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712724" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712725" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712726" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712727" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712728" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712729" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712730" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698729" version="1" comment="kernel-default is ==4.12.14-197.89.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166517"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712731" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698731" version="1" comment="kernel-default is ==4.12.14-197.92.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166519"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712732" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712733" version="1" comment="kernel-default is &lt;4.12.14-197.92.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170059"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712734" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=14-5.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170060"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712735" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712736" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712737" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712738" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712739" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712740" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712741" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712742" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712743" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712744" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698791" version="1" comment="kernel-default is ==5.3.18-24.61.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166570"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712745" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698738" version="1" comment="kernel-default is ==5.3.18-24.64.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166526"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712746" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698740" version="1" comment="kernel-default is ==5.3.18-24.67.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166528"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712747" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712748" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712749" version="1" comment="kernel-default is ==4.12.14-95.102.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170061"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712750" version="1" comment="kgraft-patch-4_12_14-95_102-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060093"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712751" version="1" comment="kernel-default is ==4.12.14-95.105.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170062"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712752" version="1" comment="kgraft-patch-4_12_14-95_105-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060221"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712753" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=13-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170063"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701405" version="1" comment="kernel-default is ==4.12.14-95.88.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167184"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712754" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=9-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170064"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701143" version="1" comment="kernel-default is ==4.12.14-95.93.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167107"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712755" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=8-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167189"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701407" version="1" comment="kernel-default is ==4.12.14-95.96.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167186"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712756" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=7-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167185"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701145" version="1" comment="kernel-default is ==4.12.14-95.99.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167109"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712757" version="1" comment="kgraft-patch-4_12_14-95_99-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059968"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701147" version="1" comment="kernel-default is &lt;4.12.14-95.99.3" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167111"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698699" version="1" comment="kernel-default is ==4.12.14-122.103.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166493"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712758" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=14-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167115"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698701" version="1" comment="kernel-default is ==4.12.14-122.106.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166494"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712759" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=12-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167116"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701411" version="1" comment="kernel-default is ==4.12.14-122.110.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167188"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712760" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=10-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167187"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701413" version="1" comment="kernel-default is ==4.12.14-122.113.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167190"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712761" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=9-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170064"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701148" version="1" comment="kernel-default is ==4.12.14-122.116.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167112"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712762" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=7-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167185"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701415" version="1" comment="kernel-default is ==4.12.14-122.121.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167191"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712763" version="1" comment="kgraft-patch-4_12_14-122_121-default is &gt;=5-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167113"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701150" version="1" comment="kernel-default is ==4.12.14-122.124.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167114"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712764" version="1" comment="kgraft-patch-4_12_14-122_124-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712765" version="1" comment="kernel-default is ==4.12.14-122.127.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170065"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712766" version="1" comment="kgraft-patch-4_12_14-122_127-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060094"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712767" version="1" comment="kernel-default is ==4.12.14-122.130.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170066"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712768" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698713" version="1" comment="kernel-default is ==4.12.14-122.88.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166503"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712769" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=16-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167105"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698715" version="1" comment="kernel-default is ==4.12.14-122.91.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166505"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712770" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=16-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167105"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698717" version="1" comment="kernel-default is ==4.12.14-122.98.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166506"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712771" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=14-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167115"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698719" version="1" comment="kernel-default is &lt;4.12.14-122.98.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166507"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701421" version="1" comment="kernel-default is ==4.12.14-150000.150.89.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167195"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712772" version="1" comment="kernel-livepatch-4_12_14-150000_150_89-default is &gt;=7-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059651"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170067"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701260" version="1" comment="kernel-default is ==4.12.14-150000.150.92.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167140"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712773" version="1" comment="kernel-livepatch-4_12_14-150000_150_92-default is &gt;=4-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059889"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170068"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712774" version="1" comment="kernel-default is ==4.12.14-150000.150.95.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170069"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712775" version="1" comment="kernel-livepatch-4_12_14-150000_150_95-default is &gt;=2-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060077"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167141"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712776" version="1" comment="kernel-default is ==4.12.14-150000.150.98.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170070"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712777" version="1" comment="kernel-livepatch-4_12_14-150000_150_98-default is &gt;=2-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060219"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167141"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712778" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=13-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170071"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701262" version="1" comment="kernel-default is ==4.12.14-150.83.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167142"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712779" version="1" comment="kernel-livepatch-4_12_14-150_83-default is &gt;=9-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170072"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701425" version="1" comment="kernel-default is ==4.12.14-150.86.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167199"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712780" version="1" comment="kernel-livepatch-4_12_14-150_86-default is &gt;=8-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059474"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170073"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701427" version="1" comment="kernel-default is &lt;4.12.14-150.86.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167201"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701265" version="1" comment="kernel-default is ==4.12.14-150100.197.111.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167145"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712781" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=7-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170074"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701154" version="1" comment="kernel-default is ==4.12.14-150100.197.114.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167117"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712782" version="1" comment="kernel-livepatch-4_12_14-150100_197_114-default is &gt;=4-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170075"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712783" version="1" comment="kernel-default is ==4.12.14-150100.197.117.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170076"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712784" version="1" comment="kernel-livepatch-4_12_14-150100_197_117-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060078"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712785" version="1" comment="kernel-default is ==4.12.14-150100.197.120.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170077"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712786" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698727" version="1" comment="kernel-default is ==4.12.14-197.102.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166515"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712787" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=13-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170078"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701428" version="1" comment="kernel-default is ==4.12.14-197.105.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167202"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712788" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=9-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170079"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701268" version="1" comment="kernel-default is ==4.12.14-197.108.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712789" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=8-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170080"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701270" version="1" comment="kernel-default is &lt;4.12.14-197.108.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167150"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698822" version="1" comment="kernel-default is ==5.3.18-150200.24.112.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166583"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712790" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=7-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170081"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698824" version="1" comment="kernel-default is ==5.3.18-150200.24.115.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166585"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712791" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=5-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166567"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009709908" version="1" comment="kernel-default is ==5.3.18-150200.24.126.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169353"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009709909" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=2-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169354"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698786" version="1" comment="kernel-default is ==5.3.18-24.102.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166566"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712792" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=12-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166593"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698788" version="1" comment="kernel-default is ==5.3.18-24.107.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166568"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712793" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=11-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166594"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698748" version="1" comment="kernel-default is ==5.3.18-24.83.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166534"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712794" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=16-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166590"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698750" version="1" comment="kernel-default is ==5.3.18-24.86.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166536"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712795" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=16-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166590"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698752" version="1" comment="kernel-default is ==5.3.18-24.93.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166537"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712796" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=15-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166591"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698754" version="1" comment="kernel-default is ==5.3.18-24.96.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166539"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712797" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=14-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170082"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698756" version="1" comment="kernel-default is ==5.3.18-24.99.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166541"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712798" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=13-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166592"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698758" version="1" comment="kernel-default is &lt;5.3.18-24.99.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166543"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698759" version="1" comment="kernel-default is ==5.3.18-150300.59.43.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166544"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712799" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698761" version="1" comment="kernel-default is ==5.3.18-150300.59.46.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166546"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712800" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698805" version="1" comment="kernel-default is ==5.3.18-150300.59.49.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166575"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712801" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698807" version="1" comment="kernel-default is ==5.3.18-150300.59.54.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166577"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712802" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698809" version="1" comment="kernel-default is ==5.3.18-150300.59.60.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166579"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712803" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=10-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166596"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698842" version="1" comment="kernel-default is ==5.3.18-150300.59.63.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166600"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712804" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=7-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166599"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698844" version="1" comment="kernel-default is ==5.3.18-150300.59.68.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166602"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712805" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=6-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170083"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698846" version="1" comment="kernel-default is ==5.3.18-150300.59.71.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166604"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712806" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701403" version="1" comment="kernel-default is ==5.3.18-150300.59.76.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167183"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712807" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009706111" version="1" comment="kernel-default is ==5.3.18-150300.59.87.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168229"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712808" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698773" version="1" comment="kernel-default is ==5.3.18-59.24.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166556"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712809" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698775" version="1" comment="kernel-default is ==5.3.18-59.27.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166558"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712810" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698777" version="1" comment="kernel-default is ==5.3.18-59.34.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166559"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712811" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698779" version="1" comment="kernel-default is ==5.3.18-59.37.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166561"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712812" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698781" version="1" comment="kernel-default is ==5.3.18-59.40.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166563"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712813" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701452" version="1" comment="kernel-default is &lt;5.3.18-59.40.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167221"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698874" version="1" comment="kernel-default is ==5.14.21-150400.22.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166613"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712814" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=5-150400.4.12.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170085"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712815" version="1" comment="kernel-default is ==5.14.21-150400.24.11.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170086"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712816" version="1" comment="kernel-livepatch-5_14_21-150400_24_11-default is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060153"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712817" version="1" comment="kernel-default is ==5.14.21-150400.24.18.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170088"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712818" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712819" version="1" comment="kernel-default is &lt;5.14.21-150400.24.18.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170089"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725853" version="1" comment="kernel-livepatch-4_12_14-150000_150_89-default is &gt;=9-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059651"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170072"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725854" version="1" comment="kernel-livepatch-4_12_14-150000_150_92-default is &gt;=6-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059889"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170166"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725497" version="1" comment="kernel-livepatch-4_12_14-150000_150_95-default is &gt;=4-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060077"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170068"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725855" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=15-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170157"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725856" version="1" comment="kernel-livepatch-4_12_14-150_83-default is &gt;=11-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173046"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725857" version="1" comment="kernel-livepatch-4_12_14-150_86-default is &gt;=10-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059474"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170158"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712820" version="1" comment="kernel-default is &lt;4.12.14-95.80.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170090"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712821" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712822" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712823" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712824" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698709" version="1" comment="kernel-default is ==4.12.14-122.80.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166500"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712825" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698711" version="1" comment="kernel-default is ==4.12.14-122.83.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166501"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712826" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712827" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712828" version="1" comment="kernel-default is &lt;4.12.14-122.88.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170091"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712829" version="1" comment="kernel-default is &lt;4.12.14-150.75.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170092"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712830" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712831" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698733" version="1" comment="kernel-default is ==4.12.14-197.99.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166521"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712832" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698735" version="1" comment="kernel-default is &lt;4.12.14-197.99.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166523"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712833" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712834" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712835" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712836" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698742" version="1" comment="kernel-default is ==5.3.18-24.70.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166529"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712837" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698744" version="1" comment="kernel-default is ==5.3.18-24.75.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166530"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712838" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698746" version="1" comment="kernel-default is ==5.3.18-24.78.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166532"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712839" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712840" version="1" comment="kernel-default is &lt;5.3.18-24.78.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170093"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698765" version="1" comment="kernel-default is ==5.3.18-59.10.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166549"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712841" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698767" version="1" comment="kernel-default is ==5.3.18-59.13.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166551"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712842" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698769" version="1" comment="kernel-default is ==5.3.18-59.16.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166552"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712843" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=7-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166599"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698771" version="1" comment="kernel-default is ==5.3.18-59.19.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166554"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712844" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=6-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170083"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698783" version="1" comment="kernel-default is ==5.3.18-59.5.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166564"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712845" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698785" version="1" comment="kernel-default is &lt;5.3.18-59.5.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166565"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704954" version="1" comment="kernel-default is &lt;5.3.18-24.86.2 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154718"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704955" version="1" comment="kernel-default-base is &lt;5.3.18-24.86.2.9.40.2 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167745"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009651689" version="1" comment="kernel-rt is &lt;5.3.18-54.1 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154640"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704956" version="1" comment="kmod is &lt;25-6.10.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058493"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704957" version="1" comment="kmod-compat is &lt;25-6.10.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704958" version="1" comment="libkmod2 is &lt;25-6.10.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058497"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704959" version="1" comment="perl-Bootloader is &lt;0.931-3.5.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032527"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167747"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334435" version="1" comment="docker is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038208"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334187" version="1" comment="python3 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037061"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712846" version="1" comment="kernel-default is &lt;4.12.14-197.64.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170094"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009669993" version="1" comment="kernel-firmware is &lt;20200107-3.26.1 for noarch" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042041"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009669994" version="1" comment="ucode-amd is &lt;20200107-3.26.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042042"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009632243" version="1" comment="xen-libs is &lt;4.13.3_02-3.34.1 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148898"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667863" version="1" comment="ucode-intel is &lt;20220207-10.1 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042104"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157420"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338728" version="1" comment="ucode-intel is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042104"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712847" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712848" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712849" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712850" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712851" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712852" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712853" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712854" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712855" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712856" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712857" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712858" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712859" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712860" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712861" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712862" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712863" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712864" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712865" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712866" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712867" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712868" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712869" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712870" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712871" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712872" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712873" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712874" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712875" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712876" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712877" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712878" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=8-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167189"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712879" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712880" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712881" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712882" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712883" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=13-5.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170095"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712884" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712885" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712886" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712887" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712888" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712889" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712890" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712891" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712892" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712893" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712894" version="1" comment="kernel-default is &lt;4.12.14-122.32.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170096"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712895" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712896" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712897" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712898" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712899" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712900" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712901" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712902" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=13-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712903" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712904" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712905" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712906" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712907" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712908" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712909" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712910" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712911" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712912" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712913" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712914" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712915" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712916" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712917" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712918" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712919" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712920" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712921" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=2-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169354"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712922" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712923" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712924" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712925" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712926" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712927" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712928" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712929" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712930" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712931" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712932" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712933" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712934" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712935" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712936" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712937" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712938" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712939" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=12-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170097"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712940" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=10-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712941" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=10-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712942" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=9-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166560"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712943" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712944" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712945" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712946" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712947" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712948" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712949" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=10-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009679192" version="1" comment="kernel-default is &lt;5.3.18-150200.24.112.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009159922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009679193" version="1" comment="kernel-default-base is &lt;5.3.18-150200.24.112.1.150200.9.52.2 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009159923"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009679475" version="1" comment="kernel-rt is &lt;5.3.18-150200.79.2 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009159984"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712950" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712951" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712952" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712953" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712954" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712955" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712956" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712957" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712958" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712959" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712960" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712961" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712962" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712963" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712964" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712965" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712966" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712967" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712968" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712969" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712970" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712971" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712972" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712973" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712974" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712975" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712976" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712977" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712978" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712979" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712980" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712981" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712982" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712983" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712984" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712985" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712986" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712987" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712988" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712989" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712990" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712991" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712992" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712993" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712994" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712995" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712996" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712997" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712998" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009712999" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713000" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713001" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713002" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713003" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713004" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713005" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713006" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713007" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713008" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713009" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713010" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713011" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713012" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713013" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713014" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713015" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713016" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713017" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713018" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713019" version="1" comment="kernel-default is &lt;5.3.18-24.53.4.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170098"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713020" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=9-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170099"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705000" version="1" comment="kernel-default is &lt;5.3.18-24.96.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155535"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705001" version="1" comment="kernel-default-base is &lt;5.3.18-24.96.1.9.44.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167756"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704902" version="1" comment="libspice-server1 is &lt;0.14.2-3.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167723"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705015" version="1" comment="libgnutls30 is &lt;3.6.7-14.10.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042507"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167764"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704952" version="1" comment="python3-rpm is &lt;4.14.1-22.4.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038306"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167743"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704953" version="1" comment="rpm is &lt;4.14.1-22.4.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032541"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167744"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503185" version="1" comment="libhogweed4 is &lt;3.4.1-4.15.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042537"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119003"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503187" version="1" comment="libnettle6 is &lt;3.4.1-4.15.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042538"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119003"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713021" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713022" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713023" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713024" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713025" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713026" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713027" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713028" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713029" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713030" version="1" comment="kernel-default is &lt;5.3.18-24.93.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170100"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713031" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713032" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713033" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713034" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713035" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713036" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713037" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713038" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009504109" version="1" comment="containerd is &lt;1.4.4-5.32.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119164"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009504110" version="1" comment="docker is &lt;20.10.6_ce-6.49.3 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038208"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119165"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009504111" version="1" comment="runc is &lt;1.0.0~rc93-1.14.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040911"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119166"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704932" version="1" comment="kernel-default is &lt;5.3.18-24.78.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147966"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704933" version="1" comment="kernel-default-base is &lt;5.3.18-24.78.1.9.36.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167732"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009628046" version="1" comment="kernel-rt is &lt;5.3.18-48.1 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148014"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704973" version="1" comment="python3-salt is &lt;3002.2-49.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042407"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167752"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704974" version="1" comment="salt is &lt;3002.2-49.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040290"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167752"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704975" version="1" comment="salt-minion is &lt;3002.2-49.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040297"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167752"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704976" version="1" comment="salt-transactional-update is &lt;3002.2-49.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051618"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167752"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713041" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713042" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713043" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713044" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713045" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713046" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713047" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713048" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=16-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170103"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713049" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713050" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713051" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713052" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713053" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713054" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713055" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713056" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713057" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713058" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713059" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713060" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713061" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713062" version="1" comment="kernel-default is &lt;4.12.14-122.80.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170104"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713063" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713064" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713065" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713066" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713067" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713068" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713069" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713070" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713071" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713072" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713073" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713074" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713075" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713076" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713077" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713078" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713079" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713080" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713081" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713082" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713083" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713084" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713085" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713086" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713087" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713088" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713089" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713090" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713091" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713092" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713093" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713094" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713095" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713096" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713097" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713098" version="1" comment="kernel-default is &lt;5.3.18-24.75.3" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170105"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713099" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=5-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170106"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713100" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713101" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713102" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713103" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713104" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713105" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=4-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169821"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713106" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713107" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713108" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704910" version="1" comment="kernel-default is &lt;5.3.18-24.75.3 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147622"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704911" version="1" comment="kernel-default-base is &lt;5.3.18-24.75.3.9.34.3 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167729"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626892" version="1" comment="kernel-rt is &lt;5.3.18-45.3 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147844"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705023" version="1" comment="libprotobuf-lite20 is &lt;3.9.2-4.12.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059490"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167769"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667498" version="1" comment="kernel-default is &lt;5.3.18-24.102.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157342"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667499" version="1" comment="kernel-default-base is &lt;5.3.18-24.102.1.9.48.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157343"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009668286" version="1" comment="kernel-rt is &lt;5.3.18-73.1 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157486"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704853" version="1" comment="curl is &lt;7.66.0-4.14.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030596"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167698"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704854" version="1" comment="libcurl4 is &lt;7.66.0-4.14.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030964"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167698"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704879" version="1" comment="curl is &lt;7.66.0-4.17.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030596"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167714"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704880" version="1" comment="libcurl4 is &lt;7.66.0-4.17.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030964"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167714"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704912" version="1" comment="curl is &lt;7.66.0-4.22.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030596"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167730"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704913" version="1" comment="libcurl4 is &lt;7.66.0-4.22.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030964"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167730"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704950" version="1" comment="curl is &lt;7.66.0-4.27.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030596"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167742"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704951" version="1" comment="libcurl4 is &lt;7.66.0-4.27.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030964"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167742"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713109" version="1" comment="kernel-default is &lt;4.12.14-95.74.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170107"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713110" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713111" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713112" version="1" comment="kernel-default is &lt;4.12.14-122.71.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170108"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713113" version="1" comment="kernel-default is &lt;4.12.14-197.89.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170109"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713114" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713115" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713116" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713117" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=3-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169822"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713118" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713119" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713120" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713121" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713122" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713123" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713124" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713125" version="1" comment="kernel-default is &lt;5.3.18-24.64.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705016" version="1" comment="libpython3_6m1_0 is &lt;3.6.13-3.78.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042555"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167765"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705017" version="1" comment="python3 is &lt;3.6.13-3.78.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037061"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167765"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705018" version="1" comment="python3-base is &lt;3.6.13-3.78.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036916"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167765"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705007" version="1" comment="libopenssl1_1 is &lt;1.1.1d-11.17.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042548"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167761"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705008" version="1" comment="openssl-1_1 is &lt;1.1.1d-11.17.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042550"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167761"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503123" version="1" comment="mozilla-nspr is &lt;4.25.1-3.17.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032358"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118984"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705019" version="1" comment="libzstd1 is &lt;1.4.4-1.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167766"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009680342" version="1" comment="xen-libs is &lt;4.13.4_08-150200.3.50.1 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160223"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713126" version="1" comment="kgraft-patch-4_12_14-95_51-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048796"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713127" version="1" comment="kgraft-patch-4_12_14-95_54-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048888"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713128" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713129" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713130" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713131" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713132" version="1" comment="kgraft-patch-4_12_14-122_20-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048798"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713133" version="1" comment="kgraft-patch-4_12_14-122_23-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713134" version="1" comment="kgraft-patch-4_12_14-122_26-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048929"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713135" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713136" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713137" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713138" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713139" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713140" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713141" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713142" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713143" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713144" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713145" version="1" comment="kernel-livepatch-4_12_14-150_52-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048927"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713146" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713147" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713148" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713149" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713150" version="1" comment="kernel-livepatch-4_12_14-197_40-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048794"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713151" version="1" comment="kernel-livepatch-4_12_14-197_45-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048886"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713152" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713153" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713154" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713155" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713156" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713157" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713158" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713159" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713160" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713161" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713162" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=10-5.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170111"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713163" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713164" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713165" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713166" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713167" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713168" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713169" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713170" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713171" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713172" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705009" version="1" comment="glib2-tools is &lt;2.62.6-3.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040978"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167762"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705010" version="1" comment="libgio-2_0-0 is &lt;2.62.6-3.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030896"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167762"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705011" version="1" comment="libglib-2_0-0 is &lt;2.62.6-3.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030899"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167762"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705012" version="1" comment="libgmodule-2_0-0 is &lt;2.62.6-3.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030902"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167762"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705013" version="1" comment="libgobject-2_0-0 is &lt;2.62.6-3.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030905"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167762"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713173" version="1" comment="kgraft-patch-4_12_14-95_51-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048796"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713174" version="1" comment="kgraft-patch-4_12_14-95_54-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048888"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713175" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713176" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713177" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713178" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713179" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713180" version="1" comment="kgraft-patch-4_12_14-122_20-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048798"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713181" version="1" comment="kgraft-patch-4_12_14-122_23-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713182" version="1" comment="kgraft-patch-4_12_14-122_26-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048929"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713183" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713184" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713185" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713186" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713187" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713188" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713189" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713190" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713191" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713192" version="1" comment="kernel-livepatch-4_12_14-150_52-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048927"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713193" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713194" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713195" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713196" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713197" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713198" version="1" comment="kernel-livepatch-4_12_14-197_37-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048742"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713199" version="1" comment="kernel-livepatch-4_12_14-197_40-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048794"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713200" version="1" comment="kernel-livepatch-4_12_14-197_45-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048886"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713201" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713202" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713203" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713204" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713205" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713206" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=5-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167113"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713207" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713208" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713209" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713210" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713211" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713212" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=9-5.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170112"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713213" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713214" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713215" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713216" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713217" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713218" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713219" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713220" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713221" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713222" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713223" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705027" version="1" comment="glib2-tools is &lt;2.62.6-150200.3.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040978"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167773"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705028" version="1" comment="libgio-2_0-0 is &lt;2.62.6-150200.3.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030896"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167773"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705029" version="1" comment="libglib-2_0-0 is &lt;2.62.6-150200.3.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030899"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167773"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705030" version="1" comment="libgmodule-2_0-0 is &lt;2.62.6-150200.3.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030902"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167773"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705031" version="1" comment="libgobject-2_0-0 is &lt;2.62.6-150200.3.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030905"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167773"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713224" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713225" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009493665" version="1" comment="xen-libs is &lt;4.13.2_08-3.25.3 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009116813"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713226" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713227" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009633428" version="1" comment="xen-libs is &lt;4.13.3_04-3.37.1 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009149196"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009658528" version="1" comment="xen-libs is &lt;4.13.4_02-3.40.1 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155719"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009658985" version="1" comment="kernel-rt is &lt;5.3.18-65.2 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155788"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704861" version="1" comment="libruby2_5-2_5 is &lt;2.5.9-4.17.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047596"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167703"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704862" version="1" comment="ruby2.5 is &lt;2.5.9-4.17.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167703"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704863" version="1" comment="ruby2.5-stdlib is &lt;2.5.9-4.17.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047600"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167703"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704870" version="1" comment="kernel-default is &lt;5.3.18-24.64.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009116874"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704871" version="1" comment="kernel-default-base is &lt;5.3.18-24.64.1.9.28.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167708"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009498544" version="1" comment="kernel-rt is &lt;5.3.18-8.10.1 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118228"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704856" version="1" comment="wpa_supplicant is &lt;2.9-4.29.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034744"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167700"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009651737" version="1" comment="containerd is &lt;1.4.11-56.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154649"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009651738" version="1" comment="docker is &lt;20.10.9_ce-156.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038208"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154650"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009651739" version="1" comment="runc is &lt;1.0.2-23.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040911"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154651"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713228" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=7-3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169819"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503414" version="1" comment="libX11-6 is &lt;1.6.5-3.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119044"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009494026" version="1" comment="libX11-data is &lt;1.6.5-3.21.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036218"/>
		<state state_ref="oval:org.opensuse.security:ste:2009116919"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503416" version="1" comment="libX11-xcb1 is &lt;1.6.5-3.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036222"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119044"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503164" version="1" comment="sudo is &lt;1.8.22-4.18.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030544"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119000"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009680329" version="1" comment="libruby2_5-2_5 is &lt;2.5.9-150000.4.23.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047596"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160220"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009680330" version="1" comment="ruby2.5 is &lt;2.5.9-150000.4.23.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047597"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160220"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009680333" version="1" comment="ruby2.5-stdlib is &lt;2.5.9-150000.4.23.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047600"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160220"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704883" version="1" comment="gstreamer is &lt;1.16.3-3.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041486"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167716"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704884" version="1" comment="gstreamer-plugins-base is &lt;1.16.3-4.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167717"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704885" version="1" comment="libgstallocators-1_0-0 is &lt;1.16.3-4.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167717"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704886" version="1" comment="libgstapp-1_0-0 is &lt;1.16.3-4.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167717"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704887" version="1" comment="libgstaudio-1_0-0 is &lt;1.16.3-4.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167717"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704888" version="1" comment="libgstgl-1_0-0 is &lt;1.16.3-4.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041162"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167717"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704889" version="1" comment="libgstpbutils-1_0-0 is &lt;1.16.3-4.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041350"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167717"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704890" version="1" comment="libgstreamer-1_0-0 is &lt;1.16.3-3.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167716"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704891" version="1" comment="libgstriff-1_0-0 is &lt;1.16.3-4.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041352"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167717"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704892" version="1" comment="libgsttag-1_0-0 is &lt;1.16.3-4.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041360"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167717"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704893" version="1" comment="libgstvideo-1_0-0 is &lt;1.16.3-4.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041362"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167717"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713229" version="1" comment="kgraft-patch-4_12_14-95_57-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049037"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713230" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713231" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713232" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713233" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713234" version="1" comment="kgraft-patch-4_12_14-122_26-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048929"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713235" version="1" comment="kgraft-patch-4_12_14-122_29-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049039"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713236" version="1" comment="kgraft-patch-4_12_14-122_32-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713237" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713238" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713239" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713240" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713241" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713242" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713243" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713244" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713245" version="1" comment="kernel-livepatch-4_12_14-150_52-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048927"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713246" version="1" comment="kernel-livepatch-4_12_14-150_55-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049029"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713247" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713248" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713249" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713250" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713251" version="1" comment="kernel-livepatch-4_12_14-197_48-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713252" version="1" comment="kernel-livepatch-4_12_14-197_51-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713253" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713254" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713255" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713256" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713257" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713258" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713259" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713260" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713261" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713262" version="1" comment="kernel-livepatch-5_3_18-22-default is &gt;=12-5.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049172"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170113"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713263" version="1" comment="kernel-livepatch-5_3_18-24_12-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713264" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713265" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713266" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713267" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713268" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713269" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713270" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713271" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713272" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713273" version="1" comment="kernel-livepatch-5_3_18-24_9-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049033"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009504140" version="1" comment="libgcrypt20 is &lt;1.8.2-8.39.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038771"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119173"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009634576" version="1" comment="glibc is &lt;2.26-13.59.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031926"/>
		<state state_ref="oval:org.opensuse.security:ste:2009149384"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009634580" version="1" comment="glibc-locale is &lt;2.26-13.59.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031925"/>
		<state state_ref="oval:org.opensuse.security:ste:2009149384"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009634581" version="1" comment="glibc-locale-base is &lt;2.26-13.59.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047237"/>
		<state state_ref="oval:org.opensuse.security:ste:2009149384"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725499" version="1" comment="kgraft-patch-4_12_14-95_102-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060093"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725858" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725859" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725860" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725861" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725862" version="1" comment="kgraft-patch-4_12_14-95_99-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059968"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725863" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=16-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170103"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725864" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725865" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725866" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725867" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725868" version="1" comment="kgraft-patch-4_12_14-122_121-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725869" version="1" comment="kgraft-patch-4_12_14-122_124-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725501" version="1" comment="kgraft-patch-4_12_14-122_127-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060094"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725870" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=16-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170103"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725871" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=9-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170079"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725872" version="1" comment="kernel-livepatch-4_12_14-150100_197_114-default is &gt;=6-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170161"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725503" version="1" comment="kernel-livepatch-4_12_14-150100_197_117-default is &gt;=4-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060078"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170075"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725873" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=15-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170160"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725874" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=11-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173047"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725875" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=10-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170159"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725876" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=10-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166595"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725877" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=8-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166540"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725878" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=15-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166591"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725879" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=14-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170082"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725880" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=18-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171218"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725881" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=17-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166589"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725882" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=16-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166590"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725883" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725884" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725885" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725886" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725887" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725888" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=10-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166596"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725889" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725890" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725891" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725505" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725892" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=18-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171219"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725893" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725894" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725895" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=8-150400.4.21.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173048"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725506" version="1" comment="kernel-livepatch-5_14_21-150400_24_11-default is &gt;=5-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060153"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172959"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713798" version="1" comment="kernel-default is &lt;5.14.21-150400.24.11.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170163"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009477296" version="1" comment="libfuse3-3 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047798"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009660091" version="1" comment="libpython3_6m1_0 is &lt;3.6.15-3.91.3 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042555"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156008"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009660092" version="1" comment="python3 is &lt;3.6.15-3.91.4 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037061"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156009"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009660093" version="1" comment="python3-base is &lt;3.6.15-3.91.3 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036916"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156008"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705020" version="1" comment="libopenssl1_1 is &lt;1.1.1d-11.20.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042548"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167767"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705021" version="1" comment="openssl-1_1 is &lt;1.1.1d-11.20.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042550"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167767"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704948" version="1" comment="kernel-default is &lt;5.3.18-24.83.2 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009149147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704949" version="1" comment="kernel-default-base is &lt;5.3.18-24.83.2.9.38.3 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009633320" version="1" comment="kernel-rt is &lt;5.3.18-51.2 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009149162"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713274" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=8-3.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170114"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713275" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713276" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713277" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713278" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713279" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713280" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704877" version="1" comment="libhivex0 is &lt;1.3.14-5.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038423"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167713"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704878" version="1" comment="perl-Win-Hivex is &lt;1.3.14-5.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038424"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167713"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009601181" version="1" comment="librados2 is &lt;15.2.12.83+g528da226523-3.25.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041228"/>
		<state state_ref="oval:org.opensuse.security:ste:2009143027"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009601182" version="1" comment="librbd1 is &lt;15.2.12.83+g528da226523-3.25.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041232"/>
		<state state_ref="oval:org.opensuse.security:ste:2009143027"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704874" version="1" comment="libxml2-2 is &lt;2.9.7-3.34.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035409"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167711"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704875" version="1" comment="libxml2-tools is &lt;2.9.7-3.34.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035414"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167711"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503309" version="1" comment="liblz4-1 is &lt;1.8.0-3.8.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048170"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119020"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704900" version="1" comment="libxml2-2 is &lt;2.9.7-3.37.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035409"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167722"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704901" version="1" comment="libxml2-tools is &lt;2.9.7-3.37.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035414"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167722"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704995" version="1" comment="kernel-default is &lt;5.3.18-24.93.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155303"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704996" version="1" comment="kernel-default-base is &lt;5.3.18-24.93.1.9.42.5 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167754"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009651700" version="1" comment="kernel-rt is &lt;5.3.18-57.1 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154642"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704905" version="1" comment="qemu is &lt;4.2.1-11.22.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167726"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499926" version="1" comment="qemu-arm is &lt;4.2.1-11.22.1 for aarch64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038462"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118550"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499934" version="1" comment="qemu-ipxe is &lt;1.0.0+-11.22.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037631"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118552"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499940" version="1" comment="qemu-seabios is &lt;1.12.1+-11.22.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037633"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499941" version="1" comment="qemu-sgabios is &lt;8-11.22.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118558"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704906" version="1" comment="qemu-tools is &lt;4.2.1-11.22.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036248"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167726"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499945" version="1" comment="qemu-vgabios is &lt;1.12.1+-11.22.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037635"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009499946" version="1" comment="qemu-x86 is &lt;4.2.1-11.22.1 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009118551"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704894" version="1" comment="libpolkit0 is &lt;0.116-3.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167718"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704895" version="1" comment="polkit is &lt;0.116-3.3.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167718"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713281" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713282" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713283" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713284" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713285" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713286" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713287" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=16-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170103"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713288" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713289" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713290" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713291" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713292" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713293" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713294" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713295" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713296" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713297" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713298" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713299" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713300" version="1" comment="kernel-default is &lt;4.12.14-122.83.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170115"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713301" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713302" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713303" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713304" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713305" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713306" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713307" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713308" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713309" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713310" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713311" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713312" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713313" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713314" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713315" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713316" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713317" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713318" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713319" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713320" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713321" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713322" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713323" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713324" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713325" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713326" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713327" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713328" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713329" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713330" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713331" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713332" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713333" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713334" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713335" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713336" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503543" version="1" comment="libhogweed4 is &lt;3.4.1-4.18.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042537"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119067"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009503545" version="1" comment="libnettle6 is &lt;3.4.1-4.18.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042538"/>
		<state state_ref="oval:org.opensuse.security:ste:2009119067"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704930" version="1" comment="qemu is &lt;4.2.1-11.25.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167731"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626240" version="1" comment="qemu-arm is &lt;4.2.1-11.25.2 for aarch64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038462"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147692"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626248" version="1" comment="qemu-ipxe is &lt;1.0.0+-11.25.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037631"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147694"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626254" version="1" comment="qemu-seabios is &lt;1.12.1+-11.25.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037633"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147699"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626255" version="1" comment="qemu-sgabios is &lt;8-11.25.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147700"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704931" version="1" comment="qemu-tools is &lt;4.2.1-11.25.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036248"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167731"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626259" version="1" comment="qemu-vgabios is &lt;1.12.1+-11.25.2 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037635"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147699"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626260" version="1" comment="qemu-x86 is &lt;4.2.1-11.25.2 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147693"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713337" version="1" comment="kernel-default is &lt;5.3.18-24.70.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170116"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704946" version="1" comment="libhivex0 is &lt;1.3.14-5.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038423"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167740"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704947" version="1" comment="perl-Win-Hivex is &lt;1.3.14-5.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038424"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167740"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009626718" version="1" comment="krb5 is &lt;1.16.3-3.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031044"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147803"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704914" version="1" comment="libvirt-daemon is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704915" version="1" comment="libvirt-daemon-driver-interface is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037566"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704916" version="1" comment="libvirt-daemon-driver-network is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037568"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704917" version="1" comment="libvirt-daemon-driver-nodedev is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037569"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704918" version="1" comment="libvirt-daemon-driver-nwfilter is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704919" version="1" comment="libvirt-daemon-driver-qemu is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704920" version="1" comment="libvirt-daemon-driver-secret is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037572"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704921" version="1" comment="libvirt-daemon-driver-storage is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037573"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704922" version="1" comment="libvirt-daemon-driver-storage-core is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704923" version="1" comment="libvirt-daemon-driver-storage-disk is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041753"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704924" version="1" comment="libvirt-daemon-driver-storage-iscsi is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704925" version="1" comment="libvirt-daemon-driver-storage-logical is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704926" version="1" comment="libvirt-daemon-driver-storage-mpath is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009624910" version="1" comment="libvirt-daemon-driver-storage-rbd is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041757"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704927" version="1" comment="libvirt-daemon-driver-storage-scsi is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041758"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704928" version="1" comment="libvirt-daemon-qemu is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037577"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704929" version="1" comment="libvirt-libs is &lt;6.0.0-13.16.2 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041759"/>
		<state state_ref="oval:org.opensuse.security:ste:2009147404"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336436" version="1" comment="libssh4 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009035367"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713338" version="1" comment="kgraft-patch-4_12_14-95_60-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713339" version="1" comment="kgraft-patch-4_12_14-95_65-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049450"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713340" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713341" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713342" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713343" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713344" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713345" version="1" comment="kgraft-patch-4_12_14-122_37-default is &gt;=16-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049176"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170103"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713346" version="1" comment="kgraft-patch-4_12_14-122_41-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049273"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713347" version="1" comment="kgraft-patch-4_12_14-122_46-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713348" version="1" comment="kgraft-patch-4_12_14-122_51-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049427"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713349" version="1" comment="kgraft-patch-4_12_14-122_54-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050026"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713350" version="1" comment="kgraft-patch-4_12_14-122_57-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050419"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713351" version="1" comment="kgraft-patch-4_12_14-122_60-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050503"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713352" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713353" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713354" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713355" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713356" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713357" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713358" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713359" version="1" comment="kernel-livepatch-4_12_14-150_58-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049197"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713360" version="1" comment="kernel-livepatch-4_12_14-150_63-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713361" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=10-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167187"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713362" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713363" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713364" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713365" version="1" comment="kernel-livepatch-4_12_14-197_56-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049178"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713366" version="1" comment="kernel-livepatch-4_12_14-197_61-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049269"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713367" version="1" comment="kernel-livepatch-4_12_14-197_64-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049332"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713368" version="1" comment="kernel-livepatch-4_12_14-197_67-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049420"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713369" version="1" comment="kernel-livepatch-4_12_14-197_72-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713370" version="1" comment="kernel-livepatch-4_12_14-197_75-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050049"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713371" version="1" comment="kernel-livepatch-4_12_14-197_78-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050415"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713372" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713373" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713374" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713375" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713376" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713377" version="1" comment="kernel-livepatch-5_3_18-24_15-default is &gt;=14-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049180"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167115"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713378" version="1" comment="kernel-livepatch-5_3_18-24_24-default is &gt;=14-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049246"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167115"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713379" version="1" comment="kernel-livepatch-5_3_18-24_29-default is &gt;=12-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167116"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713380" version="1" comment="kernel-livepatch-5_3_18-24_34-default is &gt;=12-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049396"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167116"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713381" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=12-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167116"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713382" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=11-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167106"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713383" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=11-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167106"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713384" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=10-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167187"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713385" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=9-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170064"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713386" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=4-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169769"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713387" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=6-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167108"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713388" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=6-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167108"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713389" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=4-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169769"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713390" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=4-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169769"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713391" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=3-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167192"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713392" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=2-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170022"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713393" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=6-3.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170117"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713394" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=4-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169769"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713395" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=4-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169769"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713396" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=3-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167192"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713397" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=2-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170022"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713398" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=4-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169769"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704977" version="1" comment="libvirt-daemon is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704978" version="1" comment="libvirt-daemon-driver-interface is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037566"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704979" version="1" comment="libvirt-daemon-driver-network is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037568"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704980" version="1" comment="libvirt-daemon-driver-nodedev is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037569"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704981" version="1" comment="libvirt-daemon-driver-nwfilter is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704982" version="1" comment="libvirt-daemon-driver-qemu is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704983" version="1" comment="libvirt-daemon-driver-secret is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037572"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704984" version="1" comment="libvirt-daemon-driver-storage is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037573"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704985" version="1" comment="libvirt-daemon-driver-storage-core is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704986" version="1" comment="libvirt-daemon-driver-storage-disk is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041753"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704987" version="1" comment="libvirt-daemon-driver-storage-iscsi is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704988" version="1" comment="libvirt-daemon-driver-storage-logical is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704989" version="1" comment="libvirt-daemon-driver-storage-mpath is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009652326" version="1" comment="libvirt-daemon-driver-storage-rbd is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041757"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704990" version="1" comment="libvirt-daemon-driver-storage-scsi is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041758"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704991" version="1" comment="libvirt-daemon-qemu is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037577"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704992" version="1" comment="libvirt-libs is &lt;6.0.0-13.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041759"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154757"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704941" version="1" comment="libopenssl1_1 is &lt;1.1.1d-11.27.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042548"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167737"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704942" version="1" comment="openssl-1_1 is &lt;1.1.1d-11.27.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042550"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167737"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704943" version="1" comment="libopenssl1_1 is &lt;1.1.1d-11.30.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042548"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167738"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704944" version="1" comment="openssl-1_1 is &lt;1.1.1d-11.30.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042550"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167738"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704993" version="1" comment="qemu is &lt;4.2.1-11.31.3 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031639"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167753"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009652933" version="1" comment="qemu-arm is &lt;4.2.1-11.31.3 for aarch64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038462"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154874"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009652941" version="1" comment="qemu-ipxe is &lt;1.0.0+-11.31.3 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037631"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154876"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009652947" version="1" comment="qemu-seabios is &lt;1.12.1+-11.31.3 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037633"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154881"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009652948" version="1" comment="qemu-sgabios is &lt;8-11.31.3 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154882"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704994" version="1" comment="qemu-tools is &lt;4.2.1-11.31.3 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036248"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167753"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009652952" version="1" comment="qemu-vgabios is &lt;1.12.1+-11.31.3 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037635"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154881"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009652953" version="1" comment="qemu-x86 is &lt;4.2.1-11.31.3 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009154875"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713399" version="1" comment="kernel-livepatch-5_3_18-24_37-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009049422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713400" version="1" comment="kernel-livepatch-5_3_18-24_43-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050167"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713401" version="1" comment="kernel-livepatch-5_3_18-24_46-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713402" version="1" comment="kernel-livepatch-5_3_18-24_49-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713403" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713404" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713405" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713406" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704965" version="1" comment="libblkid1 is &lt;2.33.2-4.16.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031455"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167750"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704966" version="1" comment="libfdisk1 is &lt;2.33.2-4.16.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040900"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167750"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704967" version="1" comment="libmount1 is &lt;2.33.2-4.16.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038354"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167750"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704968" version="1" comment="libsmartcols1 is &lt;2.33.2-4.16.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038362"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167750"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704969" version="1" comment="libuuid1 is &lt;2.33.2-4.16.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031465"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167750"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704970" version="1" comment="util-linux is &lt;2.33.2-4.16.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167750"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704971" version="1" comment="util-linux-systemd is &lt;2.33.2-4.16.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038357"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167750"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704960" version="1" comment="krb5 is &lt;1.16.3-3.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031044"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167748"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009669883" version="1" comment="vim-data-common is &lt;8.0.1568-5.17.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157730"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705042" version="1" comment="vim-small is &lt;8.0.1568-5.17.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052260"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157748"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336707" version="1" comment="glib2-tools is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040978"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336708" version="1" comment="libgio-2_0-0 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030896"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336711" version="1" comment="libglib-2_0-0 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030899"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336713" version="1" comment="libgmodule-2_0-0 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030902"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336715" version="1" comment="libgobject-2_0-0 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030905"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009631310" version="1" comment="cpio is &lt;2.12-3.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030506"/>
		<state state_ref="oval:org.opensuse.security:ste:2009148678"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704961" version="1" comment="libncurses6 is &lt;6.1-5.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041698"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704962" version="1" comment="ncurses-utils is &lt;6.1-5.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704963" version="1" comment="terminfo is &lt;6.1-5.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032551"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009704964" version="1" comment="terminfo-base is &lt;6.1-5.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713407" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=2-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169354"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698825" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=2-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166586"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009716156" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=3-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170169"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718697" version="1" comment="kernel-default is ==5.3.18-150200.24.129.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171217"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718698" version="1" comment="kernel-livepatch-5_3_18-150200_24_129-default is &gt;=2-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060347"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169354"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725507" version="1" comment="kernel-default is ==5.3.18-150200.24.134.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172960"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725508" version="1" comment="kernel-livepatch-5_3_18-150200_24_134-default is &gt;=2-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169354"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713408" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=4-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713409" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=3-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713410" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=12-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166533"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713411" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=14-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166525"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713412" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=14-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166525"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713413" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=12-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166533"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713414" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=12-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166533"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713415" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=11-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166572"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713416" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=10-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166535"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713417" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=8-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166540"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713418" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=8-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166540"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713419" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=7-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166542"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713420" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=6-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166573"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713421" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=5-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166567"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713422" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713423" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713424" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713425" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713426" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713427" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713428" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=2-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166605"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701443" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=3-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166603"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701404" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=2-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166605"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009706112" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009709695" version="1" comment="kernel-default is ==5.3.18-150300.59.90.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169303"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715597" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=3-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166603"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715598" version="1" comment="kernel-default is ==5.3.18-150300.59.93.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170604"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715599" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=2-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166605"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725509" version="1" comment="kernel-default is ==5.3.18-150300.59.98.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725510" version="1" comment="kernel-livepatch-5_3_18-150300_59_98-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713429" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=14-150200.3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713430" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=12-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166555"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713431" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=12-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166555"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713432" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=11-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166582"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713433" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=10-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713434" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713435" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713436" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713437" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713438" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713439" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=12-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166555"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698875" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=2-150400.4.3.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166614"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715600" version="1" comment="kernel-default is ==5.14.21-150400.24.21.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170605"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715601" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=2-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170606"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725511" version="1" comment="kernel-default is ==5.14.21-150400.24.28.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172962"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725512" version="1" comment="kernel-livepatch-5_14_21-150400_24_28-default is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729488" version="1" comment="kernel-default is ==5.14.21-150400.24.33.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173718"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729489" version="1" comment="kernel-livepatch-5_14_21-150400_24_33-default is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729490" version="1" comment="kernel-default is &lt;5.14.21-150400.24.33.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173719"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713440" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=15-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166487"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713441" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=14-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166498"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713442" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713443" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713444" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713445" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713446" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713447" version="1" comment="kernel-default is &lt;4.12.14-95.96.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170119"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713448" version="1" comment="kernel-livepatch-4_12_14-150000_150_89-default is &gt;=2-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059651"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167141"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713449" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=15-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713450" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=12-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170121"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713451" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=7-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170122"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713452" version="1" comment="kernel-livepatch-4_12_14-150_83-default is &gt;=4-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170068"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713453" version="1" comment="kernel-livepatch-4_12_14-150_86-default is &gt;=3-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059474"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170123"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662009" version="1" comment="libvirt-daemon is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662012" version="1" comment="libvirt-daemon-driver-interface is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037566"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662015" version="1" comment="libvirt-daemon-driver-network is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037568"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662016" version="1" comment="libvirt-daemon-driver-nodedev is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037569"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662017" version="1" comment="libvirt-daemon-driver-nwfilter is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037570"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662018" version="1" comment="libvirt-daemon-driver-qemu is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662019" version="1" comment="libvirt-daemon-driver-secret is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037572"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662020" version="1" comment="libvirt-daemon-driver-storage is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037573"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662021" version="1" comment="libvirt-daemon-driver-storage-core is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662022" version="1" comment="libvirt-daemon-driver-storage-disk is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041753"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662023" version="1" comment="libvirt-daemon-driver-storage-iscsi is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662024" version="1" comment="libvirt-daemon-driver-storage-logical is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662025" version="1" comment="libvirt-daemon-driver-storage-mpath is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662026" version="1" comment="libvirt-daemon-driver-storage-rbd is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041757"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662027" version="1" comment="libvirt-daemon-driver-storage-scsi is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041758"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662030" version="1" comment="libvirt-daemon-qemu is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037577"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662034" version="1" comment="libvirt-libs is &lt;6.0.0-13.24.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041759"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156372"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338902" version="1" comment="grub2 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039506"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009339065" version="1" comment="grub2-arm64-efi is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041109"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338904" version="1" comment="grub2-i386-pc is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039507"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338906" version="1" comment="grub2-snapper-plugin is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338908" version="1" comment="grub2-x86_64-efi is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338909" version="1" comment="grub2-x86_64-xen is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009039510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009337634" version="1" comment="libblkid1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031455"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009664921" version="1" comment="libfdisk1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040900"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009664923" version="1" comment="libmount1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038354"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009664926" version="1" comment="libsmartcols1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038362"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009337635" version="1" comment="libuuid1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031465"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334326" version="1" comment="util-linux is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009336434" version="1" comment="libsystemd0 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041083"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335309" version="1" comment="libudev1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009037378"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009334001" version="1" comment="systemd is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036874"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009624596" version="1" comment="systemd-container is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042704"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335313" version="1" comment="systemd-sysvinit is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009036879"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335314" version="1" comment="udev is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031048"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713454" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=13-150200.3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170124"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713455" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=11-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166582"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713456" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=11-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166582"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713457" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=10-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713458" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=9-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166560"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713459" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713460" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713461" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713462" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713463" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=11-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166582"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009343329" version="1" comment="podman is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047417"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009343330" version="1" comment="podman-cni-config is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009047418"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713464" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=4-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166601"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713465" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=4-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166601"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009664559" version="1" comment="libpolkit0 is &lt;0.116-3.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156839"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009664560" version="1" comment="polkit is &lt;0.116-3.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156839"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713466" version="1" comment="kgraft-patch-4_12_14-95_68-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050501"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713467" version="1" comment="kgraft-patch-4_12_14-95_71-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050637"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713468" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713469" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713470" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713471" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713472" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713473" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713474" version="1" comment="kgraft-patch-4_12_14-122_63-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050622"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713475" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713476" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713477" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713478" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713479" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713480" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713481" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713482" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713483" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713484" version="1" comment="kernel-livepatch-4_12_14-150_66-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050495"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713485" version="1" comment="kernel-livepatch-4_12_14-150_69-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050630"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713486" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713487" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713488" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713489" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713490" version="1" comment="kernel-livepatch-4_12_14-197_83-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050517"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713491" version="1" comment="kernel-livepatch-4_12_14-197_86-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050632"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713492" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713493" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713494" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713495" version="1" comment="kernel-livepatch-5_3_18-24_52-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050634"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713496" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713497" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713498" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713499" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713500" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713501" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713502" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713503" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713504" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713505" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713506" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713507" version="1" comment="kernel-default is &lt;5.3.18-24.96.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170125"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713508" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=11-3.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170126"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713509" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713510" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713511" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713512" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=7-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166599"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713513" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=5-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170127"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713514" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=5-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170127"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713515" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=4-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166601"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713516" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=3-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166603"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713517" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=3-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166603"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713518" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009662947" version="1" comment="kernel-rt is &lt;5.3.18-68.1 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156498"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705036" version="1" comment="containerd is &lt;1.4.12-60.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167777"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705037" version="1" comment="docker is &lt;20.10.12_ce-159.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038208"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167778"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705038" version="1" comment="libpolkit0 is &lt;0.116-3.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034515"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167779"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705039" version="1" comment="polkit is &lt;0.116-3.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034518"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167779"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009339165" version="1" comment="cryptsetup is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050294"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009339166" version="1" comment="libcryptsetup12 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050295"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009671497" version="1" comment="openssh is &lt;8.1p1-5.21.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030403"/>
		<state state_ref="oval:org.opensuse.security:ste:2009158015"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713519" version="1" comment="kernel-default is &lt;4.12.14-122.91.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170128"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713520" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713521" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713522" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713523" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713524" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713525" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=2-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170022"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713526" version="1" comment="kernel-default is &lt;5.3.18-24.86.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170129"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713527" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705040" version="1" comment="libgnutls30 is &lt;3.6.7-14.16.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042507"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713528" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713529" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713530" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=4-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169769"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009658530" version="1" comment="python3-Babel is &lt;2.8.0-3.3.1 for noarch" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058762"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155720"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659044" version="1" comment="libfreebl3 is &lt;3.68.1-3.61.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155805"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659046" version="1" comment="libsoftokn3 is &lt;3.68.1-3.61.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155805"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659048" version="1" comment="mozilla-nss is &lt;3.68.1-3.61.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032440"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155805"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659049" version="1" comment="mozilla-nss-certs is &lt;3.68.1-3.61.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033978"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155805"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009681381" version="1" comment="containerd is &lt;1.5.11-150000.68.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160436"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009681382" version="1" comment="docker is &lt;20.10.14_ce-150000.163.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038208"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160437"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705003" version="1" comment="libgmp10 is &lt;6.1.2-4.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009048750"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009659270" version="1" comment="runc is &lt;1.0.3-27.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040911"/>
		<state state_ref="oval:org.opensuse.security:ste:2009155856"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009663792" version="1" comment="containerd is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040908"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009671505" version="1" comment="kernel-default is &lt;5.3.18-24.107.1 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009158017"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009671506" version="1" comment="kernel-default-base is &lt;5.3.18-24.107.1.9.50.2 for aarch64,x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031011"/>
		<state state_ref="oval:org.opensuse.security:ste:2009158018"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009338893" version="1" comment="libharfbuzz0 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040821"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009664062" version="1" comment="libexpat1 is &lt;2.2.5-3.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009156702"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009671417" version="1" comment="kernel-rt is &lt;5.3.18-76.1 for x86_64" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031299"/>
		<state state_ref="oval:org.opensuse.security:ste:2009158001"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009667314" version="1" comment="libvirglrenderer0 is &lt;0.6.0-4.9.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157290"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009705025" version="1" comment="libvirglrenderer0 is &lt;0.6.0-4.6.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009041508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167771"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713531" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713532" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713533" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=3-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166603"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713534" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=2-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166605"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713535" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=2-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166605"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698691" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=16-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166485"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698693" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=15-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166487"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698695" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=13-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698697" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698700" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698702" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698704" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=16-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166485"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698706" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=14-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166498"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698708" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=14-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166498"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698710" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=13-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698712" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698714" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698716" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698718" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698721" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=16-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166509"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698723" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=13-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166511"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698725" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=8-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166513"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698728" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=8-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166516"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698730" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=16-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166518"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698732" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=15-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166520"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698734" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=13-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166522"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698737" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=14-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166525"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698739" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=16-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166527"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698741" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=14-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166525"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698743" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=14-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166525"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698745" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=13-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166531"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698747" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=12-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166533"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698749" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=10-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166535"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698751" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=10-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166535"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698753" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=9-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166538"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698755" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=8-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166540"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698757" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=7-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166542"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698760" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698762" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698764" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=16-150200.3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166548"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698766" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=14-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166550"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698768" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=14-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166550"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698770" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=13-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166553"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698772" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=12-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166555"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698774" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=10-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698776" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=10-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698778" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=9-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166560"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698780" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698782" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698784" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=14-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166550"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713536" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713537" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=2-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166605"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713538" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=2-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166605"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713539" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=13-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713540" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713541" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713542" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713543" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713544" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713545" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=14-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166498"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713546" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=13-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713547" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713548" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713549" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713550" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713551" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713552" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713553" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713554" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=13-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166511"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713555" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=10-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170130"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713556" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=5-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170131"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713557" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=5-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170132"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713558" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=13-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166522"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713559" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=12-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170133"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713560" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=10-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170134"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713561" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=11-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166572"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713562" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=13-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166531"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713563" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=13-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166531"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713564" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=11-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166572"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713565" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=11-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166572"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713566" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713567" version="1" comment="kernel-default is &lt;4.12.14-95.88.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170135"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713568" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713569" version="1" comment="kernel-livepatch-4_12_14-150_83-default is &gt;=2-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167141"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701264" version="1" comment="kernel-default is &lt;4.12.14-150.83.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167144"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713570" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713571" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=3-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713572" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=10-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166535"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713573" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=9-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166538"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713574" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=7-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166542"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713575" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=7-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166542"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713576" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=6-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166573"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713577" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=5-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166567"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713578" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=4-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713579" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713580" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713581" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713582" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009673279" version="1" comment="libopenssl1_1 is &lt;1.1.1d-11.43.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042548"/>
		<state state_ref="oval:org.opensuse.security:ste:2009158274"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009673282" version="1" comment="openssl-1_1 is &lt;1.1.1d-11.43.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042550"/>
		<state state_ref="oval:org.opensuse.security:ste:2009158274"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009679488" version="1" comment="dnsmasq is &lt;2.86-150100.7.20.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031669"/>
		<state state_ref="oval:org.opensuse.security:ste:2009159991"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713583" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713584" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713585" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713586" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713587" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713588" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=16-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166485"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713589" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=15-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166487"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713590" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=13-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713591" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=13-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713592" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713593" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713594" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713595" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713596" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713597" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713598" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=7-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170136"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713599" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=4-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170075"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713600" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=3-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170137"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713601" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=15-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166520"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713602" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=14-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170138"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713603" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=12-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170133"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698787" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=5-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166567"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698789" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=4-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698790" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=13-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166531"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698792" version="1" comment="kernel-livepatch-5_3_18-24_61-default is &gt;=15-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051510"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166571"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698793" version="1" comment="kernel-livepatch-5_3_18-24_64-default is &gt;=15-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051567"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166571"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698794" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=13-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166531"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698795" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=13-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166531"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698796" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=12-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166533"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698797" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=11-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166572"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698798" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=9-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166538"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698799" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=9-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166538"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698800" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=8-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166540"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698801" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=7-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166542"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698802" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=6-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166573"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698803" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698804" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698806" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698808" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698810" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698811" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=15-150200.3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166581"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698812" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=13-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166553"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698813" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=13-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166553"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698814" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=12-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166555"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698815" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=11-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166582"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698816" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=9-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166560"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698817" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=9-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166560"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698818" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698819" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698820" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698821" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=13-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166553"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713604" version="1" comment="kernel-default is &lt;4.12.14-95.93.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170139"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009685665" version="1" comment="kernel-default is &lt;5.14.21-150400.22.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009161423"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713605" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=16-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170103"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713606" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713607" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713608" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713609" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713610" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713611" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713612" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713613" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713614" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=16-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170103"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713615" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=16-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170103"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713616" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713617" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713618" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713619" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713620" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713621" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=14-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170140"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713622" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=9-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170072"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713623" version="1" comment="kernel-livepatch-4_12_14-150_83-default is &gt;=5-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170141"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713624" version="1" comment="kernel-livepatch-4_12_14-150_86-default is &gt;=4-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059474"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170142"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713625" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=9-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170079"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713626" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=5-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170143"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713627" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=4-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170144"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713628" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=16-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170145"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713629" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=14-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170146"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713630" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=8-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166588"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713631" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=7-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170081"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713632" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=16-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166590"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713633" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=16-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166590"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713634" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=16-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166590"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713635" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=15-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166591"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713636" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=14-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170082"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713637" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=12-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166593"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713638" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=12-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166593"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713639" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=11-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166594"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713640" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=10-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166595"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713641" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=9-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166587"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713642" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713643" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713644" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713645" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=7-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166599"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713646" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=6-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170083"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713647" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=18-150200.3.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713648" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713649" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713650" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713651" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713652" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713653" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713654" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713655" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=10-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166596"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713656" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=10-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166596"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713657" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009678060" version="1" comment="libfreebl3 is &lt;3.68.3-150000.3.67.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009159716"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009678062" version="1" comment="libsoftokn3 is &lt;3.68.3-150000.3.67.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009159716"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009678064" version="1" comment="mozilla-nss is &lt;3.68.3-150000.3.67.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009032440"/>
		<state state_ref="oval:org.opensuse.security:ste:2009159716"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009678065" version="1" comment="mozilla-nss-certs is &lt;3.68.3-150000.3.67.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033978"/>
		<state state_ref="oval:org.opensuse.security:ste:2009159716"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698823" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=4-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166584"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698826" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=9-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166587"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698827" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=8-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166588"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698828" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=17-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166589"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698829" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=17-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166589"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698830" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=16-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166590"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698831" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=15-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166591"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698832" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=13-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166592"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698833" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=13-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166592"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698834" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=12-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166593"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698835" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=11-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166594"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698836" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=10-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166595"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698837" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=10-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166596"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698838" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=10-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166596"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698839" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698840" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698841" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=7-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166599"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698843" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=4-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166601"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698845" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=3-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166603"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698847" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=2-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166605"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009709696" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698848" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=19-150200.3.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166606"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698849" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698850" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698851" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698852" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698853" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698854" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698855" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698856" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698857" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009698858" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713658" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=6-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166573"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713659" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=5-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166567"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713660" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713661" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713662" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009682445" version="1" comment="gzip is &lt;1.10-150200.10.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030647"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160799"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009679181" version="1" comment="liblzma5 is &lt;5.2.3-150000.4.7.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059620"/>
		<state state_ref="oval:org.opensuse.security:ste:2009159919"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009679182" version="1" comment="xz is &lt;5.2.3-150000.4.7.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009050248"/>
		<state state_ref="oval:org.opensuse.security:ste:2009159919"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713663" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713664" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713665" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713666" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713667" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=15-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166487"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713668" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=15-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166487"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713669" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=14-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166498"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713670" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=13-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713671" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713672" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713673" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713674" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=7-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166542"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713675" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=6-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166573"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713676" version="1" comment="kernel-livepatch-5_3_18-24_53_4-default is &gt;=15-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052214"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166571"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713677" version="1" comment="kernel-livepatch-5_3_18-24_67-default is &gt;=15-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051675"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166571"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713678" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=15-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166571"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713679" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=14-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166525"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713680" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=13-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166531"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713681" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=11-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166572"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713682" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=11-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166572"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713683" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=10-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166535"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713684" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=9-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166538"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713685" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=8-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166540"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713686" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713687" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713688" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713689" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713690" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713691" version="1" comment="kernel-livepatch-5_3_18-57-default is &gt;=17-150200.3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051701"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713692" version="1" comment="kernel-livepatch-5_3_18-59_10-default is &gt;=15-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051722"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170149"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713693" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=15-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170149"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713694" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=14-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166550"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713695" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=13-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166553"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713696" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=11-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166582"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713697" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=11-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166582"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713698" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=10-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713699" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=9-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166560"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713700" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=9-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166560"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713701" version="1" comment="kernel-livepatch-5_3_18-59_5-default is &gt;=15-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170149"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009682231" version="1" comment="e2fsprogs is &lt;1.43.8-150000.4.33.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160763"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009682235" version="1" comment="libcom_err2 is &lt;1.43.8-150000.4.33.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031459"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160763"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009682238" version="1" comment="libext2fs2 is &lt;1.43.8-150000.4.33.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031461"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160763"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009684924" version="1" comment="logrotate is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034546"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713702" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713703" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713704" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713705" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713706" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713707" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713708" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713709" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713710" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713711" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=17-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170150"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713712" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713713" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713714" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713715" version="1" comment="kernel-livepatch-4_12_14-150000_150_89-default is &gt;=6-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059651"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170151"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713716" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=12-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170152"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713717" version="1" comment="kernel-livepatch-4_12_14-150_83-default is &gt;=8-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170073"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713718" version="1" comment="kernel-livepatch-4_12_14-150_86-default is &gt;=7-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059474"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170067"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713719" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=6-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170153"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713720" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=12-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170154"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713721" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=8-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170080"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713722" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=7-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170074"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009335823" version="1" comment="libpcre1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009038688"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714500" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714501" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714502" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715338" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715339" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715340" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715603" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714503" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715341" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714504" version="1" comment="kgraft-patch-4_12_14-122_121-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715342" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=17-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170150"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714505" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=17-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170150"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714506" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715811" version="1" comment="kernel-livepatch-4_12_14-150000_150_89-default is &gt;=8-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059651"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170073"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715604" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=14-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170140"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715605" version="1" comment="kernel-livepatch-4_12_14-150_83-default is &gt;=10-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170158"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714507" version="1" comment="kernel-livepatch-4_12_14-150_86-default is &gt;=9-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059474"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170072"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714508" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=8-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170080"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715606" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=14-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170146"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714509" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=10-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170159"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715607" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=9-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170079"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009716236" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=8-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166588"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009716237" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=13-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166592"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715812" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=12-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166593"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715813" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=17-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166589"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715814" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=17-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166589"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009716238" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=16-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166590"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009716239" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=15-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166591"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009716240" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=14-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170082"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009716157" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715815" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714900" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009716158" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715608" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715609" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009716159" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=7-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166599"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715610" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715611" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715612" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715816" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715817" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714902" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=6-150400.4.15.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170452"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713723" version="1" comment="kgraft-patch-4_12_14-95_99-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059968"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713724" version="1" comment="kgraft-patch-4_12_14-122_121-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713725" version="1" comment="kgraft-patch-4_12_14-122_124-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713726" version="1" comment="kernel-livepatch-4_12_14-150000_150_92-default is &gt;=3-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059889"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170123"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713727" version="1" comment="kernel-livepatch-4_12_14-150100_197_114-default is &gt;=3-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170137"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713728" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=6-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170155"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713729" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=4-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713730" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=11-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166594"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713731" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=10-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166595"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713732" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=17-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166589"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713733" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=15-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166591"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713734" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=15-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166591"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713735" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=14-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170082"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713736" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=13-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166592"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713737" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=12-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166593"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713738" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713739" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713740" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713741" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=10-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166596"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713742" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713743" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=6-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170083"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713744" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=5-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170127"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713745" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713746" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713747" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713748" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713749" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713750" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713751" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713752" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713753" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=4-150400.4.9.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170156"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701141" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=16-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167105"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701142" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=11-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167106"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701406" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=7-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167185"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701144" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=6-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167108"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701408" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=5-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167113"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701146" version="1" comment="kgraft-patch-4_12_14-95_99-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059968"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701409" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=12-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167116"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701410" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=10-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167187"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701412" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=8-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167189"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701414" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=7-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167185"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701149" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=5-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167113"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701416" version="1" comment="kgraft-patch-4_12_14-122_121-default is &gt;=3-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167192"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701417" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=18-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167193"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701418" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=17-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167194"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701419" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=16-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167105"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701420" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=14-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167115"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701152" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=14-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167115"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701153" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=12-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167116"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701422" version="1" comment="kernel-livepatch-4_12_14-150000_150_89-default is &gt;=5-150000.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059651"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167196"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701423" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=16-150000.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167197"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701424" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=11-150000.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167198"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701263" version="1" comment="kernel-livepatch-4_12_14-150_83-default is &gt;=7-150000.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167143"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701426" version="1" comment="kernel-livepatch-4_12_14-150_86-default is &gt;=6-150000.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059474"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167200"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701266" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=5-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167146"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701267" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=11-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701429" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=7-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167203"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701269" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=6-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167149"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701430" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=16-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167204"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701271" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=5-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167151"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701431" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=10-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167205"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701272" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=9-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167152"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701432" version="1" comment="kernel-livepatch-5_3_18-24_70-default is &gt;=18-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052139"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167206"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701273" version="1" comment="kernel-livepatch-5_3_18-24_75-default is &gt;=17-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052202"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167153"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701433" version="1" comment="kernel-livepatch-5_3_18-24_78-default is &gt;=16-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052225"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167207"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701274" version="1" comment="kernel-livepatch-5_3_18-24_83-default is &gt;=14-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052449"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167154"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701434" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=14-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167154"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701435" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=13-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167208"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701275" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=12-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167155"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701276" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=11-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167156"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701436" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=11-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167209"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701437" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=11-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167209"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701438" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=10-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167210"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701439" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=9-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167211"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701440" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=8-150300.3.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167212"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701441" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=5-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167213"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701442" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=4-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167214"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701444" version="1" comment="kernel-livepatch-5_3_18-59_13-default is &gt;=18-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052137"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167215"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701445" version="1" comment="kernel-livepatch-5_3_18-59_16-default is &gt;=17-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052203"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167216"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701446" version="1" comment="kernel-livepatch-5_3_18-59_19-default is &gt;=16-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052226"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167217"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701447" version="1" comment="kernel-livepatch-5_3_18-59_24-default is &gt;=14-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052445"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167218"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701448" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=14-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167218"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701449" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=13-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167219"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701450" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=12-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167220"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701451" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=12-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167220"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701453" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=3-150400.4.6.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167222"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713754" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713755" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713756" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713757" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713758" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713759" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713760" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713761" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713762" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713763" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713764" version="1" comment="kgraft-patch-4_12_14-122_121-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713765" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=17-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170150"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713766" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=16-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170103"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713767" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713768" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713769" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713770" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713771" version="1" comment="kernel-livepatch-4_12_14-150000_150_89-default is &gt;=4-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059651"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170142"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713772" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=15-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170157"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713773" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=10-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170158"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713774" version="1" comment="kernel-livepatch-4_12_14-150_83-default is &gt;=6-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170151"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713775" version="1" comment="kernel-livepatch-4_12_14-150_86-default is &gt;=5-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059474"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170141"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713776" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=4-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170144"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713777" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=10-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170159"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713778" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=6-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170153"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713779" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=5-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170143"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713780" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=15-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170160"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725514" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=5-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172959"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701151" version="1" comment="kgraft-patch-4_12_14-122_124-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701261" version="1" comment="kernel-livepatch-4_12_14-150000_150_92-default is &gt;=2-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059889"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167141"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701155" version="1" comment="kernel-livepatch-4_12_14-150100_197_114-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009701157" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=3-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009680833" version="1" comment="python3-salt is &lt;3002.2-150200.64.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009042407"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160317"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009680834" version="1" comment="salt is &lt;3002.2-150200.64.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040290"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160317"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009680841" version="1" comment="salt-minion is &lt;3002.2-150200.64.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040297"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160317"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009681002" version="1" comment="salt-transactional-update is &lt;3002.2-150200.64.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051618"/>
		<state state_ref="oval:org.opensuse.security:ste:2009160317"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713781" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713782" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713783" version="1" comment="kgraft-patch-4_12_14-122_66-default is &gt;=15-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051512"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166487"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713784" version="1" comment="kgraft-patch-4_12_14-122_71-default is &gt;=14-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051581"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166498"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713785" version="1" comment="kgraft-patch-4_12_14-122_74-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051677"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713786" version="1" comment="kgraft-patch-4_12_14-122_77-default is &gt;=12-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052174"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166502"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713787" version="1" comment="kgraft-patch-4_12_14-122_80-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052205"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713788" version="1" comment="kgraft-patch-4_12_14-122_83-default is &gt;=10-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052227"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166504"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713789" version="1" comment="kgraft-patch-4_12_14-122_88-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052448"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713790" version="1" comment="kgraft-patch-4_12_14-122_91-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058492"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713791" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713792" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=6-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170161"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713793" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=3-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170137"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713794" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713795" version="1" comment="kernel-livepatch-4_12_14-197_89-default is &gt;=14-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051565"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170138"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713796" version="1" comment="kernel-livepatch-4_12_14-197_92-default is &gt;=13-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051674"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166522"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713797" version="1" comment="kernel-livepatch-4_12_14-197_99-default is &gt;=11-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052201"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170162"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009665606" version="1" comment="xen-libs is &lt;4.13.4_04-3.43.2 for x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009031482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157064"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009669199" version="1" comment="wpa_supplicant is &lt;2.9-4.33.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009034744"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157601"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009665462" version="1" comment="libexpat1 is &lt;2.2.5-3.12.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157058"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009669200" version="1" comment="cyrus-sasl is &lt;2.1.26-5.10.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157602"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009669205" version="1" comment="cyrus-sasl-digestmd5 is &lt;2.1.26-5.10.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030615"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157602"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009669214" version="1" comment="libsasl2-3 is &lt;2.1.26-5.10.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040965"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157602"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009669765" version="1" comment="libexpat1 is &lt;2.2.5-3.15.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157696"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009671238" version="1" comment="libexpat1 is &lt;2.2.5-3.19.1 for aarch64,x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009033468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009157956"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009625089" version="1" comment="libgcc_s1 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040358"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009625100" version="1" comment="libstdc++6 is ==0" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009040364"/>
		<state state_ref="oval:org.opensuse.security:ste:2009079458"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725516" version="1" comment="kgraft-patch-4_12_14-95_105-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060221"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725518" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725520" version="1" comment="kernel-livepatch-4_12_14-150000_150_98-default is &gt;=4-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060219"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170068"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725522" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=4-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170075"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725524" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=5-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166567"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725526" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737234" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=12-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166593"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737179" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=10-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166535"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737180" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=7-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166542"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737181" version="1" comment="kernel-livepatch-5_3_18-150200_24_129-default is &gt;=4-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060347"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737182" version="1" comment="kernel-livepatch-5_3_18-150200_24_134-default is &gt;=4-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737235" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=17-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166589"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737236" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=16-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166590"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737318" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=18-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171218"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729590" version="1" comment="kernel-default is ==5.3.18-150300.59.101.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173744"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009738271" version="1" comment="kernel-livepatch-5_3_18-150300_59_101-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060563"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737319" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=18-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171219"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737320" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=18-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171219"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737321" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737610" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737611" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737612" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737322" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737323" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=10-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737324" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=9-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166560"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737364" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737238" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737239" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737365" version="1" comment="kernel-livepatch-5_3_18-150300_59_98-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729113" version="1" comment="kernel-default is &lt;5.3.18-150300.59.98.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173643"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737366" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=10-150400.4.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009174881"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737613" version="1" comment="kernel-livepatch-5_14_21-150400_24_11-default is &gt;=7-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060153"/>
		<state state_ref="oval:org.opensuse.security:ste:2009174882"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737367" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=7-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009174882"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009738272" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=6-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173644"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737368" version="1" comment="kernel-livepatch-5_14_21-150400_24_28-default is &gt;=4-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737614" version="1" comment="kernel-livepatch-5_14_21-150400_24_33-default is &gt;=3-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713799" version="1" comment="kgraft-patch-4_12_14-95_74-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051574"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713800" version="1" comment="kgraft-patch-4_12_14-95_77-default is &gt;=13-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051676"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713801" version="1" comment="kgraft-patch-4_12_14-95_80-default is &gt;=11-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052204"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169834"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713802" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713803" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713804" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713805" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713806" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713807" version="1" comment="kernel-livepatch-4_12_14-150_72-default is &gt;=14-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009051571"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170164"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713808" version="1" comment="kernel-livepatch-4_12_14-150_75-default is &gt;=11-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009052200"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170165"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713809" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=6-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170166"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713810" version="1" comment="kernel-livepatch-4_12_14-150_83-default is &gt;=3-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170123"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713811" version="1" comment="kernel-livepatch-4_12_14-150_86-default is &gt;=2-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059474"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167141"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715614" version="1" comment="kgraft-patch-4_12_14-122_124-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715615" version="1" comment="kgraft-patch-4_12_14-122_127-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060094"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715343" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714903" version="1" comment="kernel-livepatch-4_12_14-150100_197_114-default is &gt;=5-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170143"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714904" version="1" comment="kernel-livepatch-4_12_14-150100_197_117-default is &gt;=3-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060078"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170168"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714905" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=3-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170168"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009716160" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=6-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170155"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715818" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=6-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170083"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714906" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=5-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170127"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715344" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=4-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166601"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715616" version="1" comment="kernel-livepatch-5_14_21-150400_24_11-default is &gt;=3-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060153"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729566" version="1" comment="kgraft-patch-4_12_14-95_83-default is &gt;=16-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058767"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170103"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729567" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729771" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729491" version="1" comment="kgraft-patch-4_12_14-122_103-default is &gt;=17-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058756"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170150"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729492" version="1" comment="kgraft-patch-4_12_14-122_106-default is &gt;=15-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059194"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170056"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729493" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729494" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729568" version="1" comment="kgraft-patch-4_12_14-122_98-default is &gt;=17-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058586"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170150"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729569" version="1" comment="kernel-livepatch-4_12_14-150_78-default is &gt;=16-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729570" version="1" comment="kernel-livepatch-4_12_14-150_83-default is &gt;=12-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059334"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170152"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729571" version="1" comment="kernel-livepatch-4_12_14-150_86-default is &gt;=11-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059474"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173046"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729496" version="1" comment="kernel-livepatch-4_12_14-197_102-default is &gt;=16-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058755"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170145"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729497" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=12-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170154"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729498" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=11-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173047"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729772" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=16-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166590"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729773" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=15-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166591"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729774" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=17-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166589"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729572" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729573" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729499" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729574" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729500" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729575" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=19-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173742"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729576" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=18-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171219"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729577" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=18-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171219"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755119" version="1" comment="kgraft-patch-4_12_14-95_102-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060093"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755215" version="1" comment="kgraft-patch-4_12_14-95_105-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060221"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755384" version="1" comment="kgraft-patch-4_12_14-95_99-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059968"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755120" version="1" comment="kgraft-patch-4_12_14-122_121-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755216" version="1" comment="kgraft-patch-4_12_14-122_124-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755217" version="1" comment="kgraft-patch-4_12_14-122_127-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060094"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755121" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725519" version="1" comment="kernel-default is &lt;4.12.14-122.130.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172965"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755218" version="1" comment="kernel-livepatch-4_12_14-150100_197_114-default is &gt;=11-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173047"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755219" version="1" comment="kernel-livepatch-4_12_14-150100_197_117-default is &gt;=9-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060078"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170079"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755220" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=9-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170079"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725523" version="1" comment="kernel-default is &lt;4.12.14-150100.197.120.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172967"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755221" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=13-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166592"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755222" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=10-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166595"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725525" version="1" comment="kernel-default is &lt;5.3.18-150200.24.126.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172968"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713812" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713813" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713814" version="1" comment="kernel-livepatch-4_12_14-150000_150_89-default is &gt;=3-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059651"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170167"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713815" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=3-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170168"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713816" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=3-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170169"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009713817" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=3-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166603"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737240" version="1" comment="kgraft-patch-4_12_14-95_102-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060093"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737009" version="1" comment="kgraft-patch-4_12_14-95_105-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060221"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714512" version="1" comment="kernel-default is ==4.12.14-95.108.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170379"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737241" version="1" comment="kgraft-patch-4_12_14-95_108-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060348"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729505" version="1" comment="kernel-default is ==4.12.14-95.111.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173722"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737242" version="1" comment="kgraft-patch-4_12_14-95_111-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060444"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737325" version="1" comment="kgraft-patch-4_12_14-95_88-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059337"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737326" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737369" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737327" version="1" comment="kgraft-patch-4_12_14-95_99-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059968"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737328" version="1" comment="kgraft-patch-4_12_14-122_110-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059338"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737329" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737370" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737330" version="1" comment="kgraft-patch-4_12_14-122_121-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737331" version="1" comment="kgraft-patch-4_12_14-122_124-default is &gt;=8-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737371" version="1" comment="kgraft-patch-4_12_14-122_127-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060094"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737332" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715347" version="1" comment="kernel-default is ==4.12.14-122.133.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170459"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737372" version="1" comment="kgraft-patch-4_12_14-122_133-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729511" version="1" comment="kernel-default is ==4.12.14-122.136.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173723"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737333" version="1" comment="kgraft-patch-4_12_14-122_136-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729513" version="1" comment="kernel-default is &lt;4.12.14-122.136.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173724"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737244" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=11-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173047"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737183" version="1" comment="kernel-livepatch-4_12_14-150100_197_114-default is &gt;=8-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166516"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737184" version="1" comment="kernel-livepatch-4_12_14-150100_197_117-default is &gt;=6-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060078"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170161"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737185" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=6-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170161"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729104" version="1" comment="kernel-default is ==4.12.14-150100.197.123.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173640"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737010" version="1" comment="kernel-livepatch-4_12_14-150100_197_123-default is &gt;=3-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170137"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729519" version="1" comment="kernel-default is ==4.12.14-150100.197.126.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173727"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737186" version="1" comment="kernel-livepatch-4_12_14-150100_197_126-default is &gt;=3-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060439"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170137"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737187" version="1" comment="kernel-livepatch-4_12_14-197_105-default is &gt;=13-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059287"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170078"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737188" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=12-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170154"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725513" version="1" comment="kernel-default is &lt;5.14.21-150400.24.28.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172963"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729502" version="1" comment="kgraft-patch-4_12_14-95_102-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060093"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729503" version="1" comment="kgraft-patch-4_12_14-95_105-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060221"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729504" version="1" comment="kgraft-patch-4_12_14-95_108-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060348"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729506" version="1" comment="kgraft-patch-4_12_14-95_111-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060444"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729578" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729097" version="1" comment="kgraft-patch-4_12_14-95_99-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059968"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729579" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729507" version="1" comment="kgraft-patch-4_12_14-122_121-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729508" version="1" comment="kgraft-patch-4_12_14-122_124-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729509" version="1" comment="kgraft-patch-4_12_14-122_127-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060094"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729098" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729510" version="1" comment="kgraft-patch-4_12_14-122_133-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729512" version="1" comment="kgraft-patch-4_12_14-122_136-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729099" version="1" comment="kernel-default is ==4.12.14-150000.150.101.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173638"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729100" version="1" comment="kernel-livepatch-4_12_14-150000_150_101-default is &gt;=2-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060345"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167141"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729514" version="1" comment="kernel-default is ==4.12.14-150000.150.104.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173725"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729515" version="1" comment="kernel-livepatch-4_12_14-150000_150_104-default is &gt;=2-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060443"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167141"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729580" version="1" comment="kernel-livepatch-4_12_14-150000_150_89-default is &gt;=10-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059651"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170158"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729581" version="1" comment="kernel-livepatch-4_12_14-150000_150_92-default is &gt;=7-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059889"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170122"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729582" version="1" comment="kernel-livepatch-4_12_14-150000_150_95-default is &gt;=5-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060077"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170131"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729583" version="1" comment="kernel-livepatch-4_12_14-150000_150_98-default is &gt;=5-150000.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060219"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170131"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729517" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=10-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170159"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729102" version="1" comment="kernel-livepatch-4_12_14-150100_197_114-default is &gt;=7-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170136"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729103" version="1" comment="kernel-livepatch-4_12_14-150100_197_117-default is &gt;=5-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060078"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170132"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729518" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=5-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170132"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729105" version="1" comment="kernel-livepatch-4_12_14-150100_197_123-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729520" version="1" comment="kernel-livepatch-4_12_14-150100_197_126-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060439"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729775" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=11-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166594"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729107" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=9-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166538"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729108" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=6-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166573"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729521" version="1" comment="kernel-livepatch-5_3_18-150200_24_129-default is &gt;=3-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060347"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729109" version="1" comment="kernel-livepatch-5_3_18-150200_24_134-default is &gt;=3-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729584" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729585" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=10-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166596"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729522" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=9-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166560"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729586" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729523" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729524" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729111" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729112" version="1" comment="kernel-livepatch-5_3_18-150300_59_98-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729587" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=9-150400.4.24.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173743"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729114" version="1" comment="kernel-livepatch-5_14_21-150400_24_11-default is &gt;=6-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060153"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173644"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729115" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=6-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173644"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729588" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=5-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172959"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729589" version="1" comment="kernel-livepatch-5_14_21-150400_24_28-default is &gt;=3-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742686" version="1" comment="kgraft-patch-4_12_14-95_102-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060093"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742526" version="1" comment="kgraft-patch-4_12_14-95_105-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060221"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742527" version="1" comment="kgraft-patch-4_12_14-95_108-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060348"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742528" version="1" comment="kgraft-patch-4_12_14-95_111-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060444"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742251" version="1" comment="kernel-default is ==4.12.14-95.114.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175688"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742252" version="1" comment="kgraft-patch-4_12_14-95_114-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060753"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742529" version="1" comment="kgraft-patch-4_12_14-95_93-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059478"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742687" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742530" version="1" comment="kgraft-patch-4_12_14-95_99-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059968"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742531" version="1" comment="kgraft-patch-4_12_14-122_113-default is &gt;=14-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059479"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169922"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742688" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742689" version="1" comment="kgraft-patch-4_12_14-122_121-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742532" version="1" comment="kgraft-patch-4_12_14-122_124-default is &gt;=9-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169800"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742533" version="1" comment="kgraft-patch-4_12_14-122_127-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060094"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742534" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=7-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169780"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742690" version="1" comment="kgraft-patch-4_12_14-122_133-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742535" version="1" comment="kgraft-patch-4_12_14-122_136-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729116" version="1" comment="kernel-default is ==4.12.14-122.139.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173645"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742254" version="1" comment="kgraft-patch-4_12_14-122_139-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060549"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742255" version="1" comment="kernel-default is ==4.12.14-122.144.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175690"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742256" version="1" comment="kgraft-patch-4_12_14-122_144-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060732"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742257" version="1" comment="kernel-default is &lt;4.12.14-122.144.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175691"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742536" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=12-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170154"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742537" version="1" comment="kernel-livepatch-4_12_14-150100_197_114-default is &gt;=9-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175731"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742538" version="1" comment="kernel-livepatch-4_12_14-150100_197_117-default is &gt;=7-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060078"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170136"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742539" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=7-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170136"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742540" version="1" comment="kernel-livepatch-4_12_14-150100_197_123-default is &gt;=4-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170075"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742541" version="1" comment="kernel-livepatch-4_12_14-150100_197_126-default is &gt;=4-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060439"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170075"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742258" version="1" comment="kernel-default is ==4.12.14-150100.197.131.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175692"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742259" version="1" comment="kernel-livepatch-4_12_14-150100_197_131-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060738"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742542" version="1" comment="kernel-livepatch-4_12_14-197_108-default is &gt;=13-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059475"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170078"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742691" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=13-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166592"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742543" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=11-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166572"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742544" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=8-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166540"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742545" version="1" comment="kernel-livepatch-5_3_18-150200_24_129-default is &gt;=5-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060347"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166567"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742546" version="1" comment="kernel-livepatch-5_3_18-150200_24_134-default is &gt;=5-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166567"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742261" version="1" comment="kernel-default is ==5.3.18-150200.24.139.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175694"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742262" version="1" comment="kernel-livepatch-5_3_18-150200_24_139-default is &gt;=2-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169354"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742547" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=17-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166589"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737237" version="1" comment="kernel-default is &lt;5.3.18-24.107.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009174858"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742264" version="1" comment="kernel-livepatch-5_3_18-150300_59_101-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060563"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742548" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742549" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742692" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742693" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742550" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=11-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166582"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742694" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=10-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166557"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742695" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=9-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166560"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742696" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=8-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166562"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742697" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742698" version="1" comment="kernel-livepatch-5_3_18-150300_59_98-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009743615" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=11-150400.7.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175989"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009743616" version="1" comment="kernel-livepatch-5_14_21-150400_24_11-default is &gt;=8-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060153"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175990"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009743617" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=8-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175990"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009743618" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=7-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009174882"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009743619" version="1" comment="kernel-livepatch-5_14_21-150400_24_28-default is &gt;=5-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172959"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715346" version="1" comment="kgraft-patch-4_12_14-95_102-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060093"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714511" version="1" comment="kgraft-patch-4_12_14-95_105-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060221"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714513" version="1" comment="kgraft-patch-4_12_14-95_108-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060348"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714514" version="1" comment="kgraft-patch-4_12_14-95_99-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059968"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715348" version="1" comment="kgraft-patch-4_12_14-122_133-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714515" version="1" comment="kernel-livepatch-4_12_14-150000_150_92-default is &gt;=5-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059889"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170141"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715618" version="1" comment="kernel-livepatch-4_12_14-150000_150_95-default is &gt;=3-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060077"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170167"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009714516" version="1" comment="kernel-livepatch-4_12_14-150000_150_98-default is &gt;=3-150000.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060219"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170167"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715619" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=3-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718699" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=9-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166587"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718700" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=7-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166542"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718701" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=4-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718702" version="1" comment="kernel-livepatch-5_3_18-24_102-default is &gt;=14-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059335"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170082"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718703" version="1" comment="kernel-livepatch-5_3_18-24_107-default is &gt;=13-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059476"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166592"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718704" version="1" comment="kernel-livepatch-5_3_18-24_86-default is &gt;=18-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058499"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171218"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718705" version="1" comment="kernel-livepatch-5_3_18-24_93-default is &gt;=17-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058587"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166589"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718706" version="1" comment="kernel-livepatch-5_3_18-24_96-default is &gt;=16-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058668"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166590"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718707" version="1" comment="kernel-livepatch-5_3_18-24_99-default is &gt;=15-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059241"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166591"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718708" version="1" comment="kernel-livepatch-5_3_18-150300_59_43-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059242"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718709" version="1" comment="kernel-livepatch-5_3_18-150300_59_46-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718710" version="1" comment="kernel-livepatch-5_3_18-150300_59_49-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059336"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718860" version="1" comment="kernel-livepatch-5_3_18-150300_59_54-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059477"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718711" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718712" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718713" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718714" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718715" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718716" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718717" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718368" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718718" version="1" comment="kernel-livepatch-5_3_18-59_27-default is &gt;=18-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058491"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171219"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718719" version="1" comment="kernel-livepatch-5_3_18-59_34-default is &gt;=17-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058584"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718720" version="1" comment="kernel-livepatch-5_3_18-59_37-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009058693"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718721" version="1" comment="kernel-livepatch-5_3_18-59_40-default is &gt;=16-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059193"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166608"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718722" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=7-150400.4.18.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171220"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718723" version="1" comment="kernel-livepatch-5_14_21-150400_24_11-default is &gt;=4-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060153"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718370" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=4-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009718371" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=3-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009715602" version="1" comment="kernel-default is &lt;5.14.21-150400.24.21.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170607"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729591" version="1" comment="kernel-livepatch-5_3_18-150300_59_101-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060563"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725528" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009725256" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=4-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009729117" version="1" comment="kgraft-patch-4_12_14-122_139-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060549"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711321" version="1" comment="kernel-default is ==" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169742"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009738273" version="1" comment="kernel-livepatch-5_14_21-150400_15_5-rt is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737373" version="1" comment="kernel-default is ==5.14.21-150400.24.38.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009174883"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009737374" version="1" comment="kernel-livepatch-5_14_21-150400_24_38-default is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060751"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009711367" version="1" comment="kernel-default is &lt;" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169761"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769980" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=12-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166593"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769981" version="1" comment="kernel-livepatch-5_3_18-150200_24_129-default is &gt;=9-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060347"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166587"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769982" version="1" comment="kernel-livepatch-5_3_18-150200_24_134-default is &gt;=9-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166587"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770206" version="1" comment="kernel-livepatch-5_3_18-150200_24_139-default is &gt;=6-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170155"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751206" version="1" comment="kernel-default is ==5.3.18-150200.24.142.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177710"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769983" version="1" comment="kernel-livepatch-5_3_18-150200_24_142-default is &gt;=5-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060956"/>
		<state state_ref="oval:org.opensuse.security:ste:2009183249"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751208" version="1" comment="kernel-default is ==5.3.18-150200.24.145.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177712"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769984" version="1" comment="kernel-livepatch-5_3_18-150200_24_145-default is &gt;=4-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061067"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751210" version="1" comment="kernel-default is &lt;5.3.18-150200.24.145.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177713"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770207" version="1" comment="kernel-livepatch-5_3_18-150300_59_101-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060563"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742266" version="1" comment="kernel-default is ==5.3.18-150300.59.106.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175697"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770208" version="1" comment="kernel-livepatch-5_3_18-150300_59_106-default is &gt;=6-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060746"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170083"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742711" version="1" comment="kernel-default is ==5.3.18-150300.59.109.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175763"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770209" version="1" comment="kernel-livepatch-5_3_18-150300_59_109-default is &gt;=6-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060937"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170083"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751212" version="1" comment="kernel-default is ==5.3.18-150300.59.112.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177714"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770210" version="1" comment="kernel-livepatch-5_3_18-150300_59_112-default is &gt;=5-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170127"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751214" version="1" comment="kernel-default is ==5.3.18-150300.59.115.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177716"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769985" version="1" comment="kernel-livepatch-5_3_18-150300_59_115-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061085"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770211" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770251" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770212" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770213" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770214" version="1" comment="kernel-livepatch-5_3_18-150300_59_98-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770252" version="1" comment="kernel-livepatch-5_14_21-150400_24_11-default is &gt;=12-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060153"/>
		<state state_ref="oval:org.opensuse.security:ste:2009183293"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770215" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=12-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009183293"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742267" version="1" comment="kernel-livepatch-5_3_18-150300_59_106-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060746"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742712" version="1" comment="kernel-livepatch-5_3_18-150300_59_109-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060937"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009743620" version="1" comment="kernel-livepatch-5_14_21-150400_15_5-rt is &gt;=3-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009743621" version="1" comment="kernel-livepatch-5_14_21-150400_15_8-rt is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060939"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009743622" version="1" comment="kernel-livepatch-5_14_21-150400_24_33-default is &gt;=4-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009743623" version="1" comment="kernel-livepatch-5_14_21-150400_24_38-default is &gt;=3-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060751"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009743624" version="1" comment="kernel-default is ==5.14.21-150400.24.41.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175991"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009743625" version="1" comment="kernel-livepatch-5_14_21-150400_24_41-default is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060940"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751177" version="1" comment="kgraft-patch-4_12_14-122_116-default is &gt;=13-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059627"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170063"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751178" version="1" comment="kgraft-patch-4_12_14-122_121-default is &gt;=11-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059702"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167106"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751179" version="1" comment="kgraft-patch-4_12_14-122_124-default is &gt;=10-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167187"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751180" version="1" comment="kgraft-patch-4_12_14-122_127-default is &gt;=8-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060094"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167189"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751181" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=8-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167189"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751182" version="1" comment="kgraft-patch-4_12_14-122_133-default is &gt;=6-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167108"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751183" version="1" comment="kgraft-patch-4_12_14-122_136-default is &gt;=5-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167113"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751184" version="1" comment="kgraft-patch-4_12_14-122_139-default is &gt;=4-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060549"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169769"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751185" version="1" comment="kgraft-patch-4_12_14-122_144-default is &gt;=3-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060732"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167192"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751186" version="1" comment="kernel-default is ==4.12.14-122.147.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177701"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751187" version="1" comment="kgraft-patch-4_12_14-122_147-default is &gt;=2-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060867"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170022"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751188" version="1" comment="kernel-default is &lt;4.12.14-122.147.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177702"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750757" version="1" comment="kernel-livepatch-5_3_18-150200_24_112-default is &gt;=14-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059625"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167154"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750758" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=12-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167155"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750759" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=9-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167152"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750760" version="1" comment="kernel-livepatch-5_3_18-150200_24_129-default is &gt;=6-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060347"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177512"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751189" version="1" comment="kernel-livepatch-5_3_18-150200_24_134-default is &gt;=6-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177512"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751190" version="1" comment="kernel-livepatch-5_3_18-150200_24_139-default is &gt;=3-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177703"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742263" version="1" comment="kernel-default is &lt;5.3.18-150200.24.139.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175695"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750762" version="1" comment="kernel-livepatch-5_3_18-150300_59_101-default is &gt;=5-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060563"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167213"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750763" version="1" comment="kernel-livepatch-5_3_18-150300_59_106-default is &gt;=3-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060746"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177514"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751191" version="1" comment="kernel-livepatch-5_3_18-150300_59_60-default is &gt;=17-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059539"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167216"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751192" version="1" comment="kernel-livepatch-5_3_18-150300_59_63-default is &gt;=14-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059626"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167218"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751193" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=13-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167219"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751194" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=12-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167220"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751195" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=11-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167209"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751196" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=10-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167210"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751197" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=9-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167211"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750764" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=8-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177515"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751198" version="1" comment="kernel-livepatch-5_3_18-150300_59_98-default is &gt;=6-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177704"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750643" version="1" comment="kernel-livepatch-5_14_21-150400_15_5-rt is &gt;=4-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751199" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=12-150400.10.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177705"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751200" version="1" comment="kernel-livepatch-5_14_21-150400_24_11-default is &gt;=9-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060153"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177706"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751201" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=9-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177706"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751202" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=8-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177707"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751203" version="1" comment="kernel-livepatch-5_14_21-150400_24_28-default is &gt;=6-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177708"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751204" version="1" comment="kernel-livepatch-5_14_21-150400_24_33-default is &gt;=5-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177709"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751205" version="1" comment="kernel-livepatch-5_14_21-150400_24_38-default is &gt;=4-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060751"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009752332" version="1" comment="kernel-livepatch-5_14_21-150400_24_41-default is &gt;=3-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060940"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764659" version="1" comment="kernel-livepatch-5_14_21-150400_15_11-rt is &gt;=4-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061016"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178777"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764660" version="1" comment="kernel-livepatch-5_14_21-150400_15_18-rt is &gt;=3-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061967"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764661" version="1" comment="kernel-livepatch-5_14_21-150400_15_23-rt is &gt;=2-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062041"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170606"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764662" version="1" comment="kernel-livepatch-5_14_21-150400_15_5-rt is &gt;=6-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178812"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764663" version="1" comment="kernel-livepatch-5_14_21-150400_15_8-rt is &gt;=5-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060939"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178776"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009765065" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=14-150400.16.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182200"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764664" version="1" comment="kernel-livepatch-5_14_21-150400_24_11-default is &gt;=11-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060153"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182089"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764665" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=11-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182089"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764666" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=10-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182090"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764667" version="1" comment="kernel-livepatch-5_14_21-150400_24_28-default is &gt;=8-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177707"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764668" version="1" comment="kernel-livepatch-5_14_21-150400_24_33-default is &gt;=7-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182091"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764669" version="1" comment="kernel-livepatch-5_14_21-150400_24_38-default is &gt;=6-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060751"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177708"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764670" version="1" comment="kernel-livepatch-5_14_21-150400_24_41-default is &gt;=5-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060940"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177709"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751216" version="1" comment="kernel-default is ==5.14.21-150400.24.46.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177717"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764671" version="1" comment="kernel-livepatch-5_14_21-150400_24_46-default is &gt;=4-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060977"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177489"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755396" version="1" comment="kernel-default is ==5.14.21-150400.24.55.3" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178813"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764672" version="1" comment="kernel-livepatch-5_14_21-150400_24_55-default is &gt;=3-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764673" version="1" comment="kernel-default is ==5.14.21-150400.24.60.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182092"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764674" version="1" comment="kernel-livepatch-5_14_21-150400_24_60-default is &gt;=2-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062027"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177490"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764675" version="1" comment="kernel-livepatch-5_3_18-150200_24_115-default is &gt;=14-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059891"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167154"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764676" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=11-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167156"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764677" version="1" comment="kernel-livepatch-5_3_18-150200_24_129-default is &gt;=8-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060347"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182093"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764678" version="1" comment="kernel-livepatch-5_3_18-150200_24_134-default is &gt;=8-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182093"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764679" version="1" comment="kernel-livepatch-5_3_18-150200_24_139-default is &gt;=5-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167151"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764680" version="1" comment="kernel-livepatch-5_3_18-150200_24_142-default is &gt;=4-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060956"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182094"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764681" version="1" comment="kernel-livepatch-5_3_18-150200_24_145-default is &gt;=3-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061067"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177703"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764682" version="1" comment="kernel-livepatch-5_3_18-150300_59_101-default is &gt;=7-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060563"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182095"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764683" version="1" comment="kernel-livepatch-5_3_18-150300_59_106-default is &gt;=5-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060746"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167213"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764684" version="1" comment="kernel-livepatch-5_3_18-150300_59_109-default is &gt;=5-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060937"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167213"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764685" version="1" comment="kernel-livepatch-5_3_18-150300_59_112-default is &gt;=4-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167214"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764686" version="1" comment="kernel-livepatch-5_3_18-150300_59_115-default is &gt;=3-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061085"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177514"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764687" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=14-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167218"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764688" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=13-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167219"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764689" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764690" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=11-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167209"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764691" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=10-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167210"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764692" version="1" comment="kernel-livepatch-5_3_18-150300_59_98-default is &gt;=8-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177515"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755385" version="1" comment="kgraft-patch-4_12_14-95_108-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060348"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755386" version="1" comment="kgraft-patch-4_12_14-95_111-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060444"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755223" version="1" comment="kgraft-patch-4_12_14-95_114-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060753"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751223" version="1" comment="kernel-default is ==4.12.14-95.117.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177718"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755387" version="1" comment="kgraft-patch-4_12_14-95_117-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060957"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755224" version="1" comment="kgraft-patch-4_12_14-122_133-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755225" version="1" comment="kgraft-patch-4_12_14-122_136-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755226" version="1" comment="kgraft-patch-4_12_14-122_139-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060549"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755227" version="1" comment="kgraft-patch-4_12_14-122_144-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060732"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755228" version="1" comment="kgraft-patch-4_12_14-122_147-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060867"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755229" version="1" comment="kernel-livepatch-4_12_14-150100_197_123-default is &gt;=6-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170153"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755230" version="1" comment="kernel-livepatch-4_12_14-150100_197_126-default is &gt;=6-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060439"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170153"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755231" version="1" comment="kernel-livepatch-4_12_14-150100_197_131-default is &gt;=4-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060738"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170144"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751233" version="1" comment="kernel-default is ==4.12.14-150100.197.134.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177722"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755232" version="1" comment="kernel-livepatch-4_12_14-150100_197_134-default is &gt;=3-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060955"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170168"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751235" version="1" comment="kernel-default is &lt;4.12.14-150100.197.134.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177724"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755233" version="1" comment="kernel-livepatch-5_3_18-150200_24_129-default is &gt;=7-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060347"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170081"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755234" version="1" comment="kernel-livepatch-5_3_18-150200_24_134-default is &gt;=7-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170081"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755235" version="1" comment="kernel-livepatch-5_3_18-150200_24_139-default is &gt;=4-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166584"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755236" version="1" comment="kernel-livepatch-5_3_18-150200_24_142-default is &gt;=3-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060956"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170169"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751236" version="1" comment="kernel-default is &lt;5.3.18-150200.24.142.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177725"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755237" version="1" comment="kernel-livepatch-5_3_18-150300_59_101-default is &gt;=6-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060563"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170083"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755238" version="1" comment="kernel-livepatch-5_3_18-150300_59_106-default is &gt;=4-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060746"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166601"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755388" version="1" comment="kernel-livepatch-5_3_18-150300_59_109-default is &gt;=4-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060937"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166601"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755389" version="1" comment="kernel-livepatch-5_3_18-150300_59_112-default is &gt;=3-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166603"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755239" version="1" comment="kernel-livepatch-5_3_18-150300_59_68-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059700"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755240" version="1" comment="kernel-livepatch-5_3_18-150300_59_71-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059787"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755241" version="1" comment="kernel-livepatch-5_3_18-150300_59_76-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059788"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755242" version="1" comment="kernel-livepatch-5_3_18-150300_59_87-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060183"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755243" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=10-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166596"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755244" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755245" version="1" comment="kernel-livepatch-5_3_18-150300_59_98-default is &gt;=7-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166599"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755246" version="1" comment="kernel-livepatch-5_14_21-150400_15_5-rt is &gt;=5-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178776"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755247" version="1" comment="kernel-livepatch-5_14_21-150400_15_8-rt is &gt;=4-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060939"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178777"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755390" version="1" comment="kernel-livepatch-5_14_21-150400_22-default is &gt;=13-150400.13.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060074"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178809"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755391" version="1" comment="kernel-livepatch-5_14_21-150400_24_11-default is &gt;=10-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060153"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178810"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755392" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=10-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178810"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755248" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=9-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178778"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755393" version="1" comment="kernel-livepatch-5_14_21-150400_24_28-default is &gt;=7-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178811"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755394" version="1" comment="kernel-livepatch-5_14_21-150400_24_33-default is &gt;=6-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178812"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755249" version="1" comment="kernel-livepatch-5_14_21-150400_24_38-default is &gt;=5-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060751"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178776"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755395" version="1" comment="kernel-livepatch-5_14_21-150400_24_41-default is &gt;=4-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060940"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178777"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009786219" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=13-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169924"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009786220" version="1" comment="kgraft-patch-4_12_14-122_133-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009794740" version="1" comment="kgraft-patch-4_12_14-122_136-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795130" version="1" comment="kgraft-patch-4_12_14-122_139-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060549"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795131" version="1" comment="kgraft-patch-4_12_14-122_144-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060732"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795992" version="1" comment="kgraft-patch-4_12_14-122_147-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060867"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751227" version="1" comment="kernel-default is ==4.12.14-122.150.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177719"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009786221" version="1" comment="kgraft-patch-4_12_14-122_150-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764702" version="1" comment="kernel-default is ==4.12.14-122.153.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182096"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009786222" version="1" comment="kgraft-patch-4_12_14-122_153-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061064"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764728" version="1" comment="kernel-default is ==4.12.14-122.156.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182104"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009786223" version="1" comment="kgraft-patch-4_12_14-122_156-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770229" version="1" comment="kernel-default is ==4.12.14-122.159.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009183294"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795132" version="1" comment="kgraft-patch-4_12_14-122_159-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062102"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776021" version="1" comment="kernel-default is ==4.12.14-122.162.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184162"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009786224" version="1" comment="kgraft-patch-4_12_14-122_162-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062252"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776023" version="1" comment="kernel-default is &lt;4.12.14-122.162.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184163"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795133" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=13-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170078"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009782315" version="1" comment="kernel-livepatch-4_12_14-150100_197_123-default is &gt;=10-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170159"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009782316" version="1" comment="kernel-livepatch-4_12_14-150100_197_126-default is &gt;=10-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060439"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170159"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009794741" version="1" comment="kernel-livepatch-4_12_14-150100_197_131-default is &gt;=8-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060738"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177518"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795134" version="1" comment="kernel-livepatch-4_12_14-150100_197_134-default is &gt;=7-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060955"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170074"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764712" version="1" comment="kernel-default is ==4.12.14-150100.197.137.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182098"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009782317" version="1" comment="kernel-livepatch-4_12_14-150100_197_137-default is &gt;=5-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061065"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170132"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764731" version="1" comment="kernel-default is ==4.12.14-150100.197.142.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182106"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009782318" version="1" comment="kernel-livepatch-4_12_14-150100_197_142-default is &gt;=5-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062004"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170132"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764734" version="1" comment="kernel-default is ==4.12.14-150100.197.145.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182108"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009782319" version="1" comment="kernel-livepatch-4_12_14-150100_197_145-default is &gt;=5-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062103"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170132"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764736" version="1" comment="kernel-default is &lt;4.12.14-150100.197.145.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182109"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795742" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=14-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170082"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795743" version="1" comment="kernel-livepatch-5_3_18-150200_24_129-default is &gt;=11-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060347"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166594"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795744" version="1" comment="kernel-livepatch-5_3_18-150200_24_134-default is &gt;=11-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166594"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795745" version="1" comment="kernel-livepatch-5_3_18-150200_24_139-default is &gt;=8-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166588"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795746" version="1" comment="kernel-livepatch-5_3_18-150200_24_142-default is &gt;=7-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060956"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170081"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795747" version="1" comment="kernel-livepatch-5_3_18-150200_24_145-default is &gt;=6-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061067"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166573"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764715" version="1" comment="kernel-default is ==5.3.18-150200.24.148.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182101"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795748" version="1" comment="kernel-livepatch-5_3_18-150200_24_148-default is &gt;=5-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062005"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166567"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764737" version="1" comment="kernel-default is ==5.3.18-150200.24.151.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795749" version="1" comment="kernel-livepatch-5_3_18-150200_24_151-default is &gt;=5-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062086"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166567"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776028" version="1" comment="kernel-default is ==5.3.18-150200.24.154.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184164"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795750" version="1" comment="kernel-livepatch-5_3_18-150200_24_154-default is &gt;=3-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062296"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776030" version="1" comment="kernel-default is &lt;5.3.18-150200.24.154.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184165"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795751" version="1" comment="kernel-livepatch-5_3_18-150300_59_101-default is &gt;=10-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060563"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166596"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009794742" version="1" comment="kernel-livepatch-5_3_18-150300_59_106-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060746"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795752" version="1" comment="kernel-livepatch-5_3_18-150300_59_109-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060937"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795753" version="1" comment="kernel-livepatch-5_3_18-150300_59_112-default is &gt;=7-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166599"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795824" version="1" comment="kernel-livepatch-5_3_18-150300_59_115-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061085"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764718" version="1" comment="kernel-default is ==5.3.18-150300.59.118.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182103"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795993" version="1" comment="kernel-livepatch-5_3_18-150300_59_118-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062001"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764740" version="1" comment="kernel-default is ==5.3.18-150300.59.121.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182112"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795825" version="1" comment="kernel-livepatch-5_3_18-150300_59_121-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062100"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775813" version="1" comment="kernel-default is ==5.3.18-150300.59.124.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184119"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795994" version="1" comment="kernel-livepatch-5_3_18-150300_59_124-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062294"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795135" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009794743" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795136" version="1" comment="kernel-livepatch-5_3_18-150300_59_98-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796654" version="1" comment="kernel-livepatch-5_14_21-150400_15_11-rt is &gt;=7-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061016"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178811"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796655" version="1" comment="kernel-livepatch-5_14_21-150400_15_18-rt is &gt;=6-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061967"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173644"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796656" version="1" comment="kernel-livepatch-5_14_21-150400_15_23-rt is &gt;=5-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062041"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172959"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796657" version="1" comment="kernel-livepatch-5_14_21-150400_15_28-rt is &gt;=5-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062101"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172959"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796658" version="1" comment="kernel-livepatch-5_14_21-150400_15_5-rt is &gt;=9-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178778"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796659" version="1" comment="kernel-livepatch-5_14_21-150400_15_8-rt is &gt;=8-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060939"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795995" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=14-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188233"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795996" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=13-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184121"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795997" version="1" comment="kernel-livepatch-5_14_21-150400_24_28-default is &gt;=11-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188234"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795998" version="1" comment="kernel-livepatch-5_14_21-150400_24_33-default is &gt;=10-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178810"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795999" version="1" comment="kernel-livepatch-5_14_21-150400_24_38-default is &gt;=9-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060751"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178778"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796000" version="1" comment="kernel-livepatch-5_14_21-150400_24_41-default is &gt;=8-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060940"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796001" version="1" comment="kernel-livepatch-5_14_21-150400_24_46-default is &gt;=7-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060977"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178811"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796002" version="1" comment="kernel-livepatch-5_14_21-150400_24_55-default is &gt;=6-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173644"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796003" version="1" comment="kernel-livepatch-5_14_21-150400_24_60-default is &gt;=5-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062027"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172959"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764743" version="1" comment="kernel-default is ==5.14.21-150400.24.63.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182113"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796004" version="1" comment="kernel-livepatch-5_14_21-150400_24_63-default is &gt;=5-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062070"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172959"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776036" version="1" comment="kernel-default is ==5.14.21-150400.24.66.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184168"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796005" version="1" comment="kernel-livepatch-5_14_21-150400_24_66-default is &gt;=3-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062295"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796660" version="1" comment="kernel-livepatch-5_14_21-150500_11-rt is &gt;=3-150500.6.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062421"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188236"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776034" version="1" comment="kernel-default is ==5.14.21-150500.53.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184166"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796007" version="1" comment="kernel-livepatch-5_14_21-150500_53-default is &gt;=3-150500.6.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188236"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751207" version="1" comment="kernel-livepatch-5_3_18-150200_24_142-default is &gt;=2-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060956"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177711"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751209" version="1" comment="kernel-livepatch-5_3_18-150200_24_145-default is &gt;=2-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061067"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177711"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751211" version="1" comment="kernel-livepatch-5_3_18-150300_59_109-default is &gt;=3-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060937"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177514"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751213" version="1" comment="kernel-livepatch-5_3_18-150300_59_112-default is &gt;=2-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177715"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751215" version="1" comment="kernel-livepatch-5_3_18-150300_59_115-default is &gt;=2-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061085"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177715"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750644" version="1" comment="kernel-livepatch-5_14_21-150400_15_11-rt is &gt;=2-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061016"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177490"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750645" version="1" comment="kernel-livepatch-5_14_21-150400_15_8-rt is &gt;=3-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060939"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177491"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751217" version="1" comment="kernel-livepatch-5_14_21-150400_24_46-default is &gt;=2-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060977"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177490"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755122" version="1" comment="kernel-default is ==4.12.14-95.120.4" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178743"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755123" version="1" comment="kgraft-patch-4_12_14-95_120-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061043"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755250" version="1" comment="kgraft-patch-4_12_14-122_150-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751229" version="1" comment="kernel-default is &lt;4.12.14-122.150.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177720"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755251" version="1" comment="kernel-livepatch-5_14_21-150400_15_11-rt is &gt;=3-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061016"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755642" version="1" comment="kernel-livepatch-5_14_21-150400_24_46-default is &gt;=3-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060977"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764693" version="1" comment="kgraft-patch-4_12_14-122_124-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764694" version="1" comment="kgraft-patch-4_12_14-122_127-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060094"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764695" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764696" version="1" comment="kgraft-patch-4_12_14-122_133-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764697" version="1" comment="kgraft-patch-4_12_14-122_136-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764698" version="1" comment="kgraft-patch-4_12_14-122_139-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060549"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764699" version="1" comment="kgraft-patch-4_12_14-122_144-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060732"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764700" version="1" comment="kgraft-patch-4_12_14-122_147-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060867"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764701" version="1" comment="kgraft-patch-4_12_14-122_150-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764703" version="1" comment="kgraft-patch-4_12_14-122_153-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061064"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764704" version="1" comment="kernel-default is &lt;4.12.14-122.153.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182097"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764705" version="1" comment="kernel-livepatch-4_12_14-150100_197_114-default is &gt;=12-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170154"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764706" version="1" comment="kernel-livepatch-4_12_14-150100_197_117-default is &gt;=10-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060078"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170159"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764707" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=10-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170159"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764708" version="1" comment="kernel-livepatch-4_12_14-150100_197_123-default is &gt;=7-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170074"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764709" version="1" comment="kernel-livepatch-4_12_14-150100_197_126-default is &gt;=7-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060439"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170074"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764710" version="1" comment="kernel-livepatch-4_12_14-150100_197_131-default is &gt;=5-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060738"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170143"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764711" version="1" comment="kernel-livepatch-4_12_14-150100_197_134-default is &gt;=4-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060955"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170144"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764713" version="1" comment="kernel-livepatch-4_12_14-150100_197_137-default is &gt;=2-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061065"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182099"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764714" version="1" comment="kernel-default is &lt;4.12.14-150100.197.137.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182100"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769736" version="1" comment="kgraft-patch-4_12_14-95_102-default is &gt;=11-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060093"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167106"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769737" version="1" comment="kgraft-patch-4_12_14-95_105-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060221"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769987" version="1" comment="kgraft-patch-4_12_14-95_108-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060348"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770216" version="1" comment="kgraft-patch-4_12_14-95_111-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060444"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769988" version="1" comment="kgraft-patch-4_12_14-95_114-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060753"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769989" version="1" comment="kgraft-patch-4_12_14-95_117-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060957"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769738" version="1" comment="kgraft-patch-4_12_14-95_120-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061043"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755124" version="1" comment="kernel-default is &lt;4.12.14-95.120.4" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178744"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770217" version="1" comment="kgraft-patch-4_12_14-122_127-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060094"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770218" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770219" version="1" comment="kgraft-patch-4_12_14-122_133-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769990" version="1" comment="kgraft-patch-4_12_14-122_136-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769991" version="1" comment="kgraft-patch-4_12_14-122_139-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060549"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769992" version="1" comment="kgraft-patch-4_12_14-122_144-default is &gt;=6-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060732"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169797"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770220" version="1" comment="kgraft-patch-4_12_14-122_147-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060867"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770221" version="1" comment="kgraft-patch-4_12_14-122_150-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769993" version="1" comment="kgraft-patch-4_12_14-122_153-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061064"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770222" version="1" comment="kernel-livepatch-4_12_14-150100_197_117-default is &gt;=11-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060078"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173047"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769994" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=11-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173047"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770223" version="1" comment="kernel-livepatch-4_12_14-150100_197_123-default is &gt;=8-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170080"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769995" version="1" comment="kernel-livepatch-4_12_14-150100_197_126-default is &gt;=8-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060439"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170080"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769996" version="1" comment="kernel-livepatch-4_12_14-150100_197_131-default is &gt;=6-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060738"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170153"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769997" version="1" comment="kernel-livepatch-4_12_14-150100_197_134-default is &gt;=5-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060955"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170143"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769998" version="1" comment="kernel-livepatch-4_12_14-150100_197_137-default is &gt;=3-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061065"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170137"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755252" version="1" comment="kernel-livepatch-5_14_21-150400_15_18-rt is &gt;=2-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061967"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170606"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009755397" version="1" comment="kernel-livepatch-5_14_21-150400_24_55-default is &gt;=2-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170606"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798679" version="1" comment="kgraft-patch-4_12_14-122_133-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798650" version="1" comment="kgraft-patch-4_12_14-122_136-default is &gt;=11-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798651" version="1" comment="kgraft-patch-4_12_14-122_139-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060549"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798680" version="1" comment="kgraft-patch-4_12_14-122_144-default is &gt;=9-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060732"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169926"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798681" version="1" comment="kgraft-patch-4_12_14-122_147-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060867"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798652" version="1" comment="kgraft-patch-4_12_14-122_150-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798653" version="1" comment="kgraft-patch-4_12_14-122_153-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061064"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798682" version="1" comment="kgraft-patch-4_12_14-122_156-default is &gt;=6-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166495"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798654" version="1" comment="kgraft-patch-4_12_14-122_159-default is &gt;=5-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062102"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169741"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798655" version="1" comment="kgraft-patch-4_12_14-122_162-default is &gt;=4-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062252"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169746"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009794744" version="1" comment="kernel-default is ==4.12.14-122.165.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188039"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798683" version="1" comment="kgraft-patch-4_12_14-122_165-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062368"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798684" version="1" comment="kernel-default is ==4.12.14-122.173.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188811"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798685" version="1" comment="kgraft-patch-4_12_14-122_173-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062472"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798686" version="1" comment="kernel-default is &lt;4.12.14-122.173.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188812"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798903" version="1" comment="kernel-livepatch-4_12_14-150100_197_123-default is &gt;=11-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173047"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798687" version="1" comment="kernel-livepatch-4_12_14-150100_197_126-default is &gt;=11-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060439"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173047"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798904" version="1" comment="kernel-livepatch-4_12_14-150100_197_131-default is &gt;=9-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060738"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170079"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798905" version="1" comment="kernel-livepatch-4_12_14-150100_197_134-default is &gt;=8-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060955"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170080"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798906" version="1" comment="kernel-livepatch-4_12_14-150100_197_137-default is &gt;=6-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061065"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170161"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798907" version="1" comment="kernel-livepatch-4_12_14-150100_197_142-default is &gt;=6-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062004"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170161"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799060" version="1" comment="kernel-livepatch-4_12_14-150100_197_145-default is &gt;=6-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062103"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170161"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775802" version="1" comment="kernel-default is ==4.12.14-150100.197.148.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184117"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799061" version="1" comment="kernel-livepatch-4_12_14-150100_197_148-default is &gt;=4-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062253"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170075"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009782321" version="1" comment="kernel-default is ==4.12.14-150100.197.151.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009185167"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799062" version="1" comment="kernel-livepatch-4_12_14-150100_197_151-default is &gt;=3-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062369"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170137"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799063" version="1" comment="kernel-default is ==4.12.14-150100.197.154.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188895"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799064" version="1" comment="kernel-livepatch-4_12_14-150100_197_154-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062493"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799065" version="1" comment="kernel-default is &lt;4.12.14-150100.197.154.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188896"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799066" version="1" comment="kernel-livepatch-5_3_18-150200_24_129-default is &gt;=12-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060347"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166593"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798908" version="1" comment="kernel-livepatch-5_3_18-150200_24_134-default is &gt;=12-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166593"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799558" version="1" comment="kernel-livepatch-5_3_18-150200_24_139-default is &gt;=9-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166587"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799067" version="1" comment="kernel-livepatch-5_3_18-150200_24_142-default is &gt;=8-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060956"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166588"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799068" version="1" comment="kernel-livepatch-5_3_18-150200_24_145-default is &gt;=7-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061067"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166542"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799069" version="1" comment="kernel-livepatch-5_3_18-150200_24_148-default is &gt;=6-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062005"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166573"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799070" version="1" comment="kernel-livepatch-5_3_18-150200_24_151-default is &gt;=6-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062086"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166573"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799559" version="1" comment="kernel-livepatch-5_3_18-150200_24_154-default is &gt;=4-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062296"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795754" version="1" comment="kernel-default is ==5.3.18-150200.24.157.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188192"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799560" version="1" comment="kernel-livepatch-5_3_18-150200_24_157-default is &gt;=3-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062373"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799561" version="1" comment="kernel-default is ==5.3.18-150200.24.160.2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188964"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799562" version="1" comment="kernel-livepatch-5_3_18-150200_24_160-default is &gt;=2-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062494"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169354"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799563" version="1" comment="kernel-default is &lt;5.3.18-150200.24.160.2" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188965"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799630" version="1" comment="kernel-livepatch-5_3_18-150300_59_101-default is &gt;=11-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060563"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166612"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799690" version="1" comment="kernel-livepatch-5_3_18-150300_59_106-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060746"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799631" version="1" comment="kernel-livepatch-5_3_18-150300_59_109-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060937"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799632" version="1" comment="kernel-livepatch-5_3_18-150300_59_112-default is &gt;=8-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166598"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799633" version="1" comment="kernel-livepatch-5_3_18-150300_59_115-default is &gt;=7-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061085"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166545"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799634" version="1" comment="kernel-livepatch-5_3_18-150300_59_118-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062001"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799635" version="1" comment="kernel-livepatch-5_3_18-150300_59_121-default is &gt;=6-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062100"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166574"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799636" version="1" comment="kernel-livepatch-5_3_18-150300_59_124-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062294"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796008" version="1" comment="kernel-default is ==5.3.18-150300.59.127.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188237"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799637" version="1" comment="kernel-livepatch-5_3_18-150300_59_127-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062370"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799638" version="1" comment="kernel-default is ==5.3.18-150300.59.130.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188981"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799639" version="1" comment="kernel-livepatch-5_3_18-150300_59_130-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062473"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799564" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=15-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799640" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=14-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170084"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799641" version="1" comment="kernel-livepatch-5_3_18-150300_59_98-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798909" version="1" comment="kernel-livepatch-5_14_21-150400_15_11-rt is &gt;=8-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061016"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798910" version="1" comment="kernel-livepatch-5_14_21-150400_15_18-rt is &gt;=7-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061967"/>
		<state state_ref="oval:org.opensuse.security:ste:2009174882"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798911" version="1" comment="kernel-livepatch-5_14_21-150400_15_23-rt is &gt;=6-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062041"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173644"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798912" version="1" comment="kernel-livepatch-5_14_21-150400_15_28-rt is &gt;=6-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062101"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173644"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798913" version="1" comment="kernel-livepatch-5_14_21-150400_15_37-rt is &gt;=3-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062356"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798914" version="1" comment="kernel-livepatch-5_14_21-150400_15_5-rt is &gt;=10-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178810"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798915" version="1" comment="kernel-livepatch-5_14_21-150400_15_8-rt is &gt;=9-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060939"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178778"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799642" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=14-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188233"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799643" version="1" comment="kernel-livepatch-5_14_21-150400_24_28-default is &gt;=12-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184122"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799644" version="1" comment="kernel-livepatch-5_14_21-150400_24_33-default is &gt;=11-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188234"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799645" version="1" comment="kernel-livepatch-5_14_21-150400_24_38-default is &gt;=10-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060751"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178810"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799646" version="1" comment="kernel-livepatch-5_14_21-150400_24_41-default is &gt;=9-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060940"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178778"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799647" version="1" comment="kernel-livepatch-5_14_21-150400_24_46-default is &gt;=8-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060977"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799648" version="1" comment="kernel-livepatch-5_14_21-150400_24_55-default is &gt;=7-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009174882"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799649" version="1" comment="kernel-livepatch-5_14_21-150400_24_60-default is &gt;=6-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062027"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173644"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799650" version="1" comment="kernel-livepatch-5_14_21-150400_24_63-default is &gt;=6-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062070"/>
		<state state_ref="oval:org.opensuse.security:ste:2009173644"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799651" version="1" comment="kernel-livepatch-5_14_21-150400_24_66-default is &gt;=4-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062295"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798916" version="1" comment="kernel-livepatch-5_14_21-150500_11-rt is &gt;=4-150500.9.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062421"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188865"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798917" version="1" comment="kernel-livepatch-5_14_21-150500_13_5-rt is &gt;=3-150500.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062367"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188866"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799652" version="1" comment="kernel-livepatch-5_14_21-150500_53-default is &gt;=4-150500.9.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188865"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764716" version="1" comment="kernel-livepatch-5_3_18-150200_24_148-default is &gt;=2-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062005"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177711"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764717" version="1" comment="kernel-default is &lt;5.3.18-150200.24.148.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182102"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764719" version="1" comment="kernel-livepatch-5_3_18-150300_59_118-default is &gt;=2-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062001"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177715"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764720" version="1" comment="kgraft-patch-4_12_14-95_102-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060093"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764721" version="1" comment="kgraft-patch-4_12_14-95_105-default is &gt;=10-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060221"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169925"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764722" version="1" comment="kgraft-patch-4_12_14-95_108-default is &gt;=8-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060348"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169792"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764723" version="1" comment="kgraft-patch-4_12_14-95_111-default is &gt;=7-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060444"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169794"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764724" version="1" comment="kgraft-patch-4_12_14-95_114-default is &gt;=5-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060753"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169789"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764725" version="1" comment="kgraft-patch-4_12_14-95_117-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060957"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764726" version="1" comment="kgraft-patch-4_12_14-95_120-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061043"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764727" version="1" comment="kgraft-patch-4_12_14-95_99-default is &gt;=12-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059968"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170051"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764729" version="1" comment="kgraft-patch-4_12_14-122_156-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764730" version="1" comment="kernel-default is &lt;4.12.14-122.156.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182105"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764732" version="1" comment="kernel-livepatch-4_12_14-150100_197_142-default is &gt;=2-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062004"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182099"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764733" version="1" comment="kernel-default is &lt;4.12.14-150100.197.142.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182107"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776019" version="1" comment="kgraft-patch-4_12_14-122_130-default is &gt;=12-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060215"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167116"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775786" version="1" comment="kgraft-patch-4_12_14-122_133-default is &gt;=10-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060344"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167187"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775787" version="1" comment="kgraft-patch-4_12_14-122_136-default is &gt;=9-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060442"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170064"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775788" version="1" comment="kgraft-patch-4_12_14-122_139-default is &gt;=8-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060549"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167189"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775789" version="1" comment="kgraft-patch-4_12_14-122_144-default is &gt;=7-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060732"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167185"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775790" version="1" comment="kgraft-patch-4_12_14-122_147-default is &gt;=6-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060867"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167108"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775791" version="1" comment="kgraft-patch-4_12_14-122_150-default is &gt;=6-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167108"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775792" version="1" comment="kgraft-patch-4_12_14-122_153-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061064"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775793" version="1" comment="kgraft-patch-4_12_14-122_156-default is &gt;=4-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169961"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776020" version="1" comment="kgraft-patch-4_12_14-122_159-default is &gt;=3-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062102"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169850"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776022" version="1" comment="kgraft-patch-4_12_14-122_162-default is &gt;=2-2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062252"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169758"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775794" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=12-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170154"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775795" version="1" comment="kernel-livepatch-4_12_14-150100_197_123-default is &gt;=9-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170079"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775796" version="1" comment="kernel-livepatch-4_12_14-150100_197_126-default is &gt;=9-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060439"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170079"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775797" version="1" comment="kernel-livepatch-4_12_14-150100_197_131-default is &gt;=7-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060738"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170074"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775798" version="1" comment="kernel-livepatch-4_12_14-150100_197_134-default is &gt;=6-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060955"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170153"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775799" version="1" comment="kernel-livepatch-4_12_14-150100_197_137-default is &gt;=4-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061065"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170075"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775800" version="1" comment="kernel-livepatch-4_12_14-150100_197_142-default is &gt;=4-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062004"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170075"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775801" version="1" comment="kernel-livepatch-4_12_14-150100_197_145-default is &gt;=4-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062103"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170075"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775803" version="1" comment="kernel-livepatch-4_12_14-150100_197_148-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062253"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775804" version="1" comment="kernel-default is &lt;4.12.14-150100.197.148.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775805" version="1" comment="kernel-livepatch-5_3_18-150200_24_126-default is &gt;=13-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060247"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166592"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776024" version="1" comment="kernel-livepatch-5_3_18-150200_24_129-default is &gt;=10-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060347"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166595"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775806" version="1" comment="kernel-livepatch-5_3_18-150200_24_134-default is &gt;=10-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060482"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166595"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776025" version="1" comment="kernel-livepatch-5_3_18-150200_24_139-default is &gt;=7-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060752"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170081"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775807" version="1" comment="kernel-livepatch-5_3_18-150200_24_142-default is &gt;=6-150200.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060956"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170155"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776026" version="1" comment="kernel-livepatch-5_3_18-150200_24_145-default is &gt;=5-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061067"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166567"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776027" version="1" comment="kernel-livepatch-5_3_18-150200_24_148-default is &gt;=4-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062005"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775808" version="1" comment="kernel-livepatch-5_3_18-150200_24_151-default is &gt;=4-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062086"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166569"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776029" version="1" comment="kernel-livepatch-5_3_18-150200_24_154-default is &gt;=2-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062296"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169354"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776031" version="1" comment="kernel-livepatch-5_3_18-150300_59_101-default is &gt;=9-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060563"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166597"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776032" version="1" comment="kernel-livepatch-5_3_18-150300_59_106-default is &gt;=7-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060746"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166599"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775809" version="1" comment="kernel-livepatch-5_3_18-150300_59_109-default is &gt;=7-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060937"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166599"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776033" version="1" comment="kernel-livepatch-5_3_18-150300_59_112-default is &gt;=6-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060976"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170083"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775810" version="1" comment="kernel-livepatch-5_3_18-150300_59_115-default is &gt;=5-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061085"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166576"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775811" version="1" comment="kernel-livepatch-5_3_18-150300_59_118-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062001"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775812" version="1" comment="kernel-livepatch-5_3_18-150300_59_121-default is &gt;=4-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062100"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166578"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775814" version="1" comment="kernel-livepatch-5_3_18-150300_59_124-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062294"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775815" version="1" comment="kernel-livepatch-5_3_18-150300_59_90-default is &gt;=13-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060254"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166610"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775816" version="1" comment="kernel-livepatch-5_3_18-150300_59_93-default is &gt;=12-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060342"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166611"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775817" version="1" comment="kernel-livepatch-5_3_18-150300_59_98-default is &gt;=10-150300.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060508"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166596"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775818" version="1" comment="kernel-livepatch-5_14_21-150400_15_11-rt is &gt;=6-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061016"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178812"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775819" version="1" comment="kernel-livepatch-5_14_21-150400_15_18-rt is &gt;=5-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061967"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172959"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775820" version="1" comment="kernel-livepatch-5_14_21-150400_15_23-rt is &gt;=4-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062041"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775821" version="1" comment="kernel-livepatch-5_14_21-150400_15_5-rt is &gt;=8-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775822" version="1" comment="kernel-livepatch-5_14_21-150400_15_8-rt is &gt;=7-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060939"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178811"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775823" version="1" comment="kernel-livepatch-5_14_21-150400_24_18-default is &gt;=13-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060259"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184121"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775824" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=12-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184122"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775825" version="1" comment="kernel-livepatch-5_14_21-150400_24_28-default is &gt;=10-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178810"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775826" version="1" comment="kernel-livepatch-5_14_21-150400_24_33-default is &gt;=9-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178778"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775827" version="1" comment="kernel-livepatch-5_14_21-150400_24_38-default is &gt;=8-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060751"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775828" version="1" comment="kernel-livepatch-5_14_21-150400_24_41-default is &gt;=7-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060940"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178811"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775829" version="1" comment="kernel-livepatch-5_14_21-150400_24_46-default is &gt;=6-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060977"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178812"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775830" version="1" comment="kernel-livepatch-5_14_21-150400_24_55-default is &gt;=5-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009172959"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775831" version="1" comment="kernel-livepatch-5_14_21-150400_24_60-default is &gt;=4-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062027"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776228" version="1" comment="kernel-livepatch-5_14_21-150500_11-rt is &gt;=2-150500.3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062421"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184167"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776035" version="1" comment="kernel-livepatch-5_14_21-150500_53-default is &gt;=2-150500.3.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062422"/>
		<state state_ref="oval:org.opensuse.security:ste:2009184167"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796009" version="1" comment="kernel-livepatch-5_3_18-150300_59_127-default is &gt;=2-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062370"/>
		<state state_ref="oval:org.opensuse.security:ste:2009168230"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796661" version="1" comment="kernel-livepatch-5_14_21-150400_15_37-rt is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062356"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796662" version="1" comment="kernel-livepatch-5_14_21-150400_15_40-rt is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062372"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796010" version="1" comment="kernel-default is ==5.14.21-150400.24.69.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188238"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796011" version="1" comment="kernel-livepatch-5_14_21-150400_24_69-default is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062366"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796012" version="1" comment="kernel-default is ==5.14.21-150400.24.74.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188239"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796013" version="1" comment="kernel-livepatch-5_14_21-150400_24_74-default is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062435"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796663" version="1" comment="kernel-livepatch-5_14_21-150500_13_5-rt is &gt;=2-150500.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062367"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188242"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796015" version="1" comment="kernel-default is ==5.14.21-150500.55.12.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188241"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796016" version="1" comment="kernel-livepatch-5_14_21-150500_55_12-default is &gt;=2-150500.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062436"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188242"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796017" version="1" comment="kernel-default is ==5.14.21-150500.55.7.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188243"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009796018" version="1" comment="kernel-livepatch-5_14_21-150500_55_7-default is &gt;=2-150500.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062384"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188242"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770231" version="1" comment="kernel-default is &lt;4.12.14-122.159.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009183295"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764735" version="1" comment="kernel-livepatch-4_12_14-150100_197_145-default is &gt;=2-150100.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062103"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182099"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764738" version="1" comment="kernel-livepatch-5_3_18-150200_24_151-default is &gt;=2-150200.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062086"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177711"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764739" version="1" comment="kernel-default is &lt;5.3.18-150200.24.151.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182111"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764741" version="1" comment="kernel-livepatch-5_3_18-150300_59_121-default is &gt;=2-150300.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062100"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177715"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764742" version="1" comment="kernel-livepatch-5_14_21-150400_15_28-rt is &gt;=2-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062101"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170606"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009764744" version="1" comment="kernel-livepatch-5_14_21-150400_24_63-default is &gt;=2-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062070"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177490"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742253" version="1" comment="kernel-default is &lt;4.12.14-95.114.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175689"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009742260" version="1" comment="kernel-default is &lt;4.12.14-150100.197.131.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009175693"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009769999" version="1" comment="kernel-livepatch-5_14_21-150400_15_5-rt is &gt;=7-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060754"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178811"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770000" version="1" comment="kernel-livepatch-5_14_21-150400_15_8-rt is &gt;=6-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060939"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178812"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770224" version="1" comment="kernel-livepatch-5_14_21-150400_24_21-default is &gt;=11-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060343"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182089"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770225" version="1" comment="kernel-livepatch-5_14_21-150400_24_28-default is &gt;=9-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060509"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177706"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770226" version="1" comment="kernel-livepatch-5_14_21-150400_24_33-default is &gt;=8-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060564"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177707"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770253" version="1" comment="kernel-livepatch-5_14_21-150400_24_38-default is &gt;=7-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060751"/>
		<state state_ref="oval:org.opensuse.security:ste:2009182091"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770227" version="1" comment="kernel-livepatch-5_14_21-150400_24_41-default is &gt;=6-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060940"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177708"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751218" version="1" comment="kgraft-patch-4_12_14-95_102-default is &gt;=8-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060093"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167189"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751219" version="1" comment="kgraft-patch-4_12_14-95_105-default is &gt;=8-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060221"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167189"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751220" version="1" comment="kgraft-patch-4_12_14-95_108-default is &gt;=6-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060348"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167108"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751221" version="1" comment="kgraft-patch-4_12_14-95_111-default is &gt;=5-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060444"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167113"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751222" version="1" comment="kgraft-patch-4_12_14-95_114-default is &gt;=3-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060753"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167192"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751224" version="1" comment="kgraft-patch-4_12_14-95_117-default is &gt;=2-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060957"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170022"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751225" version="1" comment="kgraft-patch-4_12_14-95_96-default is &gt;=13-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059653"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170063"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751226" version="1" comment="kgraft-patch-4_12_14-95_99-default is &gt;=10-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059968"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167187"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751228" version="1" comment="kgraft-patch-4_12_14-122_150-default is &gt;=2-2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061031"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170022"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750765" version="1" comment="kernel-livepatch-4_12_14-150100_197_111-default is &gt;=13-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059652"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177516"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750766" version="1" comment="kernel-livepatch-4_12_14-150100_197_114-default is &gt;=10-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009059890"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177517"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751230" version="1" comment="kernel-livepatch-4_12_14-150100_197_117-default is &gt;=8-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060078"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177518"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750767" version="1" comment="kernel-livepatch-4_12_14-150100_197_120-default is &gt;=8-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060220"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177518"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009750768" version="1" comment="kernel-livepatch-4_12_14-150100_197_123-default is &gt;=5-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060346"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167146"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751231" version="1" comment="kernel-livepatch-4_12_14-150100_197_126-default is &gt;=5-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060439"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167146"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751232" version="1" comment="kernel-livepatch-4_12_14-150100_197_131-default is &gt;=3-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060738"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177721"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009751234" version="1" comment="kernel-livepatch-4_12_14-150100_197_134-default is &gt;=2-150100.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060955"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177723"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770228" version="1" comment="kgraft-patch-4_12_14-122_156-default is &gt;=3-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062003"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169749"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770230" version="1" comment="kgraft-patch-4_12_14-122_159-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062102"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770001" version="1" comment="kernel-livepatch-4_12_14-150100_197_142-default is &gt;=3-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062004"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170137"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770002" version="1" comment="kernel-livepatch-4_12_14-150100_197_145-default is &gt;=3-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062103"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170137"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770003" version="1" comment="kernel-livepatch-5_14_21-150400_15_11-rt is &gt;=5-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061016"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178776"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770004" version="1" comment="kernel-livepatch-5_14_21-150400_15_18-rt is &gt;=4-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061967"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178777"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770232" version="1" comment="kernel-livepatch-5_14_21-150400_24_46-default is &gt;=5-150400.2.3" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009060977"/>
		<state state_ref="oval:org.opensuse.security:ste:2009177709"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770233" version="1" comment="kernel-livepatch-5_14_21-150400_24_55-default is &gt;=4-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009061969"/>
		<state state_ref="oval:org.opensuse.security:ste:2009178777"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009782320" version="1" comment="kernel-livepatch-4_12_14-150100_197_148-default is &gt;=3-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062253"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170137"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009798920" version="1" comment="kernel-livepatch-5_14_21-150400_15_40-rt is &gt;=3-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062372"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799653" version="1" comment="kernel-livepatch-5_14_21-150400_24_69-default is &gt;=3-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062366"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799654" version="1" comment="kernel-livepatch-5_14_21-150500_55_7-default is &gt;=3-150500.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062384"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188866"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770234" version="1" comment="kernel-default is ==4.12.14-95.125.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009183296"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770235" version="1" comment="kgraft-patch-4_12_14-95_125-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062168"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770236" version="1" comment="kernel-default is &lt;4.12.14-95.125.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009183297"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770005" version="1" comment="kernel-livepatch-5_3_18-150200_24_148-default is &gt;=3-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062005"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770237" version="1" comment="kernel-livepatch-5_3_18-150200_24_151-default is &gt;=3-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062086"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167120"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770238" version="1" comment="kernel-livepatch-5_3_18-150300_59_118-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062001"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770239" version="1" comment="kernel-livepatch-5_3_18-150300_59_121-default is &gt;=3-150300.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062100"/>
		<state state_ref="oval:org.opensuse.security:ste:2009166580"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770006" version="1" comment="kernel-livepatch-5_14_21-150400_15_23-rt is &gt;=3-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062041"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770007" version="1" comment="kernel-livepatch-5_14_21-150400_15_28-rt is &gt;=3-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062101"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770240" version="1" comment="kernel-livepatch-5_14_21-150400_24_60-default is &gt;=3-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062027"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009770241" version="1" comment="kernel-livepatch-5_14_21-150400_24_63-default is &gt;=3-150400.2.2" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062070"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170609"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009794745" version="1" comment="kgraft-patch-4_12_14-122_165-default is &gt;=2-2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062368"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167110"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009794746" version="1" comment="kernel-default is &lt;4.12.14-122.165.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188040"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009782322" version="1" comment="kernel-livepatch-4_12_14-150100_197_151-default is &gt;=2-150100.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062369"/>
		<state state_ref="oval:org.opensuse.security:ste:2009167118"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009782323" version="1" comment="kernel-default is &lt;4.12.14-150100.197.151.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009185168"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795755" version="1" comment="kernel-livepatch-5_3_18-150200_24_157-default is &gt;=2-150200.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062373"/>
		<state state_ref="oval:org.opensuse.security:ste:2009169354"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009795756" version="1" comment="kernel-default is &lt;5.3.18-150200.24.157.1" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188193"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775832" version="1" comment="kernel-livepatch-5_14_21-150400_15_28-rt is &gt;=4-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062101"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009775833" version="1" comment="kernel-livepatch-5_14_21-150400_24_63-default is &gt;=4-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062070"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171147"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009776037" version="1" comment="kernel-livepatch-5_14_21-150400_24_66-default is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062295"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799655" version="1" comment="kernel-livepatch-5_14_21-150400_24_74-default is &gt;=3-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062435"/>
		<state state_ref="oval:org.opensuse.security:ste:2009171148"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799691" version="1" comment="kernel-livepatch-5_14_21-150500_55_12-default is &gt;=3-150500.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062436"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188866"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799074" version="1" comment="kernel-livepatch-5_14_21-150400_15_46-rt is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062469"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799692" version="1" comment="kernel-default is ==5.14.21-150400.24.81.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188998"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799693" version="1" comment="kernel-livepatch-5_14_21-150400_24_81-default is &gt;=2-150400.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062468"/>
		<state state_ref="oval:org.opensuse.security:ste:2009170087"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799075" version="1" comment="kernel-livepatch-5_14_21-150500_13_11-rt is &gt;=2-150500.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062471"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188242"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799694" version="1" comment="kernel-default is ==5.14.21-150500.55.19.1" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009030416"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188999"/>
	</rpminfo_test>
	<rpminfo_test id="oval:org.opensuse.security:tst:2009799695" version="1" comment="kernel-livepatch-5_14_21-150500_55_19-default is &gt;=2-150500.2.1" check="none satisfy" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<object object_ref="oval:org.opensuse.security:obj:2009062470"/>
		<state state_ref="oval:org.opensuse.security:ste:2009188242"/>
	</rpminfo_test>
</tests>
<objects>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030416" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059372" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>SUSE-MicroOS-release</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038994" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>rpcbind</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030588" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>openssl</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042548" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libopenssl1_1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042550" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>openssl-1_1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009034590" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>nfs-client</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009034592" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>nfs-kernel-server</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030596" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>curl</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030964" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libcurl4</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031299" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030403" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>openssh</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041030" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libnm0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041031" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>typelib-1_0-NM-1_0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009034804" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvorbis0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009034806" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvorbisenc2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009035409" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libxml2-2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009035414" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libxml2-tools</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042567" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>vim-data-common</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052260" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>vim-small</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009033599" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>fuse</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009033600" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libfuse2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041085" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libthai-data</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041086" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libthai0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031926" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>glibc</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031925" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>glibc-locale</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047237" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>glibc-locale-base</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030401" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>tar</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031626" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>dbus-1-glib</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030544" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>sudo</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009034546" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>logrotate</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040987" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>hardlink</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038074" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>augeas</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038073" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>augeas-lenses</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038075" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libaugeas0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009033468" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libexpat1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041022" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>squashfs</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047596" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libruby2_5-2_5</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047597" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>ruby2.5</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047600" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>ruby2.5-stdlib</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032479" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>coreutils</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036075" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libXext6</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036099" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libXrender1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036115" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libXv1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031482" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>xen-libs</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libspice-server1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037564" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037566" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-interface</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037568" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-network</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037569" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-nodedev</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037570" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-nwfilter</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037571" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-qemu</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037572" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-secret</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037573" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-storage</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041752" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-storage-core</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041753" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-storage-disk</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041754" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-storage-iscsi</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041755" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-storage-logical</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041756" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-storage-mpath</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041757" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-storage-rbd</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041758" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-driver-storage-scsi</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037577" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-daemon-qemu</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041759" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirt-libs</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042541" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libjson-c3</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037637" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libyaml-0-2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038577" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_38-44-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038604" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_39-47-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038757" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_43-52_6-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038814" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_44-52_10-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038981" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_44-52_18-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038995" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_48-52_27-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039764" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_49-11-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039432" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_51-52_31-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039760" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_51-52_34-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039793" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_51-52_39-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039537" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_51-60_20-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039788" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_51-60_25-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039845" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_53-60_30-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040376" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_57-60_35-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_59-60_41-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040515" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_59-60_45-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042709" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-Jinja2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031639" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>qemu</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038462" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>qemu-arm</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037631" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>qemu-ipxe</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038466" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>qemu-ppc</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038467" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>qemu-s390</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037633" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>qemu-seabios</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037634" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>qemu-sgabios</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036248" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>qemu-tools</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037635" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>qemu-vgabios</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038468" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>qemu-x86</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009033259" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libfreebl3</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009033976" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libsoftokn3</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032440" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>mozilla-nss</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009033978" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>mozilla-nss-certs</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009033880" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libfreetype6</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038771" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgcrypt20</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030891" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>dbus-1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009035201" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libdbus-1-3</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038277" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>shim</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009034744" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>wpa_supplicant</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038950" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_32-33-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030456" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>file</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037852" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>file-magic</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037850" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libmagic1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038161" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>powerpc-utils</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038032" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>liblzo2-2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042555" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libpython3_6m1_0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037061" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036916" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-base</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048170" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>liblz4-1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038208" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>docker</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031044" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>krb5</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042533" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libevent-2_1-8</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042706" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libzmq5</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038675" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_36-38-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009035367" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libssh4</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030761" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>rsync</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042507" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgnutls30</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038688" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libpcre1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040850" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libpcre2-8-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038301" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libksba8</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038279" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libjpeg8</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030506" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>cpio</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031455" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libblkid1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040900" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libfdisk1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038354" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libmount1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038362" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libsmartcols1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031465" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libuuid1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030584" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>util-linux</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038357" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>util-linux-systemd</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038055" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>elfutils</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038057" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libasm1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038060" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libdw1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042483" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libebl-plugins</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038067" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libelf1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038591" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>less</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038420" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libmspack0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037297" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libpixman-1-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030788" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>e2fsprogs</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031459" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libcom_err2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031461" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libext2fs2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036437" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>update-alternatives</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>grep</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009033420" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libldap-2_4-2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041076" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libldap-data</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038580" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libssh2-1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041095" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>chrony</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049458" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>chrony-pool-suse</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038785" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libidn11</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041929" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libidn2-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041052" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-requests</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038046" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libtasn1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038681" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libtasn1-6</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009034515" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libpolkit0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009034518" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>polkit</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032521" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>pam</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038780" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libunwind</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040582" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libsqlite3-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042523" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libaudit1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042525" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libauparse0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009034560" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvmtools0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009034562" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>open-vm-tools</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041228" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>librados2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041232" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>librbd1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032358" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>mozilla-nspr</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041083" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libsystemd0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037378" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libudev1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036874" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>systemd</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036879" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>systemd-sysvinit</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031048" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>udev</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009035829" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libxslt1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009037593" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libpng16-16</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039506" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>grub2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041109" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>grub2-arm64-efi</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039507" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>grub2-i386-pc</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>grub2-powerpc-ieee1275</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039513" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>grub2-s390x-emu</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039508" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>grub2-snapper-plugin</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039509" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>grub2-x86_64-efi</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039510" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>grub2-x86_64-xen</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042537" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libhogweed4</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042538" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libnettle6</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041176" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_21-69-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041242" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_21-81-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040921" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_21-84-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041143" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_21-90-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041387" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_38-93-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>gstreamer</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041492" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgstreamer-1_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041508" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libvirglrenderer0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030410" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>perl</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031056" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>perl-base</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039086" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgraphite2-3</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040283" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libnghttp2-14</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042407" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-salt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040290" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>salt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040297" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>salt-minion</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031657" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libbz2-1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032484" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>dosfstools</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009033994" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>openslp</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040636" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_62-60_62-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>firewalld</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042488" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-firewall</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040634" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kdump</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040610" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>cracklib</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040611" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>cracklib-dict-small</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040619" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libcrack2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040639" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_62-60_64_8-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041418" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>policycoreutils</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009053613" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>policycoreutils-python-utils</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047412" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-policycoreutils</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041999" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libbluetooth3</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040879" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_67-60_64_18-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009039344" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>dracut</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042565" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-urllib3</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040390" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libcairo2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032478" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>bash</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042463" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libreadline7</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040918" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_67-60_64_21-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041210" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libz1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040908" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>containerd</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042189" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>docker-runc</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040911" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>runc</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041430" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libopus0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050145" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libnl-config</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050144" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libnl3-200</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042099" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_103-6_33-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042107" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_103-6_38-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041885" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_82-6_3-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041959" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_82-6_6-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042037" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_82-6_9-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042003" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_92-6_18-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042049" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_92-6_30-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041484" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_49-92_11-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041522" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_49-92_14-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041570" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_59-92_17-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041642" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_59-92_20-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041661" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_59-92_24-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041737" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_74-92_29-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041816" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_74-92_32-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041849" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_74-92_35-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041957" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_74-92_38-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042005" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_90-92_45-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048207" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_40-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048551" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-120-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048384" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_7-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048201" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_41-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048203" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_26-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042041" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-firmware</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042186" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_114-94_11-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042375" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_114-94_14-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042101" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_103-92_53-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042105" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_103-92_56-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042047" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_90-92_50-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050199" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>iscsiuio</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050200" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libopeniscsiusr0_2_0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032231" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>open-iscsi</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048670" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-PyYAML</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046680" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-23-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046581" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-25_3-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051618" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>salt-transactional-update</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>ucode-intel</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046389" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libyaml-cpp0_6</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041178" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_67-60_64_24-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041450" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_69-60_64_29-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040405" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>apparmor-parser</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041470" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_69-60_64_32-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041519" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-3_12_69-60_64_35-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031757" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libzypp</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047330" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>zypper</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047416" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>zypper-needs-restarting</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032541" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>rpm</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041827" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_73-5-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042528" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libcroco-0_6-3</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042338" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_120-94_17-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042385" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_126-94_22-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047482" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_19-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047614" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_24-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047745" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_29-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047922" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_32-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048180" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_37-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048408" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_45-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048683" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_48-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048796" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_51-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048482" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_12-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048685" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_17-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048798" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_20-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047478" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_22-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047610" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_27-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047743" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_32-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047918" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_35-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048154" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_38-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048480" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_47-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047528" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-195-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047612" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_10-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048066" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_15-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047920" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_18-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048156" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_21-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048401" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_29-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048662" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_34-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048742" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_37-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047518" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_4-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048794" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_40-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047544" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_7-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042564" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-pyOpenSSL</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030602" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>gpg2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042584" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_131-94_29-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046614" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_132-94_33-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046840" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-25_13-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046597" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-25_6-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047417" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>podman</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047418" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>podman-cni-config</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046471" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_138-94_39-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046561" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_140-94_42-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046639" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_143-94_47-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058502" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>liblldp_clif1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058503" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>open-lldp</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046688" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-25_16-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048169" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libprocps7</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038823" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>procps</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036214" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libX11-6</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036218" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libX11-data</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036222" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libX11-xcb1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046755" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_155-94_50-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046853" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_156-94_57-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046887" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_156-94_61-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046993" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_156-94_64-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046851" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-25_19-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047402" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>btrfsmaintenance</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041004" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libpango-1_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047795" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libcontainers-common</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051616" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-distro</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046922" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libxkbcommon0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040978" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>glib2-tools</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030896" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgio-2_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030899" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libglib-2_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030902" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgmodule-2_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030905" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgobject-2_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047099" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-94_41-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047020" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_3-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047080" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_6-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047083" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-25_28-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042188" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>docker-libnetwork</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048723" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>cni-plugins</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046939" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_162-94_69-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047097" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_162-94_72-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046880" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-25_22-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046908" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-25_25-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049063" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>gettext-runtime</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041698" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libncurses6</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041701" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>ncurses-utils</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032551" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>terminfo</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>terminfo-base</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009034036" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>supportutils</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046714" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libsolv-tools</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050501" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_68-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050637" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_71-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051574" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_74-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051676" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_77-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052204" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_80-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058767" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_83-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050495" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_66-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050630" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_69-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051571" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_72-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052200" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_75-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058754" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_78-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032193" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>shadow</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047209" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_13-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047380" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_16-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047218" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_14-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047376" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_17-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047163" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_175-94_79-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047220" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_176-94_88-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047378" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_178-94_91-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047480" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_4_180-94_97-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047767" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libzstd1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031669" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>dnsmasq</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042042" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>ucode-amd</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048888" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_54-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048927" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_52-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050455" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libfribidi0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009031011" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-default-base</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058585" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-psutil</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048558" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>wicked</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048559" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>wicked-service</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009033739" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libesmtp</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048836" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libbsd0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030404" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>iproute2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047019" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-setuptools</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032191" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>permissions</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009035914" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgbm1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047091" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>liblua5_3-5</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047799" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>slirp4netns</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048063" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libseccomp2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041337" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>gstreamer-plugins-base</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041342" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgstallocators-1_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041344" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgstapp-1_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041346" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgstaudio-1_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041162" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgstgl-1_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041350" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgstpbutils-1_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041352" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgstriff-1_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041360" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgsttag-1_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009041362" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgstvideo-1_0-0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049037" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_57-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049203" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_60-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049029" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_55-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049197" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_58-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049448" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_63-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049450" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_65-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048890" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_23-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048929" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_26-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049039" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_29-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049174" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_32-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049176" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_37-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049273" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_41-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049336" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_46-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049427" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_51-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050026" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_54-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048886" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_45-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049031" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_48-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049170" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_51-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049178" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_56-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049269" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_61-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049332" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_64-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049420" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_67-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049442" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_72-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050049" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_75-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049172" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-22-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049168" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_12-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049180" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_15-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049033" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_9-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049246" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_24-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049334" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_29-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049396" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_34-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009049422" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_37-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050167" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_43-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050291" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>glib-networking</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040358" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgcc_s1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040364" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libstdc++6</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009036471" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libproxy1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050503" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_60-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050622" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_63-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050517" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_83-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050632" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_86-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050499" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_49-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050634" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_52-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051701" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-57-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048667" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-asn1crypto</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048729" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-cffi</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009046896" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-cryptography</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052216" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-pyasn1</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052217" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-pycparser</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050419" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_57-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050415" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_78-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047355" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libp11-kit0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047357" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>p11-kit</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047360" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>p11-kit-tools</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050417" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_46-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050228" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-py</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_66-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052214" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_53_4-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051581" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_71-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051677" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_74-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052174" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_77-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051565" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_89-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051674" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_92-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051510" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_61-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051567" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_64-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051675" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_67-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060093" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_102-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060221" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_105-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059337" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_88-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059478" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_93-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059653" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_96-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059968" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_99-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058756" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_103-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059194" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_106-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059338" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_110-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059479" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_113-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059627" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_116-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_121-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059969" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_124-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060094" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_127-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060215" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_130-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052448" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_88-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058492" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_91-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058586" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_98-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059651" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150000_150_89-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059889" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150000_150_92-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060077" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150000_150_95-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060219" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150000_150_98-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059334" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_83-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059474" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150_86-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059652" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_111-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059890" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_114-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060078" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_117-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060220" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_120-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058755" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_102-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059287" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_105-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059475" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_108-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059625" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_112-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059891" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_115-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060247" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_126-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059335" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_102-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059476" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_107-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052449" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_83-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058499" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_86-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058587" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_93-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058668" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_96-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059241" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_99-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059242" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_43-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059343" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_46-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059336" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_49-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059477" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_54-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059539" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_60-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059626" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_63-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_68-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059787" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_71-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059788" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_76-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060183" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_87-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052445" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-59_24-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058491" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-59_27-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058584" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-59_34-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058693" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-59_37-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059193" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-59_40-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060074" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_22-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060153" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_11-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060259" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_18-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052205" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_80-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052227" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_83-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052201" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-197_99-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052139" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_70-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052202" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_75-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052225" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-24_78-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051722" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-59_10-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052137" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-59_13-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052203" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-59_16-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009052226" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-59_19-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009051700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-59_5-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058493" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kmod</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058495" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kmod-compat</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058497" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libkmod2</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009032527" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>perl-Bootloader</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038306" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-rpm</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059490" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libprotobuf-lite20</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009047798" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libfuse3-3</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038423" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libhivex0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009038424" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>perl-Win-Hivex</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060347" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_129-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060482" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_134-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060254" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_90-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060342" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_93-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060508" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_98-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060343" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_21-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060509" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_28-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060564" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_33-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009042704" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>systemd-container</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050294" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>cryptsetup</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050295" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libcryptsetup12</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009058762" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>python3-Babel</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009048750" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libgmp10</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040821" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libharfbuzz0</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030647" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>gzip</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009059620" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>liblzma5</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009050248" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>xz</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030478" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>cyrus-sasl</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009030615" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>cyrus-sasl-digestmd5</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009040965" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>libsasl2-3</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060563" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_101-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060348" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_108-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060444" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_111-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060344" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_133-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060442" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_136-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060346" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_123-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060439" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_126-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060345" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150000_150_101-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060443" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150000_150_104-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060753" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_114-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060549" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_139-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060732" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_144-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060738" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_131-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060752" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_139-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060754" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_15_5-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060751" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_38-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060956" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_142-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009061067" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_145-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060746" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_106-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060937" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_109-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060976" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_112-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009061085" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_115-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060939" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_15_8-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060940" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_41-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060867" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_147-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009061016" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_15_11-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009061967" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_15_18-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062041" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_15_23-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060977" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_46-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009061969" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_55-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062027" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_60-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060957" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_117-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009060955" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_134-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009061031" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_150-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009061064" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_153-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062003" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_156-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062102" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_159-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062252" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_162-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009061065" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_137-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062004" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_142-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062103" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_145-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062005" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_148-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062086" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_151-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062296" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_154-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062001" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_118-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062100" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_121-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062294" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_124-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062101" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_15_28-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062070" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_63-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062295" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_66-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062421" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150500_11-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062422" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150500_53-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009061043" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_120-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062368" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_165-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062472" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-122_173-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062253" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_148-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062369" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_151-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062493" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-4_12_14-150100_197_154-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062373" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_157-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062494" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150200_24_160-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062370" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_127-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062473" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_3_18-150300_59_130-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062356" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_15_37-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062367" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150500_13_5-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062372" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_15_40-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062366" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_69-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062435" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_74-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062436" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150500_55_12-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062384" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150500_55_7-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062168" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kgraft-patch-4_12_14-95_125-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062469" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_15_46-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062468" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150400_24_81-default</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062471" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150500_13_11-rt</name>
	</rpminfo_object>
	<rpminfo_object id="oval:org.opensuse.security:obj:2009062470" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
		<name>kernel-livepatch-5_14_21-150500_55_19-default</name>
	</rpminfo_object>
</objects>
<states>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009079458" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <version operation="equals">0</version>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167699" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <version operation="equals">5.0</version>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180708" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.22.10-3.3.4</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111799" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.3.6-4.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180734" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:8.0.1568-5.11.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111729" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.9.7-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111598" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.1.27-1.16</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180695" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.26-13.51.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111843" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.30-3.3.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111455" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.108-1.29</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111810" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.13.0-4.3.9</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111491" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.0+git.e66999f-1.25</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111426" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.10.1-1.11</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111899" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.2.5-3.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111664" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.3-1.29</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111981" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.5.8-4.11.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111443" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:8.29-2.12</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.3.3-1.30</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111520" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.9.10-1.30</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111523" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.0.11-1.23</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180737" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.13.2_06-3.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180714" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.14.2-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111550" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.13-1.19</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111613" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.1.7-1.17</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169740" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.38-44.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169741" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169743" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.39-47.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169744" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.43-52.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169745" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.44-52.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169746" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169747" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.44-52.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169748" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.48-52.27.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169749" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170444" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.49-11.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169750" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-14.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169751" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.51-52.31.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169752" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.51-52.34.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169753" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.51-52.39.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167110" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169754" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.51-60.20.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169755" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.51-60.25.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169756" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.53-60.30.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169757" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.57-60.35.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169758" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169759" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.59-60.41.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169760" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.59-60.45.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009047758" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.59-60.45.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111824" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.10.1-3.5.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148189" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.9.7-3.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180728" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180729" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.0.0+-11.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180730" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.12.1+-11.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180731" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:8-11.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148142" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.53.1-3.51.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148109" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.10.1-4.8.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180709" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.1.1d-11.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111967" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.1.1d-1.46</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111939" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.8.2-8.36.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111893" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.12.2-8.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180732" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:15+git47-3.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180736" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.9-4.23.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169762" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.32-33.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009044422" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.32-33.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148106" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.32-7.11.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180725" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.3.7.1-3.27.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111555" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.10-2.22</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180712" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.6.12-3.75.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148262" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:19.03.15_ce-6.46.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148131" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.16.3-3.15.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111534" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.1.8-2.23</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148191" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.2.3-3.15.4</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169763" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.36-38.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009044478" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.36-38.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180717" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:6.0.0-13.8.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111987" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.8.7-10.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180690" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:7.66.0-4.11.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169764" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-7.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169765" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-10.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009044800" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.39-47.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009112044" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.1.3-4.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180706" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.6.7-14.7.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111570" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:8.41-4.20</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111571" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:10.31-1.14</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111551" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.3.5-2.14</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148151" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:8.1.2-5.15.7</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111884" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.12-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180703" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.33.1-4.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180704" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.33.1-4.13.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111898" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.168-4.5.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111502" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:530-1.6</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111961" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.6-3.8.19</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180733" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.8.22-4.15.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180692" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.43.8-4.23.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111680" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.19.0.4-2.48</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111912" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.1-4.3.12</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169766" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180707" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.4.46-9.45.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148177" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.9.0-4.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169767" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-6.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009045120" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.43-52.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111945" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.34-3.2.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148146" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.2.0-3.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009112037" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.20.1-6.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111991" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.13-4.5.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169768" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-5.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009050202" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.49-11.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111974" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.116-1.51</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148202" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.3.0-6.29.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180716" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.2.1-4.2.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147219" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.36.0-3.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.8.1-12.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180718" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:11.2.5-4.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169769" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169770" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-4.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009045676" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.44-52.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180721" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.25.1-3.15.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009112042" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.2.3-5.9.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180715" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:246.10-2.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009112006" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.1.32-3.8.24</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009046807" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.51-60.25.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111973" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.6.34-3.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180722" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:8.1p1-5.12.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180696" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.04-9.30.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009046552" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.51-60.20.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169771" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-8.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166495" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169772" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-11.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009047048" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.53-60.30.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111943" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.4.1-4.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157569" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.26-13.65.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169773" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.21-69.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169774" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.21-81.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169775" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.21-84.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169776" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.21-90.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169777" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.38-93.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009050993" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.38-93.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111914" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.16.2-1.53</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009115626" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.6.0-4.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167755" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.26-13.62.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111482" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.3.11-2.12</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111964" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.40.0-1.15</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148090" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.2-9.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009047354" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.57-60.35.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180726" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3000-24.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111876" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.0.6-5.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009112015" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.0.0-6.12.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169778" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-17.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009047745" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.59-60.41.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169779" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-20.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169780" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169781" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.62-60.62.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169782" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-5.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009047935" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.62-60.62.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111727" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.5.5-4.24.9</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180697" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.9.0-11.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148095" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.9.7-11.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169783" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-9.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169784" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.62-60.64.8.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009047945" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.12.62-60.64.8.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169785" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-23.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166491" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180724" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.1-1.25</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169786" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.67-60.64.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170603" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.21-81.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180691" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:049.1+suse.186.g320cc3d1-1.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180727" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.24-9.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111878" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.16.0-1.55</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111870" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4-9.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111871" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:7.0-9.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169787" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.67-60.64.21.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009048707" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.21-84.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180705" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.48-13.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180719" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.2.11-3.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148261" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.3.9-5.29.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148264" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.0.0rc10+gitr3981_dc9208a3303f-6.45.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009112087" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.0.0~rc10-1.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148162" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.3.1-3.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169788" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.103-6.33.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169789" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169790" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.103-6.38.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169791" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.82-6.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169792" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169793" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.82-6.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169794" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169795" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.82-6.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169796" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.92-6.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169797" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169798" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.92-6.30.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009053338" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.92-6.30.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169799" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-18.10.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169800" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169801" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.49-92.11.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169802" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.49-92.14.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169803" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.59-92.17.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169804" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.59-92.20.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169805" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.59-92.24.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169806" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.74-92.29.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169807" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.74-92.32.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169808" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.74-92.35.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169809" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.74-92.38.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009052944" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.74-92.38.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169810" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-18.13.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169811" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-4.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169812" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-4.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169813" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-4.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169814" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-4.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169815" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-4.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169816" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-4.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169817" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-4.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009052706" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.74-92.35.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009052798" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.82-6.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180698" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.49.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-8.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169818" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-21.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169819" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169820" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169821" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169822" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009051911" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.59-92.20.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169823" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.90-92.45.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009053130" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.90-92.45.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009053116" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.92-6.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169824" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.40.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169825" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.40.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169826" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-120.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169827" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-21.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169828" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.7.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169829" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.7.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169830" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.41.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169831" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.41.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169832" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.26.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169833" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.26.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169834" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009051976" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.59-92.24.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166504" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169835" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.82-6.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180723" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.26.1-7.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180699" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:20200107-3.15.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169836" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.114-94.11.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169837" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.114-94.14.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009049850" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.21-69.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169838" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.103-92.53.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169839" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.103-92.56.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169840" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.90-92.50.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009053337" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.90-92.50.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009112030" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.1.2-6.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170445" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-23.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169841" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-25.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170446" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-25.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169842" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-18.7.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009051331" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.49-92.11.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148246" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:20210216-2.19.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148190" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.6.1-4.2.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169843" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.67-60.64.24.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169844" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.69-60.64.29.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169845" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-11.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180689" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.13.4-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169846" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.69-60.64.32.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169847" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:3.12.69-60.64.35.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009051455" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.49-92.14.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180720" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:17.25.6-3.28.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180738" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.14.42-3.17.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009112043" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.14.1-20.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009052066" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.74-92.29.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169848" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.73-5.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169849" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-2.3.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009052125" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.73-5.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111936" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.6.13-1.26</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169850" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169851" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.120-94.17.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169852" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.126-94.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169853" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.19.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169854" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.24.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169855" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.29.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169856" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.32.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169857" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.37.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169858" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.45.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169859" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.48.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169860" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.51.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169861" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.51.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169862" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-12.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169863" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169864" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.17.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169865" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.20.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169866" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169867" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.27.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169868" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.32.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169869" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.35.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169870" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.38.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169871" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.47.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169872" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.47.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170447" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-195.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169873" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-34.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169874" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169875" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.15.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169876" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169877" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.21.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169878" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.29.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169879" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.34.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169880" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.37.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169881" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.4.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169882" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.40.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169883" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.7.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169960" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.7.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111910" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.2.5-4.14.4</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169884" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.131-94.29.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169885" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.132-94.33.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169886" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-25.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167192" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169887" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-25.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169943" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-25.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148265" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.1.1-4.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169888" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.138-94.39.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169889" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.140-94.42.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169890" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.143-94.47.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169891" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-10.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169892" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-25.16.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180710" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.3.15-7.13.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169893" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-25.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111398" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-23.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180701" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.6.5-3.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169894" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.155-94.50.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169895" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.156-94.57.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169896" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.156-94.61.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169897" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.156-94.64.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169898" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-13.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169899" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-25.19.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147681" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.6-3.11.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111711" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.4.2-1.11</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169900" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.140-94.42.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169901" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-28.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111971" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.44.7+11-1.25</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169902" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-7.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148139" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:20200727-3.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009116937" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.5.0-3.5.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009119168" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3002.2-37.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111804" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.8.2-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180694" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.62.6-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169903" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-94.41.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169904" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-2.25.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169905" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169906" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-2.5-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169907" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169908" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-2.5-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169909" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169910" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-25.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167185" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169911" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-25.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148263" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.7.0.1+gitr2908_55e924b8a842-4.31.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169912" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.162-94.69.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169913" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.162-94.72.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169914" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.162-94.72.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169915" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-2.7.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169916" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169917" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-22.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169918" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-25.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169919" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-25.25.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169920" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-16.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009156457" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.6-3.14.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180693" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.19.8.1-4.11.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111962" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:6.1-5.6.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009112052" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.1.9-5.24.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111986" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:3.28.0-3.9.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167774" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.34-150000.3.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180713" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.7.16-3.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167770" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.6.1-4.5.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169921" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.68.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169922" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169923" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.71.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169924" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166484" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.74.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169925" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.77.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169926" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166488" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.80.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166490" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.83.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166492" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.83.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169927" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.66.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169928" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.69.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166508" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.72.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166510" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.75.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.78.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166514" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.78.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009159468" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.2.11-150000.3.30.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169929" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-2.5-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169930" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-2.5-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169931" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-2.5-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169932" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-2.5-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169933" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-2.5-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166502" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169934" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.132-94.33.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169935" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-19.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009112046" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.6-3.5.6</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169936" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-15.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009121033" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-120.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169937" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169938" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-2.5-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169939" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.16.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169940" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.14.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167108" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169941" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.17.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169942" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-2.13.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169944" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.175-94.79.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169945" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.176-94.88.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169946" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.178-94.91.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169947" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.178-94.91.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169948" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-2.16.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169949" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-10.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111410" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-195.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169950" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.4.180-94.97.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169951" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.180-94.97.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009112008" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.4.4-1.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169952" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-7.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170448" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.4.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169953" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-2.19.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169954" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-16.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169955" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.45.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169956" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.29.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169957" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009155674" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:20200107-3.23.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169958" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.29.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169959" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.32.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167721" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.19.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118535" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.19.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118537" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.0+-11.19.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118542" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.12.1+-11.19.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118543" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:8-11.19.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118536" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.19.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169961" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169962" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.54.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169963" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.54.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169964" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.52.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169965" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.52.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169966" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-2.22.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169967" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-19.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111954" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.8.0-3.5.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167712" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.5-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009116835" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.61.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167701" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.61.1.9.26.4</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009146725" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-8.7.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180735" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.6.64-3.3.4</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148358" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.6-150.4.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111933" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.8.7-3.3.17</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167751" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:8.45-20.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148224" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:40.5.0-6.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147344" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.12.14-10.49.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148208" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:20181224-23.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148197" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.1.1-10.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111860" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:19.3.4-45.23</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169968" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-6.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169969" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-28.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111770" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.4-3.3.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148266" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.4.7-3.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169970" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-2.10.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169971" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.4.175-94.79.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169972" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.48.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169973" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.37.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111982" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:2.4.1-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111915" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:1.16.2-2.12</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169974" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.57.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169975" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.60.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169976" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.60.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169977" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.55.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169978" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.58.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169979" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.58.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169980" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-18.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111924" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.40.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169981" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.63.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169982" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.69.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169983" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.65.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169984" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.65.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169985" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.23.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169986" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.26.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169987" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.29.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169988" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.32.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169989" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.37.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169990" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.41.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169991" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.46.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169992" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.51.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169993" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.54.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169994" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.54.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169995" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.63.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169996" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.45.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169997" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.48.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169998" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.51.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169999" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.56.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170000" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.61.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170001" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.64.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170002" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.67.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170003" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.72.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170004" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.75.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170005" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.75.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170449" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-22.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170006" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-5.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170007" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170008" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.15.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170009" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170450" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170010" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.24.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170011" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.29.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170012" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.34.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170013" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.37.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170014" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.43.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148260" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.8.6-3.8.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167763" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.40.0-3.5.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167734" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.12.2-8.11.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170015" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.61.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009116992" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.52.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167760" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.52.1.9.24.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009149102" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.68-3.56.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009149104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.32-3.20.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170016" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-9.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170017" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-31.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009156735" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.13-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167739" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.6.13-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.16.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118518" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.16.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118520" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.0+-11.16.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118525" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.12.1+-11.16.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118526" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:8-11.16.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118519" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.16.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167775" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.34.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167776" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.34.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157350" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.0+-11.34.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157352" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.12.1+-11.34.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157353" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:8-11.34.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157349" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.34.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167757" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.62.4-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148136" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:10.2.1+git583-1.3.4</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167783" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.7.8.6-22.14.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167784" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.1.4-22.14.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154953" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.86-7.14.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170018" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.57.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170019" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.55.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170020" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.51.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170021" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-5.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170022" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009120651" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.1-6.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170023" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.56.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170024" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.45.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009111923" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-22.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167724" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:8.1.2-5.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167725" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.6-3.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009116922" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:20210525-7.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167719" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.67.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167720" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.67.3.9.30.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118230" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-8.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009180711" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:0.4.15-4.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009119123" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.5.8-4.14.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170025" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-3.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170026" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.67.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170027" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-5.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170028" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.71.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170029" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.60.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170030" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.63.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170031" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.63.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170032" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.83.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170033" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.86.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170034" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.86.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170035" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.49.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170036" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.52.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170037" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.52.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166547" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-57.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170038" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-3.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148129" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-57.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147861" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:0.24.0-3.2.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167735" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.13.2-3.2.5</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167736" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.8-10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147866" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:17.5.0-8.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147867" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:0.4.2-3.2.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009117701" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:2.17-3.2.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147868" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.25.10-9.14.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147251" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.70.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167727" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.70.1.9.32.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170039" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170040" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.57.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170041" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.60.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170042" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.78.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170043" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.78.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009156840" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.99.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009156841" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.99.1.9.46.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009155784" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-62.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170044" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-5.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009158159" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.4.7-3.15.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009155941" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.23.2-4.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170045" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.68.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170046" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.66.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170047" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.83.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170048" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.46.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170049" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-5.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170050" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.57.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009116910" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.8.1-5.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167733" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148472" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148474" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.0+-11.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148479" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.12.1+-11.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148480" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:8-11.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148473" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009145986" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.12.2-8.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170051" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170052" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.66.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170053" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.66.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170054" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-5.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166524" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.53.4.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170055" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.77.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170056" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:15-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166496" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.71.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166497" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.74.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166499" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.77.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170057" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.77.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170058" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.72.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166517" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.89.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166519" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.92.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170059" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.92.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170060" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-5.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166570" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.61.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166526" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.64.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166528" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.67.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170061" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.102.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170062" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.105.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170063" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167184" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.88.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170064" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167107" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.93.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167189" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167186" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.96.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167109" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.99.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167111" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.99.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166493" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.103.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167115" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166494" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.106.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167116" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167188" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.110.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167187" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167190" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.113.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167112" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.116.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167191" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.121.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167113" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167114" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.124.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170065" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.127.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170066" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.130.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166503" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.88.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167105" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166505" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.91.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166506" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.98.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166507" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.98.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167195" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150000.150.89.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170067" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167140" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150000.150.92.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170068" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170069" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150000.150.95.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167141" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170070" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150000.150.98.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170071" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167142" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.83.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170072" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167199" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150.86.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170073" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167201" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.86.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167145" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.111.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170074" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167117" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.114.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170075" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170076" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.117.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167118" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170077" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.120.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166515" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.102.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170078" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167202" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.105.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170079" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167148" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.108.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170080" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167150" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.108.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166583" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.112.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170081" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166585" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.115.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166567" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169353" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.126.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169354" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166566" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.102.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166593" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166568" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.107.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166594" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166534" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.83.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166590" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166536" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.86.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166537" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.93.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166591" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:15-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166539" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.96.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170082" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166541" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.99.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166592" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166543" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.99.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166544" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.43.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166610" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166546" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.46.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166575" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.49.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166611" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166577" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.54.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166612" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166579" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.60.4</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166596" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166600" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.63.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166599" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166602" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.68.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170083" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166604" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.71.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166576" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167183" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.76.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166578" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009168229" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.87.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166580" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166556" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-59.24.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166608" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166558" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-59.27.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166559" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-59.34.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166609" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:15-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166561" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-59.37.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170084" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166563" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-59.40.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167221" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-59.40.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166613" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170085" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150400.4.12.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170086" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.11.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170087" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150400.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170088" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170089" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.14.21-150400.24.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170166" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170157" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:15-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173046" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170158" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170090" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.80.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166500" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.80.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166501" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.83.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170091" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.88.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170092" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.75.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166521" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-197.99.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166523" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.99.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166529" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.70.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166530" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.75.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166532" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-24.78.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170093" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.78.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166549" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-59.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166598" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166551" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-59.13.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166552" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-59.16.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166554" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-59.19.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166564" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-59.5.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166565" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-59.5.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154718" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.86.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167745" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.86.2.9.40.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154640" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-54.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167746" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:25-6.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167747" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.931-3.5.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170094" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.64.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157749" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:20200107-3.26.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148898" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.13.3_02-3.34.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157420" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:20220207-10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170095" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-5.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170096" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.32.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166489" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009168230" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170097" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166557" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166560" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166562" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166574" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009159922" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.24.112.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009159923" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.24.112.1.150200.9.52.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009159984" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.79.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170098" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.53.4.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170099" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009155535" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.96.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167756" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.96.1.9.44.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167723" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.14.2-3.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167764" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.6.7-14.10.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167743" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.14.1-22.4.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167744" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.14.1-22.4.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009119003" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.4.1-4.15.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170100" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.93.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009119164" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.4.4-5.32.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009119165" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:20.10.6_ce-6.49.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009119166" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.0~rc93-1.14.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147966" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.78.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167732" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.78.1.9.36.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148014" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-48.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167752" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3002.2-49.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170103" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.80.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170105" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.75.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170106" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147622" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.75.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167729" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.75.3.9.34.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147844" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-45.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167769" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.9.2-4.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157342" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.102.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157343" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.102.1.9.48.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-73.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167698" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:7.66.0-4.14.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167714" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:7.66.0-4.17.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167730" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:7.66.0-4.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167742" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:7.66.0-4.27.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170107" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.74.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170108" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.71.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170109" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-197.89.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170110" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.64.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167765" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.6.13-3.78.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167761" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.1.1d-11.17.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118984" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.25.1-3.17.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167766" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.4.4-1.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009160223" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.13.4_08-150200.3.50.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170111" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-5.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167762" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.62.6-3.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170112" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-5.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167773" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.62.6-150200.3.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009116813" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.13.2_08-3.25.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009149196" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.13.3_04-3.37.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009155719" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.13.4_02-3.40.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009155788" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-65.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167703" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.5.9-4.17.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009116874" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.64.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167708" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.64.1.9.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118228" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-8.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.9-4.29.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154649" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.4.11-56.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154650" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:20.10.9_ce-156.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154651" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.2-23.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009119044" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.6.5-3.21.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009116919" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.6.5-3.21.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009119000" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.8.22-4.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009160220" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.5.9-150000.4.23.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167716" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.16.3-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167717" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.16.3-4.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170113" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-5.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009119173" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.8.2-8.39.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009149384" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.26-13.59.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170161" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170160" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:15-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173047" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170159" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166595" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166540" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009171218" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:18-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166589" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:17-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166597" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166545" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009171219" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:18-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166607" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:17-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173048" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150400.4.21.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009172959" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150400.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170163" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.14.21-150400.24.11.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009156008" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.6.15-3.91.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009156009" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.6.15-3.91.4</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167767" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.1.1d-11.20.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009149147" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.83.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167741" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.83.2.9.38.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009149162" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-51.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170114" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-3.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167713" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.3.14-5.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009143027" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:15.2.12.83+g528da226523-3.25.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167711" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.9.7-3.34.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009119020" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.8.0-3.8.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167722" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.9.7-3.37.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009155303" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.93.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167754" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.93.1.9.42.5</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154642" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-57.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167726" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118550" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118552" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.0+-11.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118557" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.12.1+-11.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118558" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:8-11.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009118551" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167718" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.116-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170115" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.83.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009119067" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.4.1-4.18.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167731" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.25.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147692" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.25.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147694" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.0+-11.25.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147699" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.12.1+-11.25.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:8-11.25.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147693" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.25.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170116" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.70.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167740" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.3.14-5.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147803" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.16.3-3.21.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009147404" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:6.0.0-13.16.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167106" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170117" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-3.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154757" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:6.0.0-13.21.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167737" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.1.1d-11.27.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167738" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.1.1d-11.30.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167753" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.31.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154874" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.31.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154876" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.0+-11.31.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154881" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:1.12.1+-11.31.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154882" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:8-11.31.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009154875" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.2.1-11.31.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167750" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.33.2-4.16.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167748" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.16.3-3.24.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157730" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:8.0.1568-5.17.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157748" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:8.0.1568-5.17.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009148678" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.12-3.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167749" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:6.1-5.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166586" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170169" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009171217" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.129.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009172960" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.134.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166569" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167120" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166533" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166525" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166572" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166535" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166542" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166573" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166605" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166603" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169303" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.90.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170604" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.93.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009172961" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.98.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170118" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150200.3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166555" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166582" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166614" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150400.4.3.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170605" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.21.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170606" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009172962" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173718" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.33.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173719" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.14.21-150400.24.33.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166487" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:15-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166498" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170119" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.96.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170120" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:15-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170121" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170122" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170123" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009156372" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:6.0.0-13.24.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170124" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150200.3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166601" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009156839" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.116-3.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170125" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.96.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170126" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-3.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170127" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009156498" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-68.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167777" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.4.12-60.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167778" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:20.10.12_ce-159.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167779" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.116-3.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009158015" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:8.1p1-5.21.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170128" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.91.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170129" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.86.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167780" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.6.7-14.16.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009155720" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(noarch)</arch>
   <evr datatype="evr_string" operation="less than">0:2.8.0-3.3.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009155805" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.68.1-3.61.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009160436" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.5.11-150000.68.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009160437" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:20.10.14_ce-150000.163.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167758" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:6.1.2-4.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009155856" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.0.3-27.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009158017" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.107.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009158018" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.107.1.9.50.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009156702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.2.5-3.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009158001" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.3.18-76.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157290" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.6.0-4.9.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167771" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:0.6.0-4.6.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166485" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166509" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166511" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166513" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166516" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166518" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166520" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:15-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166522" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166527" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166531" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166538" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166548" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150200.3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166550" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166553" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170130" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170131" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170132" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170133" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170134" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170135" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.88.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167144" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150.83.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009158274" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.1.1d-11.43.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009159991" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.86-150100.7.20.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170136" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170137" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170138" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166571" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:15-150200.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166581" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:15-150200.3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170139" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.93.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009161423" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.14.21-150400.22.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170140" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170141" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170142" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170143" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170144" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170145" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170146" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166588" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166587" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170147" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:18-150200.3.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009159716" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3.68.3-150000.3.67.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166584" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009166606" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:19-150200.3.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009160799" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.10-150200.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009159919" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:5.2.3-150000.4.7.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170148" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:17-150200.3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170149" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:15-150300.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009160763" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:1.43.8-150000.4.33.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170150" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:17-2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170151" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170152" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170153" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170154" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170452" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150400.4.15.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170155" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170156" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150400.4.9.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167193" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:18-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167194" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:17-2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167196" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150000.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167197" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150000.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167198" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150000.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167143" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150000.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167200" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150000.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167146" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150100.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167147" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150100.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167203" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150100.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167149" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150100.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167204" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150100.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167151" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167205" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167152" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167206" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:18-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167153" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:17-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167207" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167154" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167208" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167155" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167156" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167209" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167210" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167211" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167212" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150300.3.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167213" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167214" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167215" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:18-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167216" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:17-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167217" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167218" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167219" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167220" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009167222" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150400.4.6.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009160317" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:3002.2-150200.64.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170162" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157064" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:4.13.4_04-3.43.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157601" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.9-4.33.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157058" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.2.5-3.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157602" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.1.26-5.10.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157696" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.2.5-3.15.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009157956" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <arch datatype="string" operation="pattern match">(aarch64|x86_64)</arch>
   <evr datatype="evr_string" operation="less than">0:2.2.5-3.19.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173744" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.101.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173643" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-150300.59.98.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009174881" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150400.4.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009174882" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150400.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173644" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150400.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009171147" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150400.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009171148" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150400.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170164" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170165" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150000.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170168" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170609" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173741" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:16-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173742" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:19-150300.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009172965" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.130.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009172967" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150100.197.120.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009172968" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.24.126.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170167" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150000.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170379" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.108.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173722" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.111.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170459" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.133.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173723" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.136.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173724" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.136.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173640" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.123.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173727" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.126.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009172963" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.14.21-150400.24.28.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173638" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150000.150.101.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173725" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150000.150.104.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173743" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150400.4.24.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175688" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.114.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009173645" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.139.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175690" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.144.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175691" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.144.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175731" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150100.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175692" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.131.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175694" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.139.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009174858" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-24.107.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175989" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150400.7.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175990" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150400.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009171220" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150400.4.18.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009170607" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.14.21-150400.24.21.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169742" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <version operation="equals"></version>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009174883" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.38.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009169761" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177710" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.142.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009183249" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150200.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177712" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.145.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177713" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.24.145.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175697" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.106.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175763" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.109.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177714" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.112.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177716" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.115.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009183293" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150400.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175991" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.41.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177701" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.147.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.147.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177703" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175695" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.24.139.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177514" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177515" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177704" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177489" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150400.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177705" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150400.10.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177706" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150400.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177707" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150400.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177708" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150400.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177709" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150400.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177491" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150400.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009178777" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009178812" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:6-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009178776" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:5-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182200" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150400.16.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182089" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150400.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182090" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150400.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182091" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150400.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177717" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.46.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009178813" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.55.3</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182092" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.60.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177490" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150400.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182093" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182094" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182095" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177718" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.117.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177722" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.134.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177724" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150100.197.134.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177725" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.24.142.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009178809" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150400.13.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009178810" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009178778" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:9-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009178811" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:7-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177719" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.150.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182096" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.153.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.156.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009183294" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.159.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184162" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.162.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184163" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.162.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177518" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150100.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182098" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.137.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182106" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.142.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182108" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.145.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182109" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150100.197.145.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182101" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.148.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182110" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.151.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184164" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.154.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184165" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.24.154.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182103" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.118.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182112" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.121.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184119" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.124.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184120" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:8-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188233" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:14-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184121" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188234" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:11-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182113" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.63.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184168" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.66.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188236" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150500.6.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184166" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150500.53.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177711" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150200.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177715" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150300.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009178743" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.120.4</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177720" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.150.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182097" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.153.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182099" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150100.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182100" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150100.197.137.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009178744" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.120.4</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188039" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.165.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188811" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-122.173.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188812" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.173.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184117" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.148.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009185167" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.151.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188895" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-150100.197.154.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188896" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150100.197.154.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188192" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.157.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188964" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150200.24.160.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188965" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.24.160.2</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188237" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.127.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188981" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.3.18-150300.59.130.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184122" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:12-150400.2.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188865" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:4-150500.9.2-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188866" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150500.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182102" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.24.148.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182105" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.156.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182107" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150100.197.142.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184118" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150100.197.148.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009184167" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150500.3.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188238" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.69.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188239" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.74.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188242" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150500.2.1-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188241" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150500.55.12.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188243" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150500.55.7.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009183295" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.159.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009182111" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.24.151.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175689" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.114.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009175693" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150100.197.131.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177516" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:13-150100.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177517" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:10-150100.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177721" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:3-150100.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009177723" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="greater than or equal">0:2-150100.2.3-0</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009183296" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:4.12.14-95.125.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009183297" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-95.125.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188040" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-122.165.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009185168" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:4.12.14-150100.197.151.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188193" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="less than">0:5.3.18-150200.24.157.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188998" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150400.24.81.1</evr>
  </rpminfo_state>
  <rpminfo_state id="oval:org.opensuse.security:ste:2009188999" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
   <evr datatype="evr_string" operation="equals">0:5.14.21-150500.55.19.1</evr>
  </rpminfo_state>
</states>
</oval_definitions>
